Now that the RAT release verification tool is available and fairly well-tested, we should start running it every now and then, to make sure our releases are OK with respect to various Apache policies. This is not a show-stopper by any means: "failing" the RAT tool does NOT stop a release from happening. It's just a pointer to improvements we need to make.
This is available as part of buildbot. See: http://ci.apache.org/projects/tomcat/rat-output.html