

I will try to answer these, and hope someone corrects any potential innaccuracy:
what’s red?
There is a comment there saying “see deep-dive for details” so the red-highlight caveat is likely explained there.
what’s the globe icon?
My assumption is that icon just indicates Free/Open-Source projects which have no “owning company” (not “based” anywhere), just globally scattered contributors.
how come some products marked not majority EU owned have the EU flag?
My guess (merely a guess) is that those are run by EU-based companies, but which don’t have a solid policy guaranteeing “majority of shareholders are in the EU” (…?)
I don’t know the details of that part directly, but I do remember reading things like this which seemed to indicate delisting of some maintainers (positions of responsibility, as opposed to blocking all developer contributions) who were associated with certain sanctioned Russian companies. This seems to be in line with standard sanctions being imposed by many companies & organisations in various countries (not just USA). Regardless of personal opinions about whether that was “right, wrong, or otherwise” at the time it at least seems a far cry from “an NSA compromise”.