GrapheneOS has an approach that always prioritizes security at a technical level over privacy over promoting FLOSS. I think the first two are difficult to balance as they are interrelated but sometimes come at the cost of one another. I think the second is reasonable to have below the first two given the state of app ecosystems in general.
F-Droid does need to improve its approach to security. I can see why projects don't promote it as a default.