Two suggestions
1) PUC Lua could have a lua-announce (lua-a) list which vendors could
subscribe to for announcements, including security announcements. This is
even better than having a big warning on the front page because it doesn't
require polling.
2) Debian already manages minor versions of various packages. Maybe an
external Lua tree could be maintained and shared by multiple distributors
which includes security fixes and dynamic library support. And for Linux, a
libtoolized build. Maybe off-list we can locate and coordinate with the
package maintainers of various Linux and BSD distros. I'd be happy to help.
I already help package and maintain Lua for the firmware at my company,
Barracuda Networks.