I think their point is that the source being open keeps the developers more honest. Of course there have been supply chain attacks in open source, but that is more probable to be found out than closed source ones. In short, auditability improves security.
But in practical terms there is a lot of trusting of someone/their-code going on. Unless you are reading/understanding it all.
I trust linux more than windows. But I've never read a line of it...