@TechNews
I think the article is misleading.
If you hang out in a PP community chat, and trust a random user to run their binary as root, you are an advanced user but don't act like one.
The question about ensuring trust is therefore not directly related.
However, there are efforts and solutions. Debian / PureOS work on reproducible builds, so it's verifiable that source and package match. In addition, @purism wants curated community apps.
But when you leave the safe space, you're on your own