However, if you build security critical software and get paid to do so it‘s not entirely unreasonable to require some sort of certification. You can‘t just build medical devices for money either without some sort of regulation. Or produce food for money. Or repair cars for money.
"THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, ...... "
It is on the user (or a third party certification authority) to accept any liability for the quality of the software.
> Limitation of consequential damages for injury to the person in the case of consumer goods is prima facie unconscionable
If so, I'd expect it to summarily obliterate the OSS world.
This would, however, not remain true if you're actually dealing with your users in a way that establishes mutual obligations (be careful you don't fall into a contract unawares!) Providing support for pay would do it, for example.
Libc, clang/gcc, whatever. Needs to be audited.
Perhaps they require the “integrator” to perform the audit or maybe the fact someone provides software which can be useful in critical environments is enough to signal an implied warranty and they are on the hook for compliance. Nobody knows until it all goes through costly legal procedures where everyone is trying to cover their asses and pass the buck.
I’m waiting for the day where FLOSS devs are greeted at EU airports by process servers because they released some software while in college and it got used in some critical software.
However, that declaration of purpose of course binds all other users/distributors of Linux, if they should dare to use or bundle it as a desktop, server or mobile operating system, they are doing so outside the original certification and need to have the required audit for critical software performed.
That, as far as I read it, also means that something like GCC, which is unambiguously a compiler, isn't critical and need not be audited, only self-certified, even if used to compile a critical software component.
The problem lies, among other things, in the fact that a business activity might be assumed even if one does not explicitly receive money for the software directly, but indirectly. For example via donations, ads on the download Web-site, using it for self-promotion, paid consultancy, selling tutorials, ...
secondary self-promotion, donations and ads are imho not "providing goods in a business-related context". Paid consultancy and selling tutorials might be though, But I assume that judges will rule on that if it comes to it and I assume that they will set some monetary boundary to which this still counts as "outside the course of commercial activity".
So if you have a permanent Website of your open-source product to promote some other product or service, or ask for donations or put ads on the site, you intent to make a profit out of your open-source product. (Almost?) every possible answer to the question: "How can I generate revenue with my open source project?" describes a business related context.