There’s very much a case being made that open source maintainers should have near-zero concerns because “they are codified best practices”; “we aren’t going to invent any new things”.
I want to be optimistic (yay, we’re already there!) but boy the decades-long, near-totally-failed push for SBOM adoption—which is being cited as a success!—does not fill me with optimism.