I'm sure we've literally never written a vulnerable line of code in our lives, right?
Security reviews are part of a healthy SDLC. You catch vulnerabilities as part of security reviews as they would be totally unnecessary if people simply wrote perfect code to begin with.
For the better, if your attitude is the “healthy SDLC”.