"A little less than a year after the publication of [blog post], we have therefore found a compromise letting us to respect both the obligation to publish the source code and the security constraints of DGFiP.
In letting us publish the code on their site and accessing confidentially the source code they didn't want published, the DGFiP let us find alternative solutions that made the publication of the source code concrete and operational.
This compromise lets both parties come out on top, unlike what happened with the source code of CNAF [link] where the administration simply argued a too-important difficulty and indefinitely postponed [1] it.
Letting those who ask for the source code to see it after a NDA therefore appears to be a possible solution when the publication is delicate for technical reasons. Could this path be useful for the report of @ebothorel?"
[Note: translation here is somewhat more geared towards a natural English translation than a literal French translation.]
[1] "repouss[er] [...] aux calendes grecques" appears to be an idiom that's not in my dictionaries, but from context appears to mean "indefinitely postponed"