Tomcat
Using the source always makes sense, because you aren't the only one reviewing it. If you use a binary, only one person reviewed it.
I hear what you're saying, but I'm looking at the source code right now. The only thing I can find that's at all suspicious is the pull that everyone's already complained about, which I can confirm doesn't even get built into your binary unless you specifically ask for it. Gentoo doesn't even allow the binary to use networking libraries by default, so the bad switches would do nothing unless you enabled that as well.
Of course, they can do anything they want in the future, but it would be hard to slip it into github without someone spotting it. They don't run github, so they can't do anything tricky like showing you one source at one time and a completely different file at another.
So, I think I'll keep using it for now. π
I guess if you're worried you could use tenacity, but I think they're pulling updates from the main project, so someone could possibly slip something in there that they miss.