The quirk in question is that macOS scanning happens on an Apple server. App publishers must submit their apps to that server for scanning. If the scan checks out, the server generates a cryptographic signature of the app, certifying it as malware-free.
App publishers must agree to a giant wall of legalese and restrictions, and pay $99/year, for the privilege of scanning their apps. FOSS developers generally won't do this.