

Stuff from the repository of your distribution generally can be considered save but everything involving a third party might not be.
This counts for both other Apt repositories as well as Flatpak. You likely have Flathub as an Flatpak source and while they have some checks and controll instances it is possible for untrusted third parties to upload packages including non-free ones there. I do not now of any incidents but some suspicion for packages with full system access can’t harm.
I think others have answered your question here quit well, I hope you’re not overwhelmed by all of this.