This might change, partly in response to this case: https://www.gov.uk/government/calls-for-evidence/use-of-evid...
Quite interesting article about this: https://www.counselmagazine.co.uk/articles/the-presumption-t...
When these sorts of things happen, the source can be subpoena'd with the relevant legal tool, and reviewed appropriately.
Why governments don't do this is beyond me. It greatly limits liability of gov procurement, and puts the liability on the companies selling such goods.
Why are the vendors so incentivized? Well, coming back to Fujitsu and the Post Office, the answer is that refusing to share the source was worth about a billion dollars: https://www.bbc.co.uk/news/articles/cgm8lmz1xk1o