Richard Kirk, European Director of Fortify has penned a response to many of the rebuttals made on web to their report.
"The response to the report set off some familiar refrains, which miss the point and dont get us any closer towards the goal of a secure enterprise..."
Apparently Fortify is already in discussions with open source providers with whom it is working to improve processes and Richard has invited any open source groups to get in touch. But he mentions no names or whether there are any costs involved...