The best option is to compile each application yourself, including the entire (Linux) system from scratch.

Then, are you 100% safe from hacker attacks and surveillance by the deep state?

Actually, no. If you have an Intel motherboard and processor, it’s necessary to clean the BIOS of the Intel ME engine using me_cleaner.
https://legends2k.github.io/note/clean_me/And you should live in a Faraday cage—offline—preferably in a cave.

Holy... I didn’t even know this existed. What do you do if the BIOS is encrypted and can’t be changed?