You are correct, of course. But what the Heartbleed showed us is that even at the scale of OpenSSL (millions of users), almost all were using it blindly. People often care more about the free in pricing aspect more than the freedom to inspect, modify and contribute - because as you say, dev time is precious.
> open source doesn't necessarily mean "anyone can edit it and improve it".
I think you missed the point in the article - it was about how anyone can create or contribute to open-source. Not about submitting patches to existing projects and have them pulled upstream without any review process.