Um... you understand that Intel CPUs themselves have updatable micro-code, right? And there are a host of other processors in you computer you have no access or ability to audit? (GPU, SATA disk, SATA controller,DVD drive, potentially USB controller, heck if you have a PS2 keyboard port, there's a small processor there...)
The idea of "auditing" a modern system is impossible.
We all understand the mythical man-month issues here, but Microsoft alone employs around 50,000 software engineers (Google 30,000). If everything done at the linux foundation is equal to less that the output of Microsoft for one year (or google for less than 16 months), there may either be a problem with your numbers, or with the entire model of open source.
I'm going to assume the issue is the models...