You’d just about have to break the oversight project into smaller pieces and have a bunch of people do it.
My son despises all the bloat, does a lot of work with Gnu and Guix
I have a friend and former co-worker who went to work for a three letter agency. He was a very good programmer, but his job was to read other people’s code to make sure they were not putting anything in the code they shouldn’t. At that agency they had three employees reading every line of new code for every guy writing code. They took security very seriously.