The only thing required for you to make something FOSS is to make the code public with a FOSS-compatible license. Your responsibility as the author ends there, unless you take it further yourself. You don't owe anyone bugfixes or implementing new features. If they want those, they can implement them yourself.
I don't think it's really morally wrong to just walk away. No different than if you got hit by a bus.
On the other hand, you maybe did create something that people now depend on and walking away is probably causing a lot of anxious moments, possible security breaches, and downtime.
Not sure of the right answer. You did something for free. But shutting everything down one day can cause harm.
This is the mistake of the people who depend on something out of their control, not the person who made some code public, with the promise that there is no warranty, the software is "as-is" and more, which is fairly common in FOSS licenses.
The right answer is for people to start understanding the license of the things they use and depend on, and if "no warranties what so ever" isn't good enough for them, it's up to them to find a project using a license they do agree with.
If we rely on them so heavily that it'll affect our finances significantly, I'm sure the contract has plenty of penalties if we don't get that support.
But yes, for small one off deals, you could be screwed. And guess what - it's still your job to fix it, just as with open source. Your employer cares for the end results. They expect you to say "OK, vendor X screwed us. Here is plan B."
In the context of FOSS, it's almost always given away "as-is" without any sort of warranties or guarantees. If people end up shooting themselves in the foot even with those warnings, it's hard to feel sad for them.
Yes, those remedies are pretty much non-existent for an open source project but you seem to be making a case that no one should ever use unsupported open source for anything important given how risky it is. There have certainly been companies that would be happy to take that side. I don't personally but you should go in with eyes wide open.
Depends on the country. The countries I've lived in (Spain & Sweden) both have "Small claims court" which you (as a individual) can go through for relatively speedy (and free) resolutions to minor things, and avoids the traditional (slow) court procedures. This might be EU wide, not sure.
> you seem to be making a case that no one should ever use unsupported open source for anything important
No, I'm trying to make the case that people and businesses need to be more aware of what the license of the software they're using, is under.
If the software license says "THE SOFTWARE IS PROVIDED AS IS WITHOUT WARRANTY OF ANY KIND" but you need some sort of warranty, then either find an entity willing to provide that for this specific piece of software, chose another project, or fork it and provide your own warranty yourself.
>but you need some sort of warranty, then either find an entity willing to provide that for this specific piece of software, chose another project, or fork it and provide your own warranty yourself.
Totally agree with this though. As someone who worked for a commercial open source vendor for a number of years, if you're dependent on Linux, Kubernetes, etc. for your business you should have a commercial subscription.
>or fork it and provide your own warranty yourself.
Realizing you're now on the hook to do your own development/support ad infinitum which is usually a bad idea.
Security breaches and downtime are the responsibility of people using the SW - not of the developers.
I rely on a lot of open source libraries for my job. It's 100% my responsibility to pick libraries that I think are well maintained, and find alternatives when there are important bugs that aren't being fixed (that I myself cannot fix).
I really could care less about some corporation's security. If some company being cheap enough to use my software without compensation or testing has it open their systems to people without proper corporate authorization, I see that as a plus. I release software as is, and if they want to try to get blood from a stone and sue me any how, so be it.
So what?
There is NO WARRANTY, to the extent permitted by law.
Spreading yourself thin because of some imagined responsibility you're not compensated for causes even more harm. The whole point of FLOSS is to provide everyone enough freedom to let them care about the stuff they use themselves.
Having a project that is all mine, and not being limited by managers, is really important. If I want to learn a new technology, I just write a library to support it [0 - 1].
If it takes off, I find some folks that would be interested in running it, and hand it over to them. I don't really mind, however, if my stuff never gets any GH stars. I write software for myself.
That's fine. Not everyone has to do OSS. It's similar to volunteering for charity (weak analogy).
Many OSS projects have a community around them that help each other, talk about things, and are cool places to learn about specific things. Of course many used to, and they do not anymore. Things do change over time and that's OK as well.