> You must trust that the contributors are trustworthy
In theory, that's only the case if you are unable to review the code yourself.
In practice, it's like saying that TLS encryption is pointless, because one needs to trust every single person who implements it.