With reproducible builds, the difference between signing a binary and signing the source code from which it is built should be meaningless.
I agree that the threat model should include the threat of untrustworthy source code, because we want the countermeasures to work equally well against backdoors, "bugdoors", and genuine bugs.