I'd like to think your average J. Random Hacker isn't feeding closed source enterprise code into these things to send off over an API just to get PRs out a little faster, but I know it's happening. The question is, how much, and how much should we worry about it?