by ashitlerferad·10y ago·view on hn ↗I think that makes them more trustworthy. If some open source software has never seen a CVE, then that is because no-one actually looked at it in depth enough. All software has bugs and security issues.