In any case, suggestions on how to achieve a good process for both Pike and standalone releases are more than welcome.
Maybe a reasonable compromise is to include it in Pike as a git submodule then? One would still need to clone the separate GJAlloc repo to be able to hack on it, but it'd avoid the bundle step at least. I don't have any direct experience with git submodules though, so I don't know how easy they are to work with.
Sharing the ACLs with Pike would be nice if you're ok with it. Wouldn't the simplest way to achieve that be to use pike-git.lysator.liu.se for GJAlloc as well?