A cautionary tale here: when you are testing, if you mock out even low-level I/O utilities, you’re vulnerable to those utilities changing specification subtly. You can supply-chain attack yourself by simply updating a library.
Full filesystem/service-engaging integration tests are helpful but far from exhaustive - here, one wouldn’t have just needed to read the cropped file using standard display systems and count the pixels, but hash the underlying file in its entirety.
For critical libraries in an I/O pipeline, encourage team members to read CHANGELOGs - both before choosing a library to make sure they’re maintained, and closely when even doing a minor upgrade.