Reporting a Vulnerability in Somebody Else's Code
A vulnerability in an open-source library inside your product is your vulnerability to report. The duty follows the product to market rather than the code to its author, so integrating somebody else's component transfers the obligation to whoever ships it. The reporting is the visible half. The harder consequence is that the same regulation requires remediation across the product in its entirety, and the party who wrote the component may have no obligation to help you.