That was a wakeup call for the community. It wasn't enough to publish sourcecode for important infrastructure. We had to build and fund *systems* that would audit that code. Having the code where anyone could see it would make their job easier, but the job wouldn't do itself.
We got lucky with Heartbleed. The good guys found it before it was ever exploited in the wild, and they coordinated a massive, global upgrade that patched the majority of webservers before the bug was disclosed.
11/