Did they implement any GrapheneOS security complaints for it to be deemed actually secure?
Could you explain? I don't understand what you mean here. https://f-droid.org/F-Droid.apk is signed by the same key that signs https://f-droid.org/repo/entry.jar