オ, xzのオリジナル開発者からの声明ある. https://tukaani.org/xz-backdoor/
> Tarballs created by Jia Tan were signed by him. Any tarballs signed by me were created by me.
> Only I have had access to the main tukaani.org website, git.tukaani.org repositories, and related files. Jia Tan only had access to things hosted on GitHub, including xz.tukaani.org subdomain (and only that subdomain).
まあ重要なのはここぐらいかしら…