Without deps reproducible builds are pretty much worthless indeed.
You will have to include them, and you will have to keep in sync with their releases and changes. As a developer that's one of the jobs you sign up for when picking a dependency. You inherit their issues and it's in your responsibility to act upon now.
So far packagers are doing the job for you, but should they really? Clearly nobody should know your own dependencies better than you, right?