ART-imageio pins the old version of pillow_heif, as newer ones apparently don't work for HDR. But cybersecurity auditors don't know that and barf at anything pinned to an old version. Due to this pin, Arch AUR packages do not include the HEIF saving functionality.
Please add a comment stating the rationale for the pin, and whether it is a genuine bug in newer versions of pillow_heif or ART-imageio should be ported.