I feel like there should be a warning in Doc/library/xml.rst too.

Is there any actual reason why we don’t ship defusedxml with Python and add an easy way to monkeypatch so there’s as little passive barriers as possible to use XML “safely”?

I’m sorry I didn’t speak up on when this was discussed on the ML but I found the discussion…depressing.
