Earlier quoted context omitted.
No, random anonymous contributors with cheng3920845823@gmail.com as their email address are not as trustworthy as your wife, and blindly merging PRs from them into some of the most security-critical and widely used code in the entire world without so much as running a static analyzer is not reasonable.
Oh I misunderstood the sections in the article about the umn.edu email stuff. My mistake. The actual course of events: 1. Prof and students make fake identities 2. They submit these secret vulns to Greg KH and friends 3. Some of these patches are accepted 4. They intervene at this point and reveal that the patches are malicious 5. The patches are then not merged 6. This news comes out and Greg KH applies big negative…
You know what would really be wasteful of volunteer hours? Instituting a policy whereby the community has to trawl through 20 years of commits from umn.edu addresses and manually review them for vulnerabilities even though you have no reasonable expectation that such commits are likely to contain malicious code and you're actually just butthurt. (they found nothing after weeks of doing this btw)