To illustrate my point, let us consider the case of Net-SNMP which was one of the projects I had direct experience with back then. We had the entire source code of Net-SNMP checked into our own project repository. From that point on, it was our responsibility to understand/maintain/update/upgrade/patch/customise the code (at least the parts that we relied on). When something didn't work the way it was supposed to, it was one of the employer's developers responsibility to figure out how to make it work. If needed, sometimes we would even engage with the community around the project in their IRC channels or mailing lists, to figure out how to solve our problems and sometimes such engagement might even end up benefitting both the community and us.
But at no point there was the notion of a supplier or "they" or "them". It was always "we". We decided to take this gift called Net-SNMP. We decided to use it develop our software. So it was now our responsibility to keep it in good shape. After all, the employer's developers were getting paid for it.
Now I know in today's world of software engineering, it is no longer possible to tend to every single dependency that is pulled into a project. There are thousands and thousands of them in every project. The way software engineering is done today is vastly different from how it was done a decade or two ago. There has been a Cambrian explosion of programming languages, open source software, frameworks, ecosystems, etc. It is impractical to assume the ownership of the thousands of dependencies that get pulled into every project and I think this is why the notion of "they" or the mythical "supplier" implicitly creeps in. While this rising complexity has resulted in increased speed and agility of software development, we have lost the simplicity and clear sense of ownership of code we rely on, which I believe was more prevalent a decade or so ago.