I think I have understood it now. I’ll try to put in in my words:
The APK certificate block as specified by Google has some optional extensions that are poorly documented. This is not intended to be part of the app, but would in principle allow for code snippets to be hidden there. As F-Droid has no means of checking this certificate block, it must be banned from apps. This is verified now and has not been done before.
And the following entry in build.gradle suppresses this extension: