Verifying signing keys is one thing, but even better, f-droid.org can verify that the APK builds 100% from source, and that the APK f-droid.org builds matches the developer's official released APK:
https://f-droid.org/wiki/page/Deterministic,_Reproducible_Bu...