Voices of Open Source: The European regulators listened to the Open Source communities! https://blog.opensource.org/the-european-regulators-listened-to-the-open-source-communities/
Open Source Entwickler doch nicht für Sicherheitslücken (etc) in ihrer Software haftbar wie kommerzielle Entwickler. Das war auch *extrem* weltfremd.
25 years ago, my mentor at uni showed me how to interrupt autoconfig runs at just the right time so the generated scripts that yielded wrong results wouldn't be deleted and we could check and fix them.
Today, a friend looks for just the right time to intercept Ansible Tower execution environments so he can debug the podman containers that yield wrong results and fail a deployment.
25 years of "progress" and we still run into the same terrible stuff.