they do static analysis, including a “am I really affected by this cve?” analysis by looking at if you’re calling the offending code.