Just got to know that F-Droid still uses only v1 signature scheme for its APKs, which is generally considered insecure (or at least not secure enough). This sounds very bad...

