F-Droid is in fact what an app store concerned about user safety looks like. Nobody gets hoodwinked into installing apps that track them or sell their data or otherwise abuse them on F-Droid.
F-Droid is so irrelevant that it doesn't even begin being targeted by supply chain and scam attacks. Being obscure always help with this, but pretending that it's the same threat model is absolutely false.
This is non-technical. F-Droid is horrible. https://privsec.dev/posts/android/f-droid-security-issues/#5...
F-Droid has not meaningfully improved since that piece was written, either. No one should use F-Droid.
It is yes. Their build system is somewhat arcane and difficult so some apps dont get updated from the git repo though. It could use some polish.