There are times when a feature is used in a way which was not intended by the developers. Now do the developers have to publish their test scenarios?
What if the bug is in 3rd party library? Add to it the complexity of open-source code.
There are times when a feature is used in a way which was not intended by the developers. Now do the developers have to publish their test scenarios?
What if the bug is in 3rd party library? Add to it the complexity of open-source code.
It will probably be similar to when a physical product is defective because of a faulty 3rd party component.
More importantly, as a professional software developer, the testing of my product should find problems in 3rd party components. If I chose poorly and the 3rd party component doesn't do what it's supposed to do, that's my responsibility. I can't just slough it off onto someone else.
Does that mean that say a security vulnerability in openssl is a responsibility of all software which uses them? I think its unreasonable to expect software projects/products to find things like heartbleed.
What about bugs in kernel/OS? How many user-mode software can find bugs in kernel/OS?
BTW: Software vendors find bugs in the OS all the time.
Why do directives even exist? Because the legal landscape can be widely different between EU countries. Directives give every country flexibility in implementing them in a way that is consistent with the way their laws work, existing precedents, etc. The downside is obviously that the implementations will somewhat differ from country from country.
This means that unless the implementations between countries are fairly consistent, the definition of what working as intended means will vary from country to country.
It's not a bad first approximation to expect courts in EU to very sensible and fair.
I think the vendor will need to be a lot more clear about what the supported use case is; and what use cases aren't supported.