Earlier quoted context omitted.
> The person who makes the software has the duty to fix the security issues in their own code, nobody else, no matter how big they are. That’s just clearly untrue for freely available software. So every person that ever published a hobby project on GitHub has a duty to fix security issues in it? The organisation who ships software to paying customer may have a duty to fix security issues. If they didn’t, it could be…
> That’s just clearly untrue for freely available software. So every person that ever published a hobby project on GitHub has a duty to fix security issues in it? Yes, i think there is a moral duty if you are presenting the software for the general public to use. Or if you dont to at least make it clear how you handle stuff so that users can make their own decisions. > But there’s no contract with the free software d…
It is up to you, the end user of the software to evaluate whether those terms, risks, and options are good enough for you. If not, don't use it. You have it completely backwards, and frankly, sound quite entitled.