> It is unethical for you not to take every possible measure...
Sidestepping open source for a moment, I don't believe this is the best way to think about security.
Or safety, for that matter. There's a reason we don't walk around in crash helmets all day despite it being a "possible measure" we could take to reduce head injuries.
Security measures can expand unto infinity often in ways that impose costs on other areas of the project.
Any given project has finite resources.
Therefore a better way to think about individual security processes, mitigations or measures is in terms of their cost-benefit.
An ineffective or costly security measure can have net-negative security impact if it consumes resources that could have been used doing something more effective or important.
Therefore the activities you undertake must maximise net benefit - while ensuring you have an effective answer for the highest priority risks that fall out of your threat model.
IMHO the hardest part of executing on this is quantifying risks and benefits, most security decisions are not data driven and must rely on expert judgement or intuition :/