It is standard for production code to rely on third party libraries. Not just standard, but the opposite is considered bad thing - you are not supposed to implement everything from scratch. If you do, you will end up with more bugs and issues. There is nothing, absolutely nothing in development last 30 years that would say "it is bad to use open source libraries".
But no, it was not all that kuch prevalent. Instead, people wrote their own almost everything.
It would also be irrational. The rare security issue like this is kot a good enough reason for such massive undertaking. You manage risks, you are not supposed to act purely out of fear.
> Good software engineers do that.
The amount of effort required would necessitate management sign up for this. And they won't, because it is not rational thing to do for majority of software.