If your source is not open that's barely a speedbump, given a binary. At least that's my impression of the current state.
One lesson out of this is that now that AI has made a certain grade of review cheap is that it would be useful to perform security review both against the source code and against the resulting binary.