You are not buying from a supplier, you are a raccoon digging through dumpsters for free code.
This is such a good post, and really gets to the heart of why I rather have lost the idealism for FOSS software.
People, who mostly have a vested interest in getting a lot of work for free, keep talking about FOSS devs "responsibilities", as if they're somehow being paid to do this work ... and they're not.
Yeah a few startups occasionally throw a bone to a dev or two, maybe if you're lucky, the lead maintainer gets hired somewhere and paid to keep working on it ... but mostly it's not.
You don't get to be mad at a developer for not doing the thing you wanted them to do, when you weren't even paying them to do it in the first place. It's like bitching that there wasn't enough change in the take-a-penny tray to pay for your groceries.
I am sympathetic to the concerns people have, the panic that one of these vulns or package disasters induce but what did you expect? The community at this point has produced truly eye-watering amounts of free labor, enough that a whole billion or even trillion dollar industry was built on it, and you want what? Even more?
It's all some kind of perverse prisoner's dilemma, every conversation gets framed around "but will Giant Corporation™ use it if ...?" and the like and ... why do we care? Because we each know our own jobs also depend on all that free labor. We're scared to question the monster we've created because our livelihoods depend on not doing so, and thus driven to just keep demanding free labor from each other.
FOSS has been twisted from some weirdo's quasi-left-libertarian manifesto into one of capitalism's most devious tricks, literally convincing all of us to exploit each other, so they don't have to. The guy who gave the big talk about "software supply chain" at StrangeLoop this year literally works for Google and sits on the board of a Linux Foundation subsidiary.
They have played us all for fools.
