Don't entirely agree with Andreas in his ongoing threads, but he has lately been thinking a lot further ahead than most on open source processes, security etc. and what all that will look like. The part being glossed over here is how users will know which projects can be trusted.
Zoomers who grew up in the GitHub era keep telling me that closing PRs means projects are no longer open source.
Obviously, all the requirements for open source still apply. Public code intake was never part of the definition; it was just a popular contribution model for a time.