> 1) simply resign it, and upload. > > 2) rebuild it from source each time I always did the second, and when I had the time and energy, I also checked the diff between his previous version, and the then-current one. > Is there any easy way to strip away the signature of the sponsoree > and sign it with mine? there used to be a 'dpkg-signpackage' > command, but I can't find it anymore You're looking for debsign from devscripts.