I am curious what are good solutions to this problem? Compile your OS (and any other software) from source?
You have to rely on a distribution that has a many-eyes review policy and has security conscious users.
That's blatantly understating how many packages are reproducible.
Multiple people can grab the sources from the developer, review and apply the patches, build the package and publish the resulting hash. With reproducible builds, all people end up with the same hash, which should also be the same for the pre-built package in the repository.
In other words, instead of trusting one single person (the maintainer) you split the trust across multiple people. This is definitely an improvement thanks to reproducible builds.
And, there are large tech firms doing this already.
With the upcoming change, we loose this verification when using Google's app store.
Developers can still create key pairs themselves and upload them to Google. So they can still publish their public key if they want and you can be certain that APKs distributed from somewhere other than Play were definitely signed by the developer.