Linux workstation

Upstream software project

defusedxml

XML bomb protection for Python stdlib modules

About defusedxml

XML bomb protection for Python stdlib modules

This project links 10 native package records across 7 recorded operating-system releases. Compare the retained versions and architectures below, then open the package for your own release.

These are catalog observations, not a guarantee of installation, compatibility, or upstream support.

Project pictures and package coverage

defusedxml repository preview from GitHub
Project repository preview, supplied by GitHub. Open source repository
Alpine Linux 3.21: 2 package records; Alpine Linux 3.22: 2 package records; Alpine Linux 3.23: 2 package records; Debian 12 (Bookworm): 1 package records; Debian 13 (Trixie): 1 package records; Fedora 43: 1 package records; Fedora 44: 1 package records. Catalog coverage diagram, not an application screenshot.defusedxml: recorded package coverageAlpine Linux 3.212 recordsAlpine Linux 3.222 recordsAlpine Linux 3.232 recordsDebian 12 (Bookworm)1 recordsDebian 13 (Trixie)1 recordsFedora 431 recordsFedora 441 records
OpenFactory diagram of linked package records. It is not an application screenshot.

Project identity

Project
defusedxml
Publisher
Not authoritatively mapped
Native package records
10
Operating systems
alpine-linux-3-21, alpine-linux-3-22, alpine-linux-3-23, debian-12, debian-13, fedora-43, fedora-44
License expression
Python-2.0
Metadata completeness
70/100 (not a software quality rating)
Source repository
Open source repository

Source-reported description

The fullest retained description is shown with its source. Distribution packaging descriptions may include downstream details.

The defusedxml package contains several Python-only workarounds and fixes for denial of service and other vulnerabilities in Python's XML libraries. In order to benefit from the protection you just have to import and use the listed functions / classes from the right defusedxml module instead of the original module.

Description source

Packages by operating system

Compare recorded versions, then open a package for dependency, file, checksum, and repository evidence. Version strings are distribution-specific, not a ranking of newer software.

Alpine Linux 3.21

  1. py3-defusedxml

    Alpine Linux 3.21 / source py3-defusedxml

    0.7.1-r5

    XML bomb protection for Python stdlib modules

    aarch64x86_64v3.21
  2. py3-defusedxml-pyc

    Alpine Linux 3.21 / source py3-defusedxml

    0.7.1-r5

    Precompiled Python bytecode for py3-defusedxml

    aarch64x86_64v3.21

Alpine Linux 3.22

  1. py3-defusedxml

    Alpine Linux 3.22 / source py3-defusedxml

    0.7.1-r5

    XML bomb protection for Python stdlib modules

    aarch64x86_64v3.22
  2. py3-defusedxml-pyc

    Alpine Linux 3.22 / source py3-defusedxml

    0.7.1-r5

    Precompiled Python bytecode for py3-defusedxml

    aarch64x86_64v3.22

Alpine Linux 3.23

  1. py3-defusedxml

    Alpine Linux 3.23 / source py3-defusedxml

    0.7.1-r5

    XML bomb protection for Python stdlib modules

    aarch64x86_64v3.23
  2. py3-defusedxml-pyc

    Alpine Linux 3.23 / source py3-defusedxml

    0.7.1-r5

    Precompiled Python bytecode for py3-defusedxml

    aarch64x86_64v3.23

Debian 12 (Bookworm)

  1. python3-defusedxml

    Debian 12 (Bookworm) / python / source defusedxml

    0.7.1-2

    XML bomb protection for Python stdlib modules (for Python 3)

    allbookworm

Debian 13 (Trixie)

  1. python3-defusedxml

    Debian 13 (Trixie) / python / source defusedxml

    0.7.1-3

    XML bomb protection for Python stdlib modules (for Python 3)

    alltrixie

Fedora 43

  1. python3-defusedxml

    Fedora 43 / Unspecified / source python-defusedxml

    0.7.1-22.fc43

    XML bomb protection for Python stdlib modules

    noarch43

Fedora 44

  1. python3-defusedxml

    Fedora 44 / Unspecified / source python-defusedxml

    0.7.1-23.fc44

    XML bomb protection for Python stdlib modules

    noarch44

Project resources and further reading

Mapping provenance

Only source-backed identity signals create public cross-OS links. A reviewer can later approve or dispute an inferred relationship without rewriting native package history.

No field-level source record is published yet.