The same is true for #proprietarysoftware except in proprietary there are also back doors and you cannot remove them (the article does not discuss this, it helps some firms sell "services")
https://searchsoftwarequality.techtarget.com/tip/Secure-open-source-components-to-bypass-breaches