Is there legal liability for making that change, even when the license says NO WARRANTY including for FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT? It's not even like the developer even delivers the software to anyone else.
Or is it only social standing? If so, I think $2 million would be enough to retire on.
It would seem that this attack vector is relevant for supply chain management. How is it currently evaluated and managed?
Also, at 8:27 (https://youtu.be/6H-V-0oQvCA?t=507), "Supply chain security has to be an industry-wide effort."
Would an unpaid FOSS developer, perhaps doing this as a retirement hobby, really be considered a part of industry? (For example, a statistician who continues to develop and distribute some very useful analysis software developed over her career, simply because she is interested in the approach.)
If so, what if they refuse to follow the demands of for-profit corporations demanding a SBOM and reproducible builds? If not, what should companies should they depend on that FOSS software?