In practice, (a) falls apart if the user doesn't have the knowledge, experience, or time necessary to perform an audit, which is quite likely for security software. And I feel like (b) isn't great either, as there are plenty of examples of major flaws in open source projects that went undetected for long periods - heartbleed is just one example.
There are major unrevealed flaws in all software more complicated than “hello, world.”
I'm not expecting anyone to do the work for free, by the way. You could still charge money for cloud sync or even app extensions and still keep the main repo open. Maybe the code could be a few revisions behind to incentivize people to pay.
In any case, from looking around, it seems that KeePass and possibly Bitwarden fit this bill.
Bitwarden just works and checks the boxes for me. I haven't tried it yet, but there is also a fork [1] that allows us to use our own hosting.