Earlier quoted context omitted.
Finding vulns in popular OSS and disclosing is probably good for your reputation as a security researcher, even if it's not immediately profitable.
How is that sustainable? Are security researchers going to be doing free labor for you indefinitely for exposure?
I’d never heard of socket until they found and reported shai hulud hiding in pytorch lightning. It pays off.