"If open source resources are in/called/touched your code, you’re responsible for their performance too. The open source resource licensed away their liability to you."
This is the norm. The private company holds responsibility for vetting everything they ship.
It's a speculation on how the law will be enforced for a law with no history and I don't see why you would assume the worst interpretation