I don't think you thought this through.
does this also apply to individual developers?
should Linux Torvalds or the ffmpeg developers go to jail if they merge a RCE zero-day into the Linux kernel or into ffmpeg?
gross negligence / honest mistake
if you cannot differentiate the 2, :insert rude thing here:
gross negligence / honest mistake
if you cannot differentiate the 2, :insert rude thing here: