If you really care about the #xz #liblzma backdoor, the IMHO (In My Humble Opinion) best source of information is the FAQ at https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27 which gets continuous updates and keeps track of the fallout and ongoing work.
However — do not read the comments on that gist, as a lot of not-so-well informed but very motivated people try to add their .02.