Is it knowing the open source code is good, and also knowing the dev is normal required? (How to vet devs?)
Discussion
If I had to guess Chris’ line of thinking, it’s probably that more people actively involved would have caught this sooner and possibly diluted the odds of stuff this questionable being included with a non-related project.