

Well, as far as I know the current idea is that you’ll have to toggle a setting in developer options and wait 24 hours (once). After that you can sideload unverified stuff as much as you like. So it’s not horribly sad, I´d say.
I actually kind of think that’s a reasonable change. It improves safety for the clueless majority, but it still gives those that know what they are doing a free reign with a minor initial inconvenience. And I kind of feel like articles still claiming how horrible this all is are mostly just outrage farming. Unless the plans have changed to something more fucked up, that is.
Well, the client code is liensed GPL 3.0 and server code is licensed AGPL 3.0, and those are both FOSS licenses. There are some additional commercial components licensed under a non-FOSS source-available license, but those are not required for the basic service. I guess you can’t use the Bitwarden trademark either. I would still consider Bitwarden FOSS, although with a slightly limited (but not crippling) scope of the term “Bitwarden”.