Smart contract security assessments are surprisingly readable: https://certificate.quantstamp.com/full/nomad
It's clear what's being audited, the issues identified are clearly categorised, and the maintainer responses are shown.
miniblog.
Related Posts
Bevy has an amazing approach to code review that requires two reviews by the community before a maintainer will review and merge.
"We let anyone submit PRs without vetting: why is the bar higher for reviewing?"
https://shaping.systems/blog/open-code-review/
One big challenge of open source is that the number of users (and bug reports) is entirely independent of the number of maintainers. Both users and maintainer capacity can fluctuate wildly.
The vast majority of libraries have a single maintainer. Even if you weight by downloads, roughly half of downloaded libraries have a single maintainer too.

