While open source, it relies on binaries from other providers. Interestingly, while this has been a noted concern for a couple of years, only recently someone ran it through claude to see if it matched up with official binaries and it mostly does
https://github.com/ventoy/Ventoy/issues/3224#issuecomment-4627219120Even so, we're relying on both this guy and all of the other projects that he's relying on for these binaries not being compromised. It's a big attack surface with a huge payoff because of the access it provides to attackers.