We’re going to add a secure way of working around this without breaking the app source security model. We’ll be adding support for having the OS automatically verify the Play Store signing metadata and then inform Play services those apps were installed from the Play Store.
GrapheneOS is already working on it:
https://grapheneos.social/@GrapheneOS/114554622772349562
That’s already released and only deals with recent changes. It doesn’t fix apps using strong integrity challenges