Getting around Google’s attestation with an unlocked bootloader requires root - I believe the go-to is Magisk and the Play Integrity Fix module.
I'm planning on using KernelSU, because I asked on the Magisk subreddit and it's unironically what they recommended. I looked around here and it solidified my decision even more.
The recommended way for me to install it goes like install custom recovery > install custom ROM > somehow flash preferred rooting solution in recovery > install preferred rooting solution as an app
. link
Yeah I've thinking about that as well for like since I found this.
Me wanting to try out custom ROMs (because I haven't done this ever) is probably what's fueling my decision to go with it, even though it might be unsafe.