GrapheneOS
Eumenia
SilverCat38
gMan
Throwing out some ideas.
I would like someone to challenge these ideas, please.
I'd like to underline (as someone already said) that the first store we have in GOS is the official App Store to install/update the applications mantained from the GOS dev team.
Why is this working? Because over time the developers gained our trust, so much that I suspect (almost) none of us actually go and see the diff of every update.
The only fact we are using GOS is based on trust.
So, suddently trust become a big part of our deciding factors.
This trust must be gained and maintained over time.
If trust is lost, people will stop to update/use/install software.
The same comes with the rest of the apps.
Installing new apps directly from the developers requires us to have some trust (in the code, in the developer, in the community or something else tied to the app).
If we see things happening like the Simple suit, Organic Maps or F-Droid behaviour over time, we might lose trust and decide to not use those software anymore.
People who still decide to put trust on F-Droid in spite of their history in security practices will still use their software.
Once we understood the implication of this, we might decide that cost/benefit (in terms of effort and other things) is good enough for us.
Anyway, there are probably some middle grounds we can still consider.
For example F-Droid clients can have more than one repository, making it a little bit more secure to install (and update) apps on your smartphone.
For example if you like Molly, there is an official repo for that.
You don't like molly and prefer SimpleX? There is an official repo for that.
If you like CollaboraOffice, and so on...
The same concept applies also for larger repositories.
For example the official Guardian Project repo contains all the apps developed by the same team.
In the same way, even more broader repositories exist, like Izzy-on-droid.
These repositories are a collection of a lot of apps signed by their respective developers and allow people to install and update them.
This is the equivalent of installing the apps directly from their respective developers without giving up on automatic updates.
In my understanging, it's pretty much the equivalent of installing them with Obtainium, with the main difference being someone needs to update the repositories before you could download the update.
I would like to have your toughts on this topic to see if this middle ground is considered somewhat ok and/or if there are some pitfalls I didn't take into account.
Of course, all of these options (directly from the developers / obtainium / izzy-on-droid) require us to trust the code/dev/community and there still is the chance that evey app we use between us and the developer (obtanium / droi-ify / f-droid / aurora / play store) might mangle with the first installation.
Your chance of getting killed by a cow are low, but never zero.