Molly advertises itself as a “hardened version of Signal,” & its FOSS variant is the same without proprietary dependencies. TwinHelix’s FOSS Signal fork goes further, adding OSM support instead of GMaps. Are these forks trustworthy, & are they worth using for added security compared to mainline?
I think they can be trusted as their build process is open. I recently learned that the official client supports reproducible builds as well, so I don’t see the point in using those versions for myself. Now I trust the Signal authors’ builds. If you want to use them because of the extra features, it’s probably worth it.