UserresU graphene only accepts updates from fdroid for that app. Is that the right opinion?
No. Signing keys are what matter when accepting updates. App source should not matter. The reason the error is occurring is because Fdroid (normally) signs apps with their own keys, so you can't update with a Github release that is signed by the developer's keys (or vice versa).
what can I do to update Libretube or potential other apps from Obtainium? Is there something's in the settings i can do?
You have to uninstall and reinstall from Obtainium.
If I shouldn't use Obtainium for updates because of security reasons at all please tell me why.
Its more secure than Fdroid as far as I'm aware.
I thaught it is a great and safe option to update direct from the developer but maybe I'm wrong I don't know.
Its currently the safest (non-GPlay) way of getting apps direct from the developer, until Accrescent matures more and gains more apps.