>>18181
>(SHA256) hash of the source
Cargo cultism. Hashed binary packages are exactly as trustworthy as uncompiled source nobody read.
>the work Guix and NixOS do is very important in this regard
The parts about ensuring bit-for-bit identical environments to those used by auditors can be deployed "the right way", instead of blindly dumping Docker images and Flatpak fake "sandboxes", yes. The arbitrary fetishism of C source as some sacred cow of transparency, not so much.
Security and bugginess aside, though, the ability to build everything the same way and roll everything backward and forward alongside multiple branches in the same install is extremely convenient for a ton of other reasons. Or at least it would be if the UI wasn't so autistically unpolished and the documentation wasn't so scattershot, for a project old enough to have kids in school.