Probably9857 you know they are coming directly from the dev, and no third party has tampered with the APK.
This doesnt preclude the possibility that the dev deliberately published safe source code then compiled malicious code, unless the apk release is also published via a github workflow. I admit, this may be an unlikelyunlikely scenario, but a possible one.
Thanks for the informative links about F-Droid!