Decisions were made about certificate revocation based on assumptions about this code and Akamai customers ended up being exposed.
Perhaps third-party security validation of such a critical piece of code should be a prerequisite before asserting that no further countermeasures such as key rotation were necessary. Such an action would demonstrate significant diligence as compared to a public release days after you've told customers there was nothing to worry about.
Additionally, that public release didn't directly encourage security review, the deprecating comments on the post were primarily around portability and design.