Ask HN: Crucial question about trust in open source apps
how can users verify that the app they're downloading from app stores is built from the exact open source code they can see in github?
This is even more true with SaaS, because the binaries used there can and do change without warning.
It is really hard to verify that a binary is based on the same source code, in addition libraries and build environment are not always included in the repository itself.
If you build the binary locally chances are that the binary will be slightly different, due to changes in the build environment for example. You will need to do a binary comparison and understand the reason and meaning of each change.