This is a really interesting accomplishment - I am also working heavily on reproducible builds for my firmware projects, and .. lo and behold .. the package manager key administrivia is the final bone to be broken.

I wonder if Arch leading the way on this will prompt other distro's to attempt the same feat. Reproducible builds are important for certification, security and safety-critical applications .. it'd be great to see Linux distros become more conformant to this method.

Debian already has an ongoing project for this: https://wiki.debian.org/ReproducibleBuilds.

And spawned a cross-distro community working on this stuff:

https://reproducible-builds.org/