I ended up simplifying my life, for my own sanity.
- Google Play Store for everything (I hate Google, but they're big enough where I trust I'm getting untampered with updates, and I don't have time to be verifying signatures of every APK I install
- Obtainium for everything else that isn't available on Play Store (eg. Amber, RoboSats)
I battled with this for a long time, but with Play Services, and the Play Store being sandboxed, I decided that was secure enough for my risk profile.
