This article points out that this doesn't just apply to companies. If you maintain an open-source project and accept donations, then you're potentially affected as well.
Adoption of open source, most open source licenses already come with broad waivers so compliance would fall mostly on the adopters.
that's not how the act works, sorry.
Article 6, Numeral 2 "In determining the level of cybersecurity risk, one or several of the following criteria shall be taken into account" seems very reasonable in scope and wouldn't include most open source/free software.