Two new high-severity Dependabot alerts are open after the prior website advisory remediation:\n\n- GHSA-w3rx-r6r6-pgpr: ICNS parser infinite-loop denial of service\n- GHSA-5p2g-fcmc-qvqq: JXL and HEIF parser infinite-loop denial of service\n\nCurrent dependency path: @docusaurus/core@3.10.2 -> @docusaurus/mdx-loader@3.10.2 -> image-size@2.0.2 in website/package-lock.json. GitHub currently reports no first patched version for either alert. The exposure is build-time parsing of documentation images rather than the shipped Dart runtime, but repository contributions can supply image inputs, so keep this P1 open until the dependency is fixed or safely constrained.\n\nAcceptance criteria:\n- update to a non-vulnerable image-size version through an upstream Docusaurus release, override, or narrowly justified replacement;\n- preserve locked website install, production docs build, link validation, and deterministic formatting;\n- verify both Dependabot alerts close without introducing a dependency downgrade or audit regression;\n- if no fixed version exists, document the trust boundary and monitor the advisories rather than suppressing them.
Two new high-severity Dependabot alerts are open after the prior website advisory remediation:\n\n- GHSA-w3rx-r6r6-pgpr: ICNS parser infinite-loop denial of service\n- GHSA-5p2g-fcmc-qvqq: JXL and HEIF parser infinite-loop denial of service\n\nCurrent dependency path: @docusaurus/core@3.10.2 -> @docusaurus/mdx-loader@3.10.2 -> image-size@2.0.2 in website/package-lock.json. GitHub currently reports no first patched version for either alert. The exposure is build-time parsing of documentation images rather than the shipped Dart runtime, but repository contributions can supply image inputs, so keep this P1 open until the dependency is fixed or safely constrained.\n\nAcceptance criteria:\n- update to a non-vulnerable image-size version through an upstream Docusaurus release, override, or narrowly justified replacement;\n- preserve locked website install, production docs build, link validation, and deterministic formatting;\n- verify both Dependabot alerts close without introducing a dependency downgrade or audit regression;\n- if no fixed version exists, document the trust boundary and monitor the advisories rather than suppressing them.