That’s not why. It’s the dependency trees that run a dozen layers deep and end up importing “isEven”. If you’re building a react app odds are good you’ll import way more code than you ever write yourself.
And no one should be leaving commented-out code in their app, that’s what source control is for.





Important to note these CVEs are from 2024, and from older versions of iOS and Android. I’m confused why it has today’s date.
Looks like, for Android at least, it was fixed (I didn’t check for iOS)? https://source.android.com/docs/security/bulletin/2024-11-01