The Linux "kernel" is outrageously huge. They've decided to put the baby and the bathwater in for no apparent reason. So yes, it is open source, but who the heck is going to search through the millions of lines of code to find any potential soft spots?
You’d just about have to break the oversight project into smaller pieces and have a bunch of people do it.
My son despises all the bloat, does a lot of work with Gnu and Guix