Date 2023-09-30
discusses using lxml as replacement for defusedxml as defusedxml had no updates
in two years untill two days ago 8-).

lxml also has a faq for security issues:

but an item lower in the faq references defusedxml as a wrapper for lxml.

defusedxml 0.8.0b was released on 9/28/2023. So looks like defusedxml with a
system supplied libexpat of 2.4.0 or newer is the best route. This means
python 3.7 or newer for the newer libexpat IIUC.
