Open-source risk is often simplistically reduced to security headlines about the latest vulnerability or bug count. Security ...