If you just want to HODL as securely as possible, then you don't need a hardware wallet. Just generate a BIP39 seed from a high-quality source of entropy and derive an address from it. Then lock the seed away somewhere very safe. (My recommendation is to generate the seed by hashing a reasonably-long passphrase together with one word that you never write down anywhere. Then store the passphrase in a few places: password manager, piece of paper in a safety deposit box, etc.) When it comes time to finally withdraw, you can buy a hardware wallet then, or use cold wallet software on an airgapped laptop.
If you need to withdraw from your wallet regularly, then a hardware wallet makes more sense. Any of the big names are fine, honestly, unless your threat model includes "evil maids" (sophisticated attackers who have physical access to your device). AFAIK the only viable attacks against major hardware wallets are evil maid attacks, wherein someone either tampers with the device, or measures its power consumption while you're using it, or replaces the client software on your computer/phone with a malicious version. So if you're worried about that, you should spring for the most paranoid option that's still user-friendly, which in my opinion is the Passport.
Two more things to note. First, you probably don't want to be using your hardware wallet for most crypto transactions. Instead, set up a second, lower-security wallet (e.g. an account on cash.app) with a maximum balance, and top it up with withdrawals from your hardware wallet as needed. Importantly, this means you'll never have to carry your hardware wallet around with you; it can sit safely at home. Second, if your hardware wallet breaks, you're screwed, so you still need to back up your seed somewhere secure. That's why if you just want to HODL I recommend not bothering with the hardware wallet -- it won't save you much effort.
Foundation devices is committed to using fully open source designs, all the way from the software down to the firmware, the hardware designs, and eventually I believe they hope to open source the secure elements and semiconductor designs as well.
Avoid Ledger if possible.
I own all three. Currently using Coldcard + Casa.
Which is not great. The entire reason you use a hardware wallet is because you assume that less secure hardware has been compromised.
I don't know that I would go as far as saying 'don't use ledger' though, all the hardware wallets have pros and cons and we don't really have a champion 'this one is best' yet. Though I might point to https://foundationdevices.com/ as being on the right track.
Trezor has had better service but this could as easily happen to them. To be really safe Coldcard is the best option.
[1] https://news.bitcoin.com/ledger-wallet-customer-data-leak-in...