

As far as I can tell running xz directly should be fine, but for the extra paranoid check the version of the xz-utils
package. If it is safe, it will be either less than 5.6.0
, or it should be 5.6.1+really5.4.5-1
(xz 5.4.5
with a spoof version number to ensure compromised systems get the update).
Email subscriptions also sometimes have that, with bonus points for several vague and similar sounding categories, and emails not mentioning what category they’re in.