And what happens if the server holding the keys gets compromised? I guess most manufacturers won’t care, but the more reputable ones would have things in their source they consider proprietary and would definitely not want to have to submit it.
Verification that it is, in fact, the actual shipped source might not be trivial either.
What happens when someone hacks GitHub and gains access to private repositories? That slim possibility doesn't stop the vast majority of companies from hosting their source in a private repo.
Verification that it is, in fact, the actual shipped source might not be trivial either.