The question is simple. I wanted to get a general consensus on if people actually audit the code that they use from FOSS or open source software or apps.
Do you blindly trust the FOSS community? I am trying to get a rough idea here. Sometimes audit the code? Only on mission critical apps? Not at all?
Let’s hear it!
I don’t because I don’t have the necessary depth of skill.
But I don’t say I “blindly” trust anyone who says they’re FOSS. I read reviews, I do what I can to understand who is behind the project. I try to use software (FOSS or otherwise) in a way that minimizes impact to my system as a whole if something goes south. While I can’t audit code meaningfully, I can setup unique credentials for everything and use good network management practices and other things to create firebreaks.