This is also something that bothers me. Even Gentoo (!) gives up on building some applications and just redistributes upstream binaries (eg. Cassandra or Kafka), because it's too hard to actually build them.
I mentioned this on the #nixos IRC channel, and they seem open to having a configuration variable to disable packages not built from source (like they currently do for non-free licenses [1]), there is just no one currently working on it.
[1] https://nixos.org/nixpkgs/manual/#sec-allow-unfree
> but really haven't considered to how to deal with the "disapearing sources" problem, including vanishing git repositories
Guix does [2], and Nix is working on it in a similar way.
[2] https://guix.gnu.org/blog/2019/connecting-reproducible-deplo...
The build that F-Droid executes comes in two phases: one to obtain source code, which then gets packaged, the second phase to execute the build. Note however that the build execution phase does have network access and many builds actually do use the network to download dependencies, so its certainly not as advanced as Debian. I'd put what F-Droid is doing to somewhere between Nix OS (which doesn't have source packages at all) and Debian (whose source packages are complete so that no internet is needed).
For F-Droid, one could maybe think about running build twice: first with internet enabled but a recording proxy in between, and second with internet disabled but that proxy replaying the recorded file. That file is then published with the sources. There are formats for this, e.g. warc. It would be a partial improvement although it might still download binaries etc instead of source code and patching the source code would be also hard (tools would have to be developed to do this), hurting the FLOSS spirit.
I also think that believing you have the source code to an app but being unable to build it because of missing, possibly proprietary dependencies is far more damaging to the FLOSS spirit than any amount of format difficulty.
I think it's pretty common that stuff is being downloaded during the build phase, mostly from java package hosts like mvn, jitpack, etc. There are checks in f-droid to ensure those hosts are on a whitelist of FLOSS-policy repos but the checks don't prevent any custom build logic of downloading stuff via http, cloning git repos, etc. Also while maven central does not, some of these hosts also allow takedowns of published artifacts, at least jitpack allows it and it's on the whitelist (also jitpack's policy isn't FLOSS only, only requiring that the package is on public github, which still allows for nonfree "source available" software AND jitpack doesn't have any policy about downloaded binaries during its build).
This is a problem on F-droid, as the app you're installing will not get updates, and are out-of-sync with upstream. I was pretty sure F-droid archived the source tarball, but i can't find it now.
Disappearing sources are also an issue, as it has every disadvantage proprietary software has, with none of the upsides. It's much harder to patch in case it is needed, for instance. And hard to tell if someone tampered with the binary archives, I guess? (IIRC, the hash in Nix is based on the configuration, not the resulting binary).
Oh lord, but thanks for the info, would probably not have found it otherwise