Well - since it's open source, theoretically you can build it yourself and "trust but verify" the audit, although there we're also assuming you trust your own judgement or that of your security team.
Well, right, of course. My comment is more along the lines of "paying for an audit implies putting faith in those auditors to do a good enough job"
It’s open source. I’ll inspect the source myself. Cross check against auditor findings. Build from source