We haven't built a way to fully verify that open-source software hasn't been secretly tampered with.
open
Global / Unspecified, Global
WS00172
Millions of applications depend on open-source code maintained by volunteers, and a single hidden change can spread unnoticed to countless systems. A trustworthy verification system remains a major unsolved need.