@lanodan @nytpu @lispi314
IIRC (some?) Debian source packages use an upstream source tarball + -debian tarball (containing the debian/ directory, including patches and buildscripts) that gets extracted on top of it, and then patches get applied.
It's not as clean as I would like, but in principle the stuff authored by Debian is separate from upstream code.
You just need pre-compromise build-essential, upsteram tarballs, and audited *-debian tarballs.