I got the first interpretation, but I think yours is what we should be talking about. The responsibility for this bug is not on the maintainer, more so on the company for accepting it into their codebase without any vetting.

