Rookie
Instead of Aurora Store you should just use the official Play Store. It is the most secure and private for Play Store apps on GrapheneOS and Play Services doesn't get any special privileges. Aurora Store doesn't avoid Google anyways and the really minor info that Google gets with sandboxed Google Play it would also get with Aurora Store. So there is no privacy benefit with Aurora in the first place.
For non-play store app, there is Accrescent on the built in GOS App Store. It is the best option in terms of security and privacy to get apps, so always look there first.
For FOSS apps which are published through GitHub/GitLab releases, you can use Obtainium, a feed reader, to download and automatically update those. Note, Obtainium only fetches and installs apps from sources you give it. its not an app store itself.
Always verify apps installed with Obtainium through AppVerifier (it is available on Accrescent).
So general priority order of apps sources (most to least prior):
- built-in GOS App Store
- Accrescent
- official Play Store
- sideloading through Obtainium + AppVerifier