With F-Droid, you've to trust them to compile the apps correctly. With Obtainium, you have to trust every app developer to deliver what they have in their source code. GitHub itself is also a point of failure, you have to trust it too.
There's a risk on all sides. The most secure way of getting #android apps on your #grapheneOS is to download the source code, examine it yourself, and compile the app – an unlikely scenario for most people.
#privacy #cybersecurity #opsec