What guarantees do you have that open source code faithfully reflects what is in the compiled binary?

The idea is that you download the source, review, and then build it yourself.

It’s easier for security researchers to check