Could you describe any plausible scenario in which one pull request could compromise the entire .gov IT infrastructure?
wow, where to begin?
Anywhere. Just one.
exec()
That's just code, not a scenario. Government IT systems are currently subject to oversight, testing, comprehensive threat risk assessments etc. Those controls don't disappear just because the software is open source. Right now it's not possible to just deploy new code, open source or not, into a production environment on a critical piece of infrastructure without review. If anything, the open source code should be significantly more secure, because you have added an additional layer of public review, testing and comment.
Let's hope you are right.. :)
The UK gov does not have the best record with IT projects.
If it's open source, the code will be visible and noticed. In a closed source environment, you could still have the exploit, but it'd be behind closed doors.
That is assuming the code is well scrutinized and how they manage contributions.