Why is everyone up in arms about this?
The legislation specifically excludes open source software. Has nobody in this discussion actually read the proposed legislation?
From the current proposal legislation text:
In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable.
There is also a clause that states those using open source software in commercial products must report any vulnerabilities found to the maintainer.