Who and how is it decided that a application goes into a software repository?

Yes, but here you have to trust the creator of these instructions and the related package repo.
Personally, I prefer the explicit way, then I know what’s happening. But TBH, we have to trust the keys and the repo anyway.