@dfeldman All (?) distributions build everything from source. That's what a (legitimate) distribution is.
Moreover, reproducibility has nothing to do with my proposal. You're not testing that your binary matches somebody else's. You're testing that the source release tarball actually came from the vetted project history.