> If an upstream author knows their code will go straight into an active > Debian suite when they push a git tag to GitHub, the trust dynamic is > changed, I think for the worse.
this is the model of travis no ?, the upstream could become also the debian maintainer. And check that his package build properly on Debian. They are doing the work for travis, appveyor, gitlab-ci etc.. and why not Debian ? Cheers Frederic