Earlier quoted context omitted.
> As far as I know, it's also still standard practice in > most companies to either read the source code of open- > source stuff before deploying it to production (binary > or build) or get a support contract from someone else > who has I'm afraid I have no better, more cogent response for this than 'lol'.
At the risk of my karma I'll have to maintain that for companies who are subject to regulation (publicly-traded companies, banks, etc.) what I said is still standard. Unless you have any specific instances to the contrary you're willing to offer?
> for companies who are subject to regulation (publicly-
> traded companies, banks, etc.)
Well for starters, that's not most companies, or even that many companies as a percentage of the whole.The only place I've ever seen (or even heard of this) being done is banks and defense.
It ain't in ISO27001, and so nobody cares.