My experience is that OSS security scales upwards based on increased contributors, while commercial software is the inverse.
A small git* repo with a couple contributors is likely very insecure compared to one with 5000+. An enterprise tool from a company with 70 devs is probably far less bloated and insecure than one from a company with 1000 devs.
My 2 cents.