The microG creator goes into more detail about signature spoofing at https://github.com/microg/GmsCore/issues/1467#issuecomment-8... The concerns usually raised against that are due to the "default" patch included in their repository, which has a specific purpose.
We don't use that, https://calyxos.org/about/tech/microg/ are the precautions we take to try and prevent "weakening overall package security"
In addition, microG is optional and can be disabled on first install, see https://calyxos.org/features/microg/#1-microg-disabled