With reproducible builds (and as long as the distribution doesn't need to maintain any patches vs. upstream), this could even provide the best of both worlds: Verifiable hashes (comparable with upstream and other distributions) and a smaller set of trusted entities.
On the other hand, I'm not sure I'd necessarily trust a small open-source distribution's maintainers more than a widely used password manager's developers; I think I'd prefer my root of trust to be whatever has more users (and by proxy, hopefully scrutiny).
On the other hand, I'm not sure I'd necessarily trust a small open-source distribution's maintainers more than a widely used password manager's developers; I think I'd prefer my root of trust to be whatever has more users (and by proxy, hopefully scrutiny).