It's also easier to share vulnerability fixes between different projects.
"Y" was using a similar memory management as "T", T was hacked due to whatever, people that use Y and T report to Y that a similar vulnerability might be exploitable
Edit:
In closed source, this might happen if both projects are under the same company.
But users will never have the ability to tell Y that T was hacked in a way that might affect Y
It's hidden for users. Try
sudo ./exploit