I covered this in an essay about security of various models of source sharing. It came down to talent and methods of developers and reviewers being what determines trustworthiness of a specific project/product. Although my stuff is text (old school), roryokane on Lobste.rs kindly made a better-formated, HTML version here:
EDIT: This also answers another commenter's question about when I'd trust closed-source software. Essentially if I trust the developer and/or reviewer. Then, I have to know I'm using the same thing. So, they have to publish signed hashes and so on of either the binary or source.
https://gist.github.com/roryokane/d02addfa9329c579f15daef5b4...
EDIT: This also answers another commenter's question about when I'd trust closed-source software. Essentially if I trust the developer and/or reviewer. Then, I have to know I'm using the same thing. So, they have to publish signed hashes and so on of either the binary or source.