I wish there was a way to do signed, git-verified builds for phone apps. Right now even if a project is opensource there's no way to tell that the version I have on my phone actually matches the source code I read in github.
I'm imagining a process where you point Apple or Google to your project's source tree. They download it and do the actual build process, and then the git SHA of the codebase they compiled gets signed and embedded in the build artifact. As a result, I could go into my phone and see the SHA of the code thats actually running, to make sure the developer of an opensource app hasn't quietly bundled in any changes that don't appear in the source tree.
Of course, this is still vulnerable to tampering from Apple or Google, but they have that capability anyway.