Beware, the binary .apk's have unreleased patches you can't get from compiling yourself.
> This code is up-to-date and is matching the build on the Play Store.
which seems to be in conflict with your statement.
Also not found on F-droid. Hard pass.
An F-Droid compromise could backdoor every app.
For anyone: Why don't they cross-sign with their key+dev key?
Does apk support such a thing?
Not affiliated with Bromite, just cycling accounts, can point toward my last one if anyone's concerned about this acct's greenness.
Also, they may very well take PRs for extension support (haven't looked through their Issues/roadmap), but, I'm sure it's not on the top of a security-first project's to-do list.