The law is not geared towards "just putting some software on a server and calling it open source" which is what most projects do. It is geared as far as I understand towards bad IOT devices, among others. People sell them and know outright that there are existing vulnerabilities, and that rightfully should be illegal.
I think (maybe after some adjustments) this will be a boon to open source. Because every company shipping a program or a physical product with some GPL or MIT source inside will now be forced to bring it up to good quality before making money out of it. And at least in case of GPL, it is likely it will be contributed back to upstream. (I personally prefer upstreaming all open source code even when not required to share it, because you don't have the burden of maintaining a fork, and you have a better relationship with the developers in case you need to incorporate new features.)