On the opaque binary, the CI now rebuilds it from the kernel.org bluez-5.66 tarball inside a pinned debian:bookworm container and fails if a single byte differs from what's committed!
The tarball's checksum is pinned too otherwise the whole thing rests on whatever the download happened to return. There is a oneline docker command in the README if you want to verify it yourself rather than take my word for it ;-) I also added a MANUAL_INSTALL.md which is moer or less the blog post you suggested... build btproxy from source and write the two units by hand -> no script and no binary from me!
One correction to my own docs while I'm here: Id written that btproxy isnt packaged anywhere. That was wrong! Accoreding to my reading, Arch ships it in bluez-utils. Its Debian, Ubuntu and Fedora that donesn't which happens to be Proxmox and the guests this is for...
Also fixed a few things the review shook loose, including a bug where the port restriction I added could be bypassed with a /0 CIDR while still reporting itself as locked down.
Lastly, you said the repo merits very low trust. That's fair! And it's the right default for any new repo asking for root on your hypervisor and so mine included. Pinning the hash and making the build reproducible isn't me trying to convince you that I'm trustworthy. Its so that it doesn't have to matter...