> OpenBSD is designed as a single system with a single codebase, and has a general aversion to features such that it is difficult for an undersecured random library to become a vehicle to breaking a major, important component.
From what I understand, those security benefits aren't incidental; they are a major reason for doing those things.
> a clever contributor
Doesn't seem like it would be very hard for someone to join the team and obtain maintainer status? Also, remember the social engineering done by the xz attacker to get their exploit included in updates - that also seems a bit challenging in the OpenBSD project.
OpenBSD seems to do more careful code reviews than other projects, but I don't know that I have an objective measure of it.