Note: This is written with the assumption of having a separation between the packages for the system differ from the packages for ApV.
Hosting our own packages on our own servers would be the ideal solution, and that’s true. However, with a small team and limited resources, that’s not currently feasible (though it should remains the long-term goal).
What we can do instead is source packages from existing systems, whether Nix, Arch, Gentoo, or others as long as we can obtain pure, upstream, patchless packages. Reproducibility is essential here to ensure that the packages have not been tampered with in the path of delivery.