My reading of the text is that the one actually selling the software product is the one having to abide by this law. Am I incorrect?
How could this be negative? I presume that most publishers of open source software would prefer that some Silicon Valley Unicorn did _not_ half-heartedly integrate their library, causing security issues and tainting their library name?