the most trust would have a hidden person that has no ties to known entity or even physical human as those conditions offer the best IRL physical security and peace of mind for the dev
Agreed 100%!
Everyone can see when code is changed in a public open source project
Most coders are illiterate to read C/C++ code. So diffs don't do a lot in this regard. Linux kernel has never ending stream of bugs and vulnerabilities...
Also how can we know a government won't force the dev to compromise his own application under a gag order?
In this particular case we can't be sure, unfortunately. But somehow the long dev's track record is telling he would most likely discard the dev efforts and withdraw from the projects entirely than to obey into submission mode. Donations aren't taxable are they? And how do we know Tor isn't monitored globally end-to-end down to the physical addresses on any interesting endpoint?