I don't? You can apply a similar technique to bust file hashes. Add a new comment to each source file, or whatever.
My point is that automated methods to detect unwanted content will only get GitHub so far. It will have to be fuzzy, and that means it's an arms race between detectors and obfuscators.