Making commercial vendors who rely on open source software liable for bugs is fantastic news, that's how it always should have been. You can't have a commercial company throw their hands up and say "well github.com/cutefuzzypuppy is at fault for writing an open-source npm package we used so harm to our customers is not our fault!"
What will happen the opensource world once you're held liable for some moron who uses some software I wrote for myself? or incorrectly uses it?
do you really believe the curl should be held liable because some POST failed and a user lost something over it?
what about my old backup scripts? I need to remove them from my repos?
My reading of the text is that the one actually selling the software product is the one having to abide by this law. Am I incorrect?
How could this be negative? I presume that most publishers of open source software would prefer that some Silicon Valley Unicorn did _not_ half-heartedly integrate their library, causing security issues and tainting their library name?