Possibility of trojan in an open source code

After reading about the following article, and knowing that Trezor firmware is an open source code:

Should I be worried about Trezor firmware?

At the time of writing, there is no bad code hidden via this method in the Trezor firmware source repository.

We will of course be on the lookout for possible future attacks.

