I'm imagining a process where you point Apple or Google to your project's source tree. They download it and do the actual build process, and then the git SHA of the codebase they compiled gets signed and embedded in the build artifact. As a result, I could go into my phone and see the SHA of the code thats actually running, to make sure the developer of an opensource app hasn't quietly bundled in any changes that don't appear in the source tree.
Of course, this is still vulnerable to tampering from Apple or Google, but they have that capability anyway.
https://f-droid.org/wiki/page/Deterministic,_Reproducible_Bu...
A self built Signal would go a long way to be usable for me. One that didn't depend on Google Services would be even better.
[0] https://gist.github.com/alanorth/a755abbe21f5fdde2281771edae...
I wonder when we are going to see it on f-droid.
https://github.com/LibreSignal/LibreSignal/issues/37#issueco...