I understand a mutual fingerprint is good, but how is this better than LibreWolf?
Librewolf breaks trust (for lack of a better term) by not offering both of those options.
You just have to assume the binary you download isn’t compromised (maybe you could argue checking the hash is enough) and that the third-party updating service won’t serve you a compromised update.