> I am just having a conversation about trust
It all comes down to trust, I think, not source code. How many of the "open source only" proponents have read and analyzed the source code? How many of them have verified that the shipping product is exactly the same as the source? Almost nobody, I suspect.
A relatively small number of people actually work on open source, even with the biggest, most popular projects. The number of eyeballs on the source is a lot smaller than you might expect.
> the vast majority of big players have demonstrated that they shouldn't be trusted
I'm not a big player, just an indie dev.