I've requested access to the code, but have not yet heard anything back.
It is clear that it is going to get more complicated for MG as the public info will be raising additional questions.
- Questions will be raised about the age of some of the software, but 'security' issues are limited by the fact that MG has never made the MG4 that open. Without software interfaces (such as the one Octopus Energy would like to have) issues with older code can not easily be exploited by a third party.
- They are using a few products that are licensed under the GPL terms. These are interesting as all derivative works have to be then released, so if you used GPL code in a product, where the GPL code gets incorporated into the wider code, all the code then becomes GPL licensed.