When I saw that people lost millions of dollars from a supposed bug in the coldcard hardware wallet firmware I just smiled. My company is very particular about the products we sell. One of the things we always look at are things like licenses. So the coldcard wallet was under a "source available" license, not a FOSS license. FOSS doesn't equal security, but it's a fundamental starting point before we can have a serious conversation about security.
We would never have sold the coldcard hardware wallet is the gist of it.
Not your keys not your coin certainly applies, but what software you use matters too. There are tons of wallets and a hardware wallet isn't necessarily better than software wallet. On can be potentially better than another depending on ones particular needs though.
If your risky with your computing (ie running Microsoft Windows or some Apple product) you probably aught to be using a hardware wallet. The hardware wallet will ensure that your infected system doesn't expose your private key to a third party. However you still need to trust the device your using to generate that private key.
A straight up self-custody software wallet properly written and maintained on a GNU/Linux system could potentially be better than a hardware wallet. It's certainly is better than a hardware wallet if you need to keep the fact you posses crypto hidden from prying eyes.
On the other hand a hardware wallet is still better than not generally speaking particularly on a platform like MS Windows or some Apple device. Since your more likely to lose crypto from an infection of some kind the hardware wallet should hinder that since the system itself doesn't have access to your private key.
Coldcard firmware: 48% Python. Scary.
https://www.youtube.com/watch?v=2X2V3xv_jik