Earlier quoted context omitted.
I used an Android phone with CalyxOS and microG for a year and never had this problem. There were a few apps I had a hard time getting APKs for without the Play Store, but even those I found I could side load from other devices that had the Play Store.
Or just use Aurora store! You dont have this problem because CalyxOS has a workaround for SafetyNet, i hear its pretty hacky, but it works.
It has a bad name but really all that they do is replace Google's signing certificate with their own and change the OS to accept it. It's not that "hacky" IMO, you're just trusting a different party. It's just like when you install Ubuntu, you trust Canonical to sign your packages, not debian. They use the same thing to replace play services. And if you trusted Google you wouldn't be using microG anyways, you'd just use play services.
The reason it gets a bad rap is because of the risk MicroG's signing key gets stolen. This is obviously higher than the risk of this happening for Google which is definitely in some highly protected HSM vault somewhere. True. Personally if I were a MicroG developer I'd keep it on a smartcard somewhere like a yubikey so it couldn't be easily copied. I don't know if they do this.
On the other hand, there is more you need to do to exploit it, even if you have the signing key. You need to get the user to use some malicious software and get it on F-Droid or something undetected. Just having the private key will not net you anything.
In my point of view you're trading a definitely possible but difficult possibility of a hack, for a total certainty that Google will track you every hour of every day. Personally I don't trust my smartphone with that much information anyway, but Google manages to collect so much because of their extended network. So they're able to extract much more info from my smartphone than I put into it by association. So it's an ok tradeoff for me. Everyone needs to make their own judgement on that.
For that reason I don't use banking apps on my mobile anyway and I don't have a need for SafetyNet as a result.But it's nice to know that there is a possibility to use SafetyNet protected apps in some cases if I want (some detect the workaround I believe).