Unless packages are uploaded as src to an autobuild+package facility, is there a quick and simple way to verify that the binaries submitted are bulid from the referenced sources?