In this case, the app itself is in fact open source. The problem is that it relies on a non-free Google/Apple service for detecting contacts. However, I agree: Even such a dependency should strictly be avoided by government apps. This includes not limiting an app to the Play Store and also using alternative channels such as F-Droid.
I agree on a philosophical level. I disagree on a corporate level. I have yet to have an experience with a government that actually maintains bleeding edge security and proper maintenance. The farther down you go the administration levels, the worse it becomes.