Ask HN: Are OSS developers responsible for ensuring their code is secure?
But no one is paying them for doing so
There are even services that allow the detection of malpractices and provide free tiers for OSS projects, such as Sonarqube.
Obviously this is easier said than done when the OSS project is small and not used by many developers.