I don't think it's the death of open source, but it shows how the economics of open source turned into a tragedy of the commons, with maintainers not being provided the resources needed to sustainably operate projects.
It also is an admission of how organizations never prioritized security for decades both within engineering and organizationally, but that's a separate conversation that HNers are not equipped to discuss looking at the lacking calibre of conversations on here.
If OSS lovers actually care, then they need to put their money where their mouth is, stop being idealistic, and think about either going open core or getting formalized funding and sponsorship. Adopting much more restrictive licenses that also allow commercialization by project owners is also critical. The majority of GNU style project that exists on the goodwill of a couple of ideologically aligned individuals will not survive, becuase contributors also need to be paid.
Edit: can't reply
> What do you mean by that? They can't possibly stop using Linux/Kubernetes/Chrome (including Edge)/almost all programming languages/nginx/...
Meaning they will freeze all dependencies and libraries being used going forward, and will not release source code until end-to-end vuln remediation can be done within 24 hours.
Teams are also seriously considering forking core projects and dependencies to use in-house and not contribute upstream out of fear that upstream contributions could be tainted or introduce additional vulnerabilities.