-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
I don't know if this is any better, but could we have some sort of agreement that contributers would have to give legal agreement too, that their code is completely legal and not copied from other sources? Or wouldn't that help?
I'm wondering if the source of these problems is people who are deliberately trying to taint ROS, or who don't know that this is bad. If the latter, then maybe the above agreement and an addition to the developer FAQ that such contributions are dangerous. If the former then I'm not immediately sure what steps can be taken, maybe partial hashing and comparison, or other partial/contextual comparisons of MS/contributed files?
My 2ยข, ~ -uniQ