The problem is that they get away too easily with bugs in their products they ship to customers. If this would come with some penalties, there would be some incentive to invest in security and this would probably often flow back to upstream projects.
Like a money-back guarantee?
Like you get when you buy e.g. MS products?
/s
Seriously? You think that curl gets away with bugs shipping to prod? And that's the major problem?
I don't agree with any of that.