It used to say that, it was removed as a PR measure, while in practice the national implementations (as you do not use this app, but a national one) require it, because the specification only mandates Android/iOS versions to be provided (it allows others, but no government will do so), and it does not mandate them not to have "attestation".
This entire issue is a disaster of a Github issue. It looks like its on the entirely wrong repository. I did eventually find the text in another repository; the one for the Android reference implementation: https://github.com/eu-digital-identity-wallet/av-app-android...
It was removed from there to clarify the entire "Hey, this application is not done yet"
It being in the reference implementation instead of the spec is a massive difference. One means that it's just there to show an example, and we should push national governments to do it better in their implementations, while the other would mean that it'd be a requirement for all implementations, which it doesn't appear to be.
In my opinion the whole "it's just a reference and national govs can decide" is a nonsense excuse to diffuse blame in a circle. The only outcome is that national governments will closely follow the reference and reuse the decision, the citizens of each country then have to manually complain to their own government individually, at which point they might get ignored because, well the reference implementation has it or talks about it, so they're just following the recommended security requirements, and who are you anyway to be demanding our system get less secure are you some kind of cybercriminal?
Honestly, root detection is a cat and mouse game. So many ways to spoof it. Same with Play Integrity. If the goal is to prevent bad actors, it will never work really. It will be just a big headache for the citizens. Look at how gatekeeping certain websites is working. VPNs became mainstream. So are proxies too especially for bad actors. Malicious actors have just to pay up a service to do so. And I am sure it will be the same with Android (it already is with keyboxes you can purchase to spoof play integrity)
From what I can gather from the linked discussion it was started as a pull request or a issue and was transferred to a discussion later. Perhaps some data was lost there? If you expand the comments fully there is also mention of a nuked merge request, I assume it was related to this text.
Edit it was not visible from the discussion link but it is visible from the issue link below. Also it seems to be transferred over from a totally different repo?