my build scripts are on github. i can tell you how to set up the rest and you could replicate the builds and check that they are equal when you build them yourself. if they're not you can investigate why and fix the build system / source. then you can run that after each release to verify that every release is still ok. other than that you still have to read the source code and check that there are no intentional or unintentional vulnerabilities and fix them