Anyone that is mildly evolved with SecDevOps knows how much of theory that happens to be in practice.

I'm unsure what your talking about. Surely SecDevOps would be mostly alerted when a vulnerability isn't caught by someone looking at OSS. Those vulnerabilities that are caught should be mostly invisible.

Pentesting is also part of it.

