I feel like any security issues could be solved by just letting app developers sign their own app bundles again. Then you could ensure an app is legitimate whether from the Play Store, F-Droid, or Shady Free App Store. Currently, Google makes it so painful to try to use independently-distributed software because apps signed by Google can't be upgraded by independently built versions and vice-versa. (Plus Play Protect pops up and disguisedly asks if I want to delete all F-Droid apps like every month.)