add xmltodict as tainted with alternative and update fastapi evidence (#1616)

### Description of Changes

* adds xmltodict as tainted
* update link: fastapi evidence

Reviewed-on: https://codeberg.org/ethical-foss/open-slopware/pulls/1616
Reviewed-by: Ethical FOSS admin <ethical-foss-admin@noreply.codeberg.org>
This commit is contained in:
hmn 2026-09-29 12:28:10 +02:00 • committed by Ethical FOSS admin
commit 4d9352fd57

View file

@ -2270,7 +2270,7 @@ Note that CPython is itself tainted; see [the Programming Languages section](#pr
| [charset\_normalizer](https://github.com/jawah/charset_normalizer) | [`3.4.9`](https://github.com/jawah/charset_normalizer/releases/tag/3.4.9) <br /> [`cc68407`](https://github.com/jawah/charset_normalizer/commits/cc6840753f17f00dea4e339ce37507747217e916) | [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/jawah/charset_normalizer/commit/667b93c9243cc650354562b871fcfcc35282fe97)) | [![Request for Help](./badges/request-for-help.svg)](#request-for-help) |
| [`cryptography`](https://github.com/pyca/cryptography) | [`44.0.0`](https://github.com/pyca/cryptography/releases/tag/44.0.0) | [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/pyca/cryptography/blob/main/AGENTS.md), [2](https://github.com/pyca/cryptography/commit/ce7f263d2b5492222497966e4132010caf650a70), [3](https://github.com/pyca/cryptography/commit/62d0783211a329c5d1d27b52c527a245e9bc842b)) <br /> [![AI Code Reviews](./badges/ai-code-reviews-purple.svg)](#ai-code-reviews) ([1](https://github.com/pyca/cryptography/pull/12976), [2](https://github.com/pyca/cryptography/pull/13137), [3](https://github.com/pyca/cryptography/pull/12937)) | [PyCryptodome](https://github.com/Legrandin/pycryptodome) |
| [Django](https://github.com/django/django) | [`5.2.9`](https://github.com/django/django/releases/tag/5.2.9) <br /> [`1820d35`](https://github.com/django/django/commits/1820d35b17f0a95f4ce888971b9ca0c7a3697c83) | [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/django/djangoproject.com/blob/main/djangoproject/templates/conduct/index.html#L490C11-L530), [2](https://github.com/django/django/pull/20568), [3](https://github.com/django/django/pull/20699)) <br /> [![AI Code Reviews](./badges/ai-code-reviews-purple.svg)](#ai-code-reviews) ([1](https://github.com/django/django/pull/20471), [2](https://github.com/django/django/pull/20811)) | [Flask] [![Anti-AI Policy](./badges/anti-ai-policy.svg)](#anti-ai-policy) ([1][pallets-policy]) |
| [FastAPI](https://github.com/fastapi/fastapi) | [![Request for Help](./badges/request-for-help.svg)](#request-for-help) | [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/fastapi/fastapi/commit/31bbb380748ccead62fc0f42dbf4273f11dadccf), [2](https://github.com/fastapi/fastapi/commit/faee822574d3c202123f48eb09b9bd207385335b)) <br/>![AI sponsored](./badges/ai-sponsored-blue.svg) ([CodeRabbit](https://github.com/fastapi/fastapi#gold-sponsors)) | [Flask] [![Anti-AI Policy](./badges/anti-ai-policy.svg)](#anti-ai-policy) ([1][pallets-policy]) |
| [FastAPI](https://github.com/fastapi/fastapi) | [![Request for Help](./badges/request-for-help.svg)](#request-for-help) | [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/fastapi/fastapi/commit/31bbb380748ccead62fc0f42dbf4273f11dadccf), [2](https://github.com/fastapi/fastapi/commit/faee822574d3c202123f48eb09b9bd207385335b)) <br /> [![AI sponsored](./badges/ai-sponsored-blue.svg)](#sponsored-by-ai) ([1](https://github.com/fastapi/fastapi/blob/master/README.md#gold-sponsors)) | [Flask] [![Anti-AI Policy](./badges/anti-ai-policy.svg)](#anti-ai-policy) ([1][pallets-policy]) |
| [isort](https://github.com/pycqa/isort) | [`8.0.0`](https://github.com/PyCQA/isort/releases/tag/8.0.0) | [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/PyCQA/isort/pull/2459), [2](https://github.com/PyCQA/isort/pull/2471), [3](https://github.com/PyCQA/isort/pull/2470)) <br /> [![AI Code Reviews](./badges/ai-code-reviews-purple.svg)](#ai-code-reviews) ([1](https://github.com/PyCQA/isort/pull/2509), [2](https://github.com/PyCQA/isort/pull/2516), [3](https://github.com/PyCQA/isort/pull/2503)) <br /> [![AI sponsored](./badges/ai-sponsored-blue.svg)](#sponsored-by-ai) ([1](https://github.com/PyCQA/isort/blob/main/README.md#why-isort)) | [![Request for Help](./badges/request-for-help.svg)](#request-for-help) |
| [JupyterLab](https://github.com/jupyterlab/jupyterlab) | [`v4.5.6`](https://github.com/jupyterlab/jupyterlab/tree/v4.5.6) | [![AI Functionality](./badges/ai-functionality.svg)](#ai-functionality) ([1](https://github.com/jupyterlab/jupyter-ai)) <br /> [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/jupyterlab/jupyterlab/blob/main/AGENTS.md)) | Possibly GNU Emacs ([1](https://www.danliden.com/notes/20241112-python-setup.html), [2](https://blog.serghei.pl/posts/emacs-python-ide/)) |
| [Pygments](https://github.com/pygments/pygments) | [`2.19.2`](https://github.com/pygments/pygments/commits/2.19.2/) | [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/pygments/pygments/pull/3038)) | [![Request for Help](./badges/request-for-help.svg)](#request-for-help) |
@ -2289,6 +2289,7 @@ Note that CPython is itself tainted; see [the Programming Languages section](#pr
| [ty](https://github.com/astral-sh/ty) | [![Request for Help](./badges/request-for-help.svg)](#request-for-help) | [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/astral-sh/.github/blob/main/AI_POLICY.md), [2](https://github.com/astral-sh/ty/commit/065338a1fcc24ac5b974724dbb5d8a3ab740c5b7)) <br /> [![AI sponsored](./badges/ai-sponsored-blue.svg)](#sponsored-by-ai) ([1](https://astral.sh/blog/openai)) | [![Request for Help](./badges/request-for-help.svg)](#request-for-help) |
| [Typer](https://github.com/fastapi/typer) | [`0.25.1`](https://github.com/fastapi/typer/releases/tag/0.25.1) | [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/tiangolo/tiangolo.com/blob/master/docs/open-source/contributing.md#automated-code-and-ai), [2](https://github.com/fastapi/typer/pull/1623), [3](https://github.com/fastapi/typer/pull/1690)) | [`argparse` (Python Standard Lib)](https://docs.python.org/library/argparse.html) <br /> [Click](https://github.com/pallets/click) [![Anti-AI Policy](./badges/anti-ai-policy.svg)](#anti-ai-policy) ([1][pallets-policy]) |
| [uv](https://github.com/astral-sh/uv) | [![Request for Help](./badges/request-for-help.svg)](#request-for-help) | [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/astral-sh/.github/blob/main/AI_POLICY.md), [2](https://github.com/astral-sh/uv/blob/main/AGENTS.md), [3](https://github.com/astral-sh/uv/commit/bd2e0c9b09551c6570b14c4da80364fe90805b78)) <br /> [![AI sponsored](./badges/ai-sponsored-blue.svg)](#sponsored-by-ai) ([1](https://astral.sh/blog/openai)) | [![Request for Help](./badges/request-for-help.svg)](#request-for-help) |
| [xmltodict](https://github.com/martinblech/xmltodict) | [`v1.0.0`](https://github.com/martinblech/xmltodict/releases/tag/v1.0.0) <br /> [`f8c60ef`](https://github.com/martinblech/xmltodict/commits/f8c60ef48c604097da3187dc43d7a05a5aaad6b3) | [![Permissive AI policy](./badges/permissive-ai-policy-orange.svg)](#permissive-ai-policy) ([1](https://github.com/martinblech/xmltodict/blob/master/AGENTS.md), [2](https://github.com/martinblech/xmltodict/pull/393), [3](https://github.com/martinblech/xmltodict/commit/966b903e4441f27816cd39ecf3305727b294a9c5)) | [lxml](https://github.com/lxml/lxml) <br /> [`xml.etree.ElementTree` (Python Standard Lib)](https://docs.python.org/library/xml.etree.elementtree.html) |
### Ruby