So much time has been wasted by the open source community on pointless projects like this. >Reproducible builds allow people to "have more confidence that the binary you are using, which is actually executing on the computer, corresponds to the source code". The developer signing the build provides sufficient guarantees. Reproducible builds is another waste of time that the open source community has fallen for instea…
There are tons of documented cases of people resorting to physical attacks to obtain valuable cryptographic signing keys stored in full in one place.
https://github.com/jlopp/physical-bitcoin-attacks
I can only guess the people painting targets on their backs that big are woefully unaware of it, or living in deep survivors bias.
Trusting control of the entire internet to the laptop memory holding the PGP signing key that signs debian packages of GCC was always an insane thing to do, and still is.
Imagine what happens when one of those maintainers decides they like bribes or do not like being hit with rubber hoses.
Quorum signing of full source bootstrapped deterministic builds completed on independently owned and geo-distributed hardware produced by different vendors is currently the only viable solution to greatly reduce the incentive to coerce maintainers.