Debian Policy 4.13 states that Debian packages should not use convenience copies.

The list of packages embedding code from other projects is maintained in the secure-testing svn repository:


This list also contains information about code forks so that the security team can check if all forks contain the same vulnerabilities. Send suggestions or additions to secure-testing-team@lists.alioth.debian.org.

Lintian detects embedding of feedparser, common JavaScript/C/C++/PEAR/PHP libraries and ?PostScript fragments (1 2).

If you have a particular piece of code with some interesting aspect (security issue etc) you can likely find other copies using the Debian code search site.