hi all Leaving aside the questions of dependencies of other Debian packages, I agree that 5.2.5 looks like the most recent version that is definitely free of any directly or indirectly authored contributions by Jia Tan.
https://salsa.debian.org/debian/xz-utils/-/tree/v5.2.5?ref_type=tags In the salsa full source: $ git checkout v5.2.5 Previous HEAD position was d24a57b7 Bump version and soname for 5.2.7. HEAD is now at 2327a461 Bump version and soname for 5.2.5. $ git log --stat --graph |grep "Jia" # No sign of Jia Tan. $ git checkout v5.2.6 Previous HEAD position was 2327a461 Bump version and soname for 5.2.5. HEAD is now at 8dfed05b Bump version and soname for 5.2.6. $ git log --stat --graph |grep "Jia" |wc 16 129 774 # Two commits and several 'Thanks to ... '. Cheers Boud PS: For any RedHat people reading this thread: unfortunately, 5.2.5 is before the fix 31d80c6b that Lasse Collin did to handle the "ill patch" introduced by RHEL/CentOS7: https://salsa.debian.org/debian/xz-utils/-/commit/31d80c6b261b24220776dfaeb8a04f80f80e0a24 That's a RHEL problem to handle, not a Debian problem.