1. the scope of the known backdoor is very constrained to only be inserted into native OS packages. As such, I don't think we need every other user of liblzma to post blog posts that they are not vulnerable independently of which version they embed. This is at best noise and at worst dangerous because
2. the bad actor has been submitting patches to liblzma for much longer than the 5.6 release and given the ingenuity of the attack, it's too early to claim that a project is not vulnerable to backdoors simply because there might already have been other "presents" left by the threat actor.
Given these two points, I really believe we should not be posting "hey we are not vulnerable" blog posts here because at best they are useless noise (nobody aside of debian or redhat and their downstreams is vulnerable) and at worst false assurances.