An F-Droid compromise could backdoor every app.
For anyone: Why don't they cross-sign with their key+dev key?
Does apk support such a thing?