i mostly do the same, if a popular distro i would use uses the source then it's probably fine, otherwise i'll read the source myself. i checked some that were packaged just because they seemed like high-risk pieces of software but the software maintainer are likely doing a way better job and i obviously found nothing.
i'm wondering a bit how viable checking all the sources is though, because even after reading the full source i sometimes feel like i didn't understood it enough. for example bento4 took me several hours to read and contained a ton of cryptography so if something nasty was hiding there, jia tan style, how likely would i be to notice? it's so troublesome with tools that are complex, useful, but not popular enough for a capable maintainer to pick up.

