> where are YOUR commits?
The 'it's open source, fix it yourself' concept breaks down significantly when you're dealing with other people's complex projects.
OpenSSL in particular is a convoluted and horrific codebase, due to a significant number of reasonably awful and insecure decisions, making submitting your own patches a nightmare. Consider yesterday's MITM flaw, where a patch to OpenSSL 1.0.1 provided the opportunity to exploit a bug that OpenSSL has had for over 15 years.
There's also the issue of many open-source projects won't accept patches from outside people, or for features they don't care to implement/support. In the case of OpenSSL, that might actually be a good policy, but it still makes the 'why don't you fix it yourself' argument a weak one.