Nothing. The innovation here is that you are downloading Bitcoin-core from a Nostr-based app store, and the keys signing for the legitimacy of the app are being vouched for by people within your web of trust.
got it ... maybe ... would the nostr app host it's own version of bitcoin core? how does that handle the remote origin of the original repo still being github.com? or does it serve the latest code from that remote origin? truly fascinating .... this is the revolution (one app at a time) that we're all here for :-)
get it again maybe ... these apps host/serve this source code from github.com but we can "trust" it through our follow list (so to speak)
The app could be hosted from just about anywhere. GitHub, a Blossom 🌸 server, or whatever, and signed with a PGP key or nsec when listing it on zap.store, and your web of trust on Nostr can be used as a measurement of the trustworthiness of that key.