Is it safer to download app from official fdroid repo or same as downloading direct from github?

Oh, and the effort to make an app, have it FLOSS, maintain it, pass the inclusion tests, etc are rather hard(er) steps to take when you want a quick buck via malware