For the library to be secure, there needs to be funding, not by magic and expecting maintainers will do stuff on there free will.
The assumed base state we're looking to augment via open source software being: "Fully working software"(Augmented: free) vs "No software" (Augmented: yes software)?
Like, what you seem to want is business, plain and simple. Pay a guy, have your specs filled, get guarantees. That would be expecting open source to fill a role it just isn't made for.
And it leads to unmaintained libraries, since companies don't want to pay.
At some point, is open sourcing your work a liability?
And then they can shrug and move on with their respective days. If I open source something it's a gift to the commons, not a promise to work on it for free in perpetuity. I don't really care if someone tries to shame me for that, as there's nothing to be ashamed of.
Maybe you're overloaded, maybe you just don't feel like it. It's totally normal, and different projects have different levels of resources, some with none anymore.
My main concern is supply chain compromise.
That said, everything in my previous post still applies: a nonzero buglist is totally normal and widely accepted.
I argue that open sourcing your work is no more liable than making a comment on social media. The biggest risk to an open source maintainer is publicly losing their patience and/or being heterodox in their beliefs. Code isn't a requirement for that to happen.