Don't use RSS method. Too cumbersome. If you wann get apps from github use Obtanium. It does the exact same thing just much faster and more convenient.
Also remember, just because an app is open source and available on github doesn't mean that its privacy respecting or "safe" to use.
Apps on f-droid however have been checked for funny business. Also new and updated apps on F-droid don't really have a disadvantage. Depends on the app. some apps are actually better from F-droid, example: OsmAnd+, Geometric Weather.
The f-droid signing keys threat is overblown. Its not really a big threat. Outdated SDK however is, but thats a per app issue.
EDIT: Heed @matchboxbananasynergy following comments. There is merit to what he says.