> you can look at the code and double check
Can you honestly say that when a few months ago someone was trying to put a security hole in OpenSSH by making changes that looked harmless to an archiving tool (the xz backdoor)?
Your response is such textbook propaganda, instantly riffing into whataboutism with US surveillance, that I actually had to wonder if you had a real profile.
I then did see that you have actual posts, but imagine if I'd have to investigate the profile of absolutely every commenter I read. Isn't that practically impossible to do? And isn't auditing the source code of absolutely every project you use a few times harder than that?