For an open source app distributed on the App Store, is there actually any way of verifying that what you get on your phone is the same as the source code you can read?
If Apple keeps pushing their Bitcode LLVM IR trans-compiling, along with magic App Store re-linking, they will kill the possibility of reproducible builds forever. In Apple's world, you are supposed to trust their app vetting process, not the source code on some website.
Checksum of a binary package against checksum of a reproducible build?
How do you run a checksum of a binary you download to your phone?