Earlier quoted context omitted.
People have thought about how to prevent it -- it's not a new issue.
In that case could you provide a source or two for those of us who want to get up to date with the current thinking?
If you look at the question, you can see that some people don't make the connection that the motivation behind code signing is figuring out who committed suspicious code. Code that has security bugs is one interest, another is code which the committer didn't have permission to commit, for example proprietary code.