Proton should be responsible no matter it uses the third-party open-source/propriety components or not.
If they decide to use third party libraries, that's their responsibility to review those libraries and include them to their code base.
Not "it's not my fault; it's others fault"