The bill specifically mentions open-source software, and given how broadly an 'entity' is defined, and open source project/library that has contributions from a citizen of a 'adversarial country' and has more than 1MM users could be affected by this bill if directed by the Sec.State or Executive
Section 5(a)(3)(c)
(a) Priority Information And Communications Technology Areas.—In carrying out sections 3 and 4, the Secretary shall prioritize evaluation of—
...
(3) any software, hardware, or any other product or service integral to data hosting or computing service that uses, processes, or retains, or is expected to use, process, or retain, sensitive personal data with respect to greater than 1,000,000 persons in the United States at any point during the year period preceding the date on which the covered transaction is referred to the Secretary for review or the Secretary initiates review of the covered transaction, including—
...
(C) machine learning, predictive analytics, and data science products and services, *including those involving the provision of services to assist a party utilize, manage, or maintain open-source software;*
Section 5(a)(3)(c)
(a) Priority Information And Communications Technology Areas.—In carrying out sections 3 and 4, the Secretary shall prioritize evaluation of—
...
(3) any software, hardware, or any other product or service integral to data hosting or computing service that uses, processes, or retains, or is expected to use, process, or retain, sensitive personal data with respect to greater than 1,000,000 persons in the United States at any point during the year period preceding the date on which the covered transaction is referred to the Secretary for review or the Secretary initiates review of the covered transaction, including—
...
(C) machine learning, predictive analytics, and data science products and services, *including those involving the provision of services to assist a party utilize, manage, or maintain open-source software;*