How do you attest this without simply trusting the dev or monitoring package data transferred by the app?[1] iOS, differently from Android, doesn’t have a explicit network permission that the user can verify.
All apps have network access by default and there’s nothing you can do about it without jailbreaking.
[1] as many pointed out: open source in iOS is a moot point as there’s no way to verify the binaries.