n3t_admin I mean, its better to grab it by the source, extract the signing key of the APK, verify it from the github page, then install than it is to install from Aurora. I think even they would agree that much.
Do try to verify apk key however, or at least verify the source.
Once its installed, every update requires proper signatures, so you could use an auto updater like Obtainium.