zero improvement on end-user experience. does not solve supply chain issues, debian package will reproducabily contain the malware from upstream.
That's not what reproducible builds aim to prevent, and no one claims that. When upstream pushes bad code, that's on upstream. The thing reproducible builds aim to prevent is Debian or individual developers and system administrators with access rights to binary uploads and signing keys to get forced to sign and upload binary packages by attackers - be these governments (with or without court orders) or criminal organ…
Indeed, this could mitigate an attacker replacing the binary with something that's not produced from the code, but it does not mitigate the tool chain or code itself containing the exploit, creating a malicious binary.