All apps have network access by default and there’s nothing you can do about it without jailbreaking.
[1] as many pointed out: open source in iOS is a moot point as there’s no way to verify the binaries.
There’s an important distinction. On the first instance the app can’t access the outside world. On the second you will just know that it did.
[Edit]
See the author of keepassium commenting on the same issue about a month ago:
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
There is another option - buy an iPhone in China:
iOS: Disable WiFi (not just cellular) for specific apps without jailbreaking https://tinyapps.org/blog/202209100700_ios-disable-wifi-per-...
Have been using it for 3-4 years now. Its integration with the Apple ecosystem is second to none. I do use an online version that syncs with iCloud so I can access it anywhere (but with a Yubikey).
https://play.google.com/store/apps/details?id=keepass2androi...
Besides, I'm sure some clever attackers could think long and hard and come up with plenty of covert exfiltration channels without even needing direct network access. For example, adding a "safety redirect" every time you open your web browser, like t.co does.
It's still not 100% secure, but you would need both a compromised Keepass app and a compromised Dropbox app.
Almost all apps make outside connections and it would make no sense to prompt the user for that.