summaryrefslogtreecommitdiff
path: root/static/releases.html
blob: 76e2035de396f5fe7f6b9b6232f984e06d0c079b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
1001
1002
1003
1004
1005
1006
1007
1008
1009
1010
1011
1012
1013
1014
1015
1016
1017
1018
1019
1020
1021
1022
1023
1024
1025
1026
1027
1028
1029
1030
1031
1032
1033
1034
1035
1036
1037
1038
1039
1040
1041
1042
1043
1044
1045
1046
1047
1048
1049
1050
1051
1052
1053
1054
1055
1056
1057
1058
1059
1060
1061
1062
1063
1064
1065
1066
1067
1068
1069
1070
1071
1072
1073
1074
1075
1076
1077
1078
1079
1080
1081
1082
1083
1084
1085
1086
1087
1088
1089
1090
1091
1092
1093
1094
1095
1096
1097
1098
1099
1100
1101
1102
1103
1104
1105
1106
1107
1108
1109
1110
1111
1112
1113
1114
1115
1116
1117
1118
1119
1120
1121
1122
1123
1124
1125
1126
1127
1128
1129
1130
1131
1132
1133
1134
1135
1136
1137
1138
1139
1140
1141
1142
1143
1144
1145
1146
1147
1148
1149
1150
1151
1152
1153
1154
1155
1156
1157
1158
1159
1160
1161
1162
1163
1164
1165
1166
1167
1168
1169
1170
1171
1172
1173
1174
1175
1176
1177
1178
1179
1180
1181
1182
1183
1184
1185
1186
1187
1188
1189
1190
1191
1192
1193
1194
1195
1196
1197
1198
1199
1200
1201
1202
1203
1204
1205
1206
1207
1208
1209
1210
1211
1212
1213
1214
1215
1216
1217
1218
1219
1220
1221
1222
1223
1224
1225
1226
1227
1228
1229
1230
1231
1232
1233
1234
1235
1236
1237
1238
1239
1240
1241
1242
1243
1244
1245
1246
1247
1248
1249
1250
1251
1252
1253
1254
1255
1256
1257
1258
1259
1260
1261
1262
1263
1264
1265
1266
1267
1268
1269
1270
1271
1272
1273
1274
1275
1276
1277
1278
1279
1280
1281
1282
1283
1284
1285
1286
1287
1288
1289
1290
1291
1292
1293
1294
1295
1296
1297
1298
1299
1300
1301
1302
1303
1304
1305
1306
1307
1308
1309
1310
1311
1312
1313
1314
1315
1316
1317
1318
1319
1320
1321
1322
1323
1324
1325
1326
1327
1328
1329
1330
1331
1332
1333
1334
1335
1336
1337
1338
1339
1340
1341
1342
1343
1344
1345
1346
1347
1348
1349
1350
1351
1352
1353
1354
1355
1356
1357
1358
1359
1360
1361
1362
1363
1364
1365
1366
1367
1368
1369
1370
1371
1372
1373
1374
1375
1376
1377
1378
1379
1380
1381
1382
1383
1384
1385
1386
1387
1388
1389
1390
1391
1392
1393
1394
1395
1396
1397
1398
1399
1400
1401
1402
1403
1404
1405
1406
1407
1408
1409
1410
1411
1412
1413
1414
1415
1416
1417
1418
1419
1420
1421
1422
1423
1424
1425
1426
1427
1428
1429
1430
1431
1432
1433
1434
1435
1436
1437
1438
1439
1440
1441
1442
1443
1444
1445
1446
1447
1448
1449
1450
1451
1452
1453
1454
1455
1456
1457
1458
1459
1460
1461
1462
1463
1464
1465
1466
1467
1468
1469
1470
1471
1472
1473
1474
1475
1476
1477
1478
1479
1480
1481
1482
1483
1484
1485
1486
1487
1488
1489
1490
1491
1492
1493
1494
1495
1496
1497
1498
1499
1500
1501
1502
1503
1504
1505
1506
1507
1508
1509
1510
1511
1512
1513
1514
1515
1516
1517
1518
1519
1520
1521
1522
1523
1524
1525
1526
1527
1528
1529
1530
1531
1532
1533
1534
1535
1536
1537
1538
1539
1540
1541
1542
1543
1544
1545
1546
1547
1548
1549
1550
1551
1552
1553
1554
1555
1556
1557
1558
1559
1560
1561
1562
1563
1564
1565
1566
1567
1568
1569
1570
1571
1572
1573
1574
1575
1576
1577
1578
1579
1580
1581
1582
1583
1584
1585
1586
1587
1588
1589
1590
1591
1592
1593
1594
1595
1596
1597
1598
1599
1600
1601
1602
1603
1604
1605
1606
1607
1608
1609
1610
1611
1612
1613
1614
1615
1616
1617
1618
1619
1620
1621
1622
1623
1624
1625
1626
1627
1628
1629
1630
1631
1632
1633
1634
1635
1636
1637
1638
1639
1640
1641
1642
1643
1644
1645
1646
1647
1648
1649
1650
1651
1652
1653
1654
1655
1656
1657
1658
1659
1660
1661
1662
1663
1664
1665
1666
1667
1668
1669
1670
1671
1672
1673
1674
1675
1676
1677
1678
1679
1680
1681
1682
1683
1684
1685
1686
1687
1688
1689
1690
1691
1692
1693
1694
1695
1696
1697
1698
1699
1700
1701
1702
1703
1704
1705
1706
1707
1708
1709
1710
1711
1712
1713
1714
1715
1716
1717
1718
1719
1720
1721
1722
1723
1724
1725
1726
1727
1728
1729
1730
1731
1732
1733
1734
1735
1736
1737
1738
1739
1740
1741
1742
1743
1744
1745
1746
1747
1748
1749
1750
1751
1752
1753
1754
1755
1756
1757
1758
1759
1760
1761
1762
1763
1764
1765
1766
1767
1768
1769
1770
1771
1772
1773
1774
1775
1776
1777
1778
1779
1780
1781
1782
1783
1784
1785
1786
1787
1788
1789
1790
1791
1792
1793
1794
1795
1796
1797
1798
1799
1800
1801
1802
1803
1804
1805
1806
1807
1808
1809
1810
1811
1812
1813
1814
1815
1816
1817
1818
1819
1820
1821
1822
1823
1824
1825
1826
1827
1828
1829
1830
1831
1832
1833
1834
1835
1836
1837
1838
1839
1840
1841
1842
1843
1844
1845
1846
1847
1848
1849
1850
1851
1852
1853
1854
1855
1856
1857
1858
1859
1860
1861
1862
1863
1864
1865
1866
1867
1868
1869
1870
1871
1872
1873
1874
1875
1876
1877
1878
1879
1880
1881
1882
1883
1884
1885
1886
1887
1888
1889
1890
1891
1892
1893
1894
1895
1896
1897
1898
1899
1900
1901
1902
1903
1904
1905
1906
1907
1908
1909
1910
1911
1912
1913
1914
1915
1916
1917
1918
1919
1920
1921
1922
1923
1924
1925
1926
1927
1928
1929
1930
1931
1932
1933
1934
1935
1936
1937
1938
1939
1940
1941
1942
1943
1944
1945
1946
1947
1948
1949
1950
1951
1952
1953
1954
1955
1956
1957
1958
1959
1960
1961
1962
1963
1964
1965
1966
1967
1968
1969
1970
1971
1972
1973
1974
1975
1976
1977
1978
1979
1980
1981
1982
1983
1984
1985
1986
1987
1988
1989
1990
1991
1992
1993
1994
1995
1996
1997
1998
1999
2000
2001
2002
2003
2004
2005
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026
2027
2028
2029
2030
2031
2032
2033
2034
2035
2036
2037
2038
2039
2040
2041
2042
2043
2044
2045
2046
2047
2048
2049
2050
2051
2052
2053
2054
2055
2056
2057
2058
2059
2060
2061
2062
2063
2064
2065
2066
2067
2068
2069
2070
2071
2072
2073
2074
2075
2076
2077
2078
2079
2080
2081
2082
2083
2084
2085
2086
2087
2088
2089
2090
2091
2092
2093
2094
2095
2096
2097
2098
2099
2100
2101
2102
2103
2104
2105
2106
2107
2108
2109
2110
2111
2112
2113
2114
2115
2116
2117
2118
2119
2120
2121
2122
2123
2124
2125
2126
2127
2128
2129
2130
2131
2132
2133
2134
2135
2136
2137
2138
2139
2140
2141
2142
2143
2144
2145
2146
2147
2148
2149
2150
2151
2152
2153
2154
2155
2156
2157
2158
2159
2160
2161
2162
2163
2164
2165
2166
2167
2168
2169
2170
2171
2172
2173
2174
2175
2176
2177
2178
2179
2180
2181
2182
2183
2184
2185
2186
2187
2188
2189
2190
2191
2192
2193
2194
2195
2196
2197
2198
2199
2200
2201
2202
2203
2204
2205
2206
2207
2208
2209
2210
2211
2212
2213
2214
2215
2216
2217
2218
2219
2220
2221
2222
2223
2224
2225
2226
2227
2228
2229
2230
2231
2232
2233
2234
2235
2236
2237
2238
2239
2240
2241
2242
2243
2244
2245
2246
2247
2248
2249
2250
2251
2252
2253
2254
2255
2256
2257
2258
2259
2260
2261
2262
2263
2264
2265
2266
2267
2268
2269
2270
2271
2272
2273
2274
2275
2276
2277
2278
2279
2280
2281
2282
2283
2284
2285
2286
2287
2288
2289
2290
2291
2292
2293
2294
2295
2296
2297
2298
2299
2300
2301
2302
2303
2304
2305
2306
2307
2308
2309
2310
2311
2312
2313
2314
2315
2316
2317
2318
2319
2320
2321
2322
2323
2324
2325
2326
2327
2328
2329
2330
2331
2332
2333
2334
2335
2336
2337
2338
2339
2340
2341
2342
2343
2344
2345
2346
2347
2348
2349
2350
2351
2352
2353
2354
2355
2356
2357
2358
2359
2360
2361
2362
2363
2364
2365
2366
2367
2368
2369
2370
2371
2372
2373
2374
2375
2376
2377
2378
2379
2380
2381
2382
2383
2384
2385
2386
2387
2388
2389
2390
2391
2392
2393
2394
2395
2396
2397
2398
2399
2400
2401
2402
2403
2404
2405
2406
2407
2408
2409
2410
2411
2412
2413
2414
2415
2416
2417
2418
2419
2420
2421
2422
2423
2424
2425
2426
2427
2428
2429
2430
2431
2432
2433
2434
2435
2436
2437
2438
2439
2440
2441
2442
2443
2444
2445
2446
2447
2448
2449
2450
2451
2452
2453
2454
2455
2456
2457
2458
2459
2460
2461
2462
2463
2464
2465
2466
2467
2468
2469
2470
2471
2472
2473
2474
2475
2476
2477
2478
2479
2480
2481
2482
2483
2484
2485
2486
2487
2488
2489
2490
2491
2492
2493
2494
2495
2496
2497
2498
2499
2500
2501
2502
2503
2504
2505
2506
2507
2508
2509
2510
2511
2512
2513
2514
2515
2516
2517
2518
2519
2520
2521
2522
2523
2524
2525
2526
2527
2528
2529
2530
2531
2532
2533
2534
2535
2536
2537
2538
2539
2540
2541
2542
2543
2544
2545
2546
2547
2548
2549
2550
2551
2552
2553
2554
2555
2556
2557
2558
2559
2560
2561
2562
2563
2564
2565
2566
2567
2568
2569
2570
2571
2572
2573
2574
2575
2576
2577
2578
2579
2580
2581
2582
2583
2584
2585
2586
2587
2588
2589
2590
2591
2592
2593
2594
2595
2596
2597
2598
2599
2600
2601
2602
2603
2604
2605
2606
2607
2608
2609
2610
2611
2612
2613
2614
2615
2616
2617
2618
2619
2620
2621
2622
2623
2624
2625
2626
2627
2628
2629
2630
2631
2632
2633
2634
2635
2636
2637
2638
2639
2640
2641
2642
2643
2644
2645
2646
2647
2648
2649
2650
2651
2652
2653
2654
2655
2656
2657
2658
2659
2660
2661
2662
2663
2664
2665
2666
2667
2668
2669
2670
2671
2672
2673
2674
2675
2676
2677
2678
2679
2680
2681
2682
2683
2684
2685
2686
2687
2688
2689
2690
2691
2692
2693
2694
2695
2696
2697
2698
2699
2700
2701
2702
2703
2704
2705
2706
2707
2708
2709
2710
2711
2712
2713
2714
2715
2716
2717
2718
2719
2720
2721
2722
2723
2724
2725
2726
2727
2728
2729
2730
2731
2732
2733
2734
2735
2736
2737
2738
2739
2740
2741
2742
2743
2744
2745
2746
2747
2748
2749
2750
2751
2752
2753
2754
2755
2756
2757
2758
2759
2760
2761
2762
2763
2764
2765
2766
2767
2768
2769
2770
2771
2772
2773
2774
2775
2776
2777
2778
2779
2780
2781
2782
2783
2784
2785
2786
2787
2788
2789
2790
2791
2792
2793
2794
2795
2796
2797
2798
2799
2800
2801
2802
2803
2804
2805
2806
2807
2808
2809
2810
2811
2812
2813
2814
2815
2816
2817
2818
2819
2820
2821
2822
2823
2824
2825
2826
2827
2828
2829
2830
2831
2832
2833
2834
2835
2836
2837
2838
2839
2840
2841
2842
2843
2844
2845
2846
2847
2848
2849
2850
2851
2852
2853
2854
2855
2856
2857
2858
2859
2860
2861
2862
2863
2864
2865
2866
2867
2868
2869
2870
2871
2872
2873
2874
2875
2876
2877
2878
2879
2880
2881
2882
2883
2884
2885
2886
2887
2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
2903
2904
2905
2906
2907
2908
2909
2910
2911
2912
2913
2914
2915
2916
2917
2918
2919
2920
2921
2922
2923
2924
2925
2926
2927
2928
2929
2930
2931
2932
2933
2934
2935
2936
2937
2938
2939
2940
2941
2942
2943
2944
2945
2946
2947
2948
2949
2950
2951
2952
2953
2954
2955
2956
2957
2958
2959
2960
2961
2962
2963
2964
2965
2966
2967
2968
2969
2970
2971
2972
2973
2974
2975
2976
2977
2978
2979
2980
2981
2982
2983
2984
2985
2986
2987
2988
2989
2990
2991
2992
2993
2994
2995
2996
2997
2998
2999
3000
3001
3002
3003
3004
3005
3006
3007
3008
3009
3010
3011
3012
3013
3014
3015
3016
3017
3018
3019
3020
3021
3022
3023
3024
3025
3026
3027
3028
3029
3030
3031
3032
3033
3034
3035
3036
3037
3038
3039
3040
3041
3042
3043
3044
3045
3046
3047
3048
3049
3050
3051
3052
3053
3054
3055
3056
3057
3058
3059
3060
3061
3062
3063
3064
3065
3066
3067
3068
3069
3070
3071
3072
3073
3074
3075
3076
3077
3078
3079
3080
3081
3082
3083
3084
3085
3086
3087
3088
3089
3090
3091
3092
3093
3094
3095
3096
3097
3098
3099
3100
3101
3102
3103
3104
3105
3106
3107
3108
3109
3110
3111
3112
3113
3114
3115
3116
3117
3118
3119
3120
3121
3122
3123
3124
3125
3126
3127
3128
3129
3130
3131
3132
3133
3134
3135
3136
3137
3138
3139
3140
3141
3142
3143
3144
3145
3146
3147
3148
3149
3150
3151
3152
3153
3154
3155
3156
3157
3158
3159
3160
3161
3162
3163
3164
3165
3166
3167
3168
3169
3170
3171
3172
3173
3174
3175
3176
3177
3178
3179
3180
3181
3182
3183
3184
3185
3186
3187
3188
3189
3190
3191
3192
3193
3194
3195
3196
3197
3198
3199
3200
3201
3202
3203
3204
3205
3206
3207
3208
3209
3210
3211
3212
3213
3214
3215
3216
3217
3218
3219
3220
3221
3222
3223
3224
3225
3226
3227
3228
3229
3230
3231
3232
3233
3234
3235
3236
3237
3238
3239
3240
3241
3242
3243
3244
3245
3246
3247
3248
3249
3250
3251
3252
3253
3254
3255
3256
3257
3258
3259
3260
3261
3262
3263
3264
3265
3266
3267
3268
3269
3270
3271
3272
3273
3274
3275
3276
3277
3278
3279
3280
3281
3282
3283
3284
3285
3286
3287
3288
3289
3290
3291
3292
3293
3294
3295
3296
3297
3298
3299
3300
3301
3302
3303
3304
3305
3306
3307
3308
3309
3310
3311
3312
3313
3314
3315
3316
3317
3318
3319
3320
3321
3322
3323
3324
3325
3326
3327
3328
3329
3330
3331
3332
3333
3334
3335
3336
3337
3338
3339
3340
3341
3342
3343
3344
3345
3346
3347
3348
3349
3350
3351
3352
3353
3354
3355
3356
3357
3358
3359
3360
3361
3362
3363
3364
3365
3366
3367
3368
3369
3370
3371
3372
3373
3374
3375
3376
3377
3378
3379
3380
3381
3382
3383
3384
3385
3386
3387
3388
3389
3390
3391
3392
3393
3394
3395
3396
3397
3398
3399
3400
3401
3402
3403
3404
3405
3406
3407
3408
3409
3410
3411
3412
3413
3414
3415
3416
3417
3418
3419
3420
3421
3422
3423
3424
3425
3426
3427
3428
3429
3430
3431
3432
3433
3434
3435
3436
3437
3438
3439
3440
3441
3442
3443
3444
3445
3446
3447
3448
3449
3450
3451
3452
3453
3454
3455
3456
3457
3458
3459
3460
3461
3462
3463
3464
3465
3466
3467
3468
3469
3470
3471
3472
3473
3474
3475
3476
3477
3478
3479
3480
3481
3482
3483
3484
3485
3486
3487
3488
3489
3490
3491
3492
3493
3494
3495
3496
3497
3498
3499
3500
3501
3502
3503
3504
3505
3506
3507
3508
3509
3510
3511
3512
3513
3514
3515
3516
3517
3518
3519
3520
3521
3522
3523
3524
3525
3526
3527
3528
3529
3530
3531
3532
3533
3534
3535
3536
3537
3538
3539
3540
3541
3542
3543
3544
3545
3546
3547
3548
3549
3550
3551
3552
3553
3554
3555
3556
3557
3558
3559
3560
3561
3562
3563
3564
3565
3566
3567
3568
3569
3570
3571
3572
3573
3574
3575
3576
3577
3578
3579
3580
3581
3582
3583
3584
3585
3586
3587
3588
3589
3590
3591
3592
3593
3594
3595
3596
3597
3598
3599
3600
3601
3602
3603
3604
3605
3606
3607
3608
3609
3610
3611
3612
3613
3614
3615
3616
3617
3618
3619
3620
3621
3622
3623
3624
3625
3626
3627
3628
3629
3630
3631
3632
3633
3634
3635
3636
3637
3638
3639
3640
3641
3642
3643
3644
3645
3646
3647
3648
3649
3650
3651
3652
3653
3654
3655
3656
3657
3658
3659
3660
3661
3662
3663
3664
3665
3666
3667
3668
3669
3670
3671
3672
3673
3674
3675
3676
3677
3678
3679
3680
3681
3682
3683
3684
3685
3686
3687
3688
3689
3690
3691
3692
3693
3694
3695
3696
3697
3698
3699
3700
3701
3702
3703
3704
3705
3706
3707
3708
3709
3710
3711
3712
3713
3714
3715
3716
3717
3718
3719
3720
3721
3722
3723
3724
3725
3726
3727
3728
3729
3730
3731
3732
3733
3734
3735
3736
3737
3738
3739
3740
3741
3742
3743
3744
3745
3746
3747
3748
3749
3750
3751
3752
3753
3754
3755
3756
3757
3758
3759
3760
3761
3762
3763
3764
3765
3766
3767
3768
3769
3770
3771
3772
3773
3774
3775
3776
3777
3778
3779
3780
3781
3782
3783
3784
3785
3786
3787
3788
3789
3790
3791
3792
3793
3794
3795
3796
3797
3798
3799
3800
3801
3802
3803
3804
3805
3806
3807
3808
3809
3810
3811
3812
3813
3814
3815
3816
3817
3818
3819
3820
3821
3822
3823
3824
3825
3826
3827
3828
3829
3830
3831
3832
3833
3834
3835
3836
3837
3838
3839
3840
3841
3842
3843
3844
3845
3846
3847
3848
3849
3850
3851
3852
3853
3854
3855
3856
3857
3858
3859
3860
3861
3862
3863
3864
3865
3866
3867
3868
3869
3870
3871
3872
3873
3874
3875
3876
3877
3878
3879
3880
3881
3882
3883
3884
3885
3886
3887
3888
3889
3890
3891
3892
3893
3894
3895
3896
3897
3898
3899
3900
3901
3902
3903
3904
3905
3906
3907
3908
3909
3910
3911
3912
3913
3914
3915
3916
3917
3918
3919
3920
3921
3922
3923
3924
3925
3926
3927
3928
3929
3930
3931
3932
3933
3934
3935
3936
3937
3938
3939
3940
3941
3942
3943
3944
3945
3946
3947
3948
3949
3950
3951
3952
3953
3954
3955
3956
3957
3958
3959
3960
3961
3962
3963
3964
3965
3966
3967
3968
3969
3970
3971
3972
3973
3974
3975
3976
3977
3978
3979
3980
3981
3982
3983
3984
3985
3986
3987
3988
3989
3990
3991
3992
3993
3994
3995
3996
3997
3998
3999
4000
4001
4002
4003
4004
4005
4006
4007
4008
4009
4010
4011
4012
4013
4014
4015
4016
4017
4018
4019
4020
4021
4022
4023
4024
4025
4026
4027
4028
4029
4030
4031
4032
4033
4034
4035
4036
4037
4038
4039
4040
4041
4042
4043
4044
4045
4046
4047
4048
4049
4050
4051
4052
4053
4054
4055
4056
4057
4058
4059
4060
4061
4062
4063
4064
4065
4066
4067
4068
4069
4070
4071
4072
4073
4074
4075
4076
4077
4078
4079
4080
4081
4082
4083
4084
4085
4086
4087
4088
4089
4090
4091
4092
4093
4094
4095
4096
4097
4098
4099
4100
4101
4102
4103
4104
4105
4106
4107
4108
4109
4110
4111
4112
4113
4114
4115
4116
4117
4118
4119
4120
4121
4122
4123
4124
4125
4126
4127
4128
4129
4130
4131
4132
4133
4134
4135
4136
4137
4138
4139
4140
4141
4142
4143
4144
4145
4146
4147
4148
4149
4150
4151
4152
4153
4154
4155
4156
4157
4158
4159
4160
4161
4162
4163
4164
4165
4166
4167
4168
4169
4170
4171
4172
4173
4174
4175
4176
4177
4178
4179
4180
4181
4182
4183
4184
4185
4186
4187
4188
4189
4190
4191
4192
4193
4194
4195
4196
4197
4198
4199
4200
4201
4202
4203
4204
4205
4206
4207
4208
4209
4210
4211
4212
4213
4214
4215
4216
4217
4218
4219
4220
4221
4222
4223
4224
4225
4226
4227
4228
4229
4230
4231
4232
4233
4234
4235
4236
4237
4238
4239
4240
4241
4242
4243
4244
4245
4246
4247
4248
4249
4250
4251
4252
4253
4254
4255
4256
4257
4258
4259
4260
4261
4262
4263
4264
4265
4266
4267
4268
4269
4270
4271
4272
4273
4274
4275
4276
4277
4278
4279
4280
4281
4282
4283
4284
4285
4286
4287
4288
4289
4290
4291
4292
4293
4294
4295
4296
4297
4298
4299
4300
4301
4302
4303
4304
4305
4306
4307
4308
4309
4310
4311
4312
4313
4314
4315
4316
4317
4318
4319
4320
4321
4322
4323
4324
4325
4326
4327
4328
4329
4330
4331
4332
4333
4334
4335
4336
4337
4338
4339
4340
4341
4342
4343
4344
4345
4346
4347
4348
4349
4350
4351
4352
4353
4354
4355
4356
4357
4358
4359
4360
4361
4362
4363
4364
4365
4366
4367
4368
4369
4370
4371
4372
4373
4374
4375
4376
4377
4378
4379
4380
4381
4382
4383
4384
4385
4386
4387
4388
4389
4390
4391
4392
4393
4394
4395
4396
4397
4398
4399
4400
4401
4402
4403
4404
4405
4406
4407
4408
4409
4410
4411
4412
4413
4414
4415
4416
4417
4418
4419
4420
4421
4422
4423
4424
4425
4426
4427
4428
4429
4430
4431
4432
4433
4434
4435
4436
4437
4438
4439
4440
4441
4442
4443
4444
4445
4446
4447
4448
4449
4450
4451
4452
4453
4454
4455
4456
4457
4458
4459
4460
4461
4462
4463
4464
4465
4466
4467
4468
4469
4470
4471
4472
4473
4474
4475
4476
4477
4478
4479
4480
4481
4482
4483
4484
4485
4486
4487
4488
4489
4490
4491
4492
4493
4494
4495
4496
4497
4498
4499
4500
4501
4502
4503
4504
4505
4506
4507
4508
4509
4510
4511
4512
4513
4514
4515
4516
4517
4518
4519
4520
4521
4522
4523
4524
4525
4526
4527
4528
4529
4530
4531
4532
4533
4534
4535
4536
4537
4538
4539
4540
4541
4542
4543
4544
4545
4546
4547
4548
4549
4550
4551
4552
4553
4554
4555
4556
4557
4558
4559
4560
4561
4562
4563
4564
4565
4566
4567
4568
4569
4570
4571
4572
4573
4574
4575
4576
4577
4578
4579
4580
4581
4582
4583
4584
4585
4586
4587
4588
4589
4590
4591
4592
4593
4594
4595
4596
4597
4598
4599
4600
4601
4602
4603
4604
4605
4606
4607
4608
4609
4610
4611
4612
4613
4614
4615
4616
4617
4618
4619
4620
4621
4622
4623
4624
4625
4626
4627
4628
4629
4630
4631
4632
4633
4634
4635
4636
4637
4638
4639
4640
4641
4642
4643
4644
4645
4646
4647
4648
4649
4650
4651
4652
4653
4654
4655
4656
4657
4658
4659
4660
4661
4662
4663
4664
4665
4666
4667
4668
4669
4670
4671
4672
4673
4674
4675
4676
4677
4678
4679
4680
4681
4682
4683
4684
4685
4686
4687
4688
4689
4690
4691
4692
4693
4694
4695
4696
4697
4698
4699
4700
4701
4702
4703
4704
4705
4706
4707
4708
4709
4710
4711
4712
4713
4714
4715
4716
4717
4718
4719
4720
4721
4722
4723
4724
4725
4726
4727
4728
4729
4730
4731
4732
4733
4734
4735
4736
4737
4738
4739
4740
4741
4742
4743
4744
4745
4746
4747
4748
4749
4750
4751
4752
4753
4754
4755
4756
4757
4758
4759
4760
4761
4762
4763
4764
4765
4766
4767
4768
4769
4770
4771
4772
4773
4774
4775
4776
4777
4778
4779
4780
4781
4782
4783
4784
4785
4786
4787
4788
4789
4790
4791
4792
4793
4794
4795
4796
4797
4798
4799
4800
4801
4802
4803
4804
4805
4806
4807
4808
4809
4810
4811
4812
4813
4814
4815
4816
4817
4818
4819
4820
4821
4822
4823
4824
4825
4826
4827
4828
4829
4830
4831
4832
4833
4834
4835
4836
4837
4838
4839
4840
4841
4842
4843
4844
4845
4846
4847
4848
4849
4850
4851
4852
4853
4854
4855
4856
4857
4858
4859
4860
4861
4862
4863
4864
4865
4866
4867
4868
4869
4870
4871
4872
4873
4874
4875
4876
4877
4878
4879
4880
4881
4882
4883
4884
4885
4886
4887
4888
4889
4890
4891
4892
4893
4894
4895
4896
4897
4898
4899
4900
4901
4902
4903
4904
4905
4906
4907
4908
4909
4910
4911
4912
4913
4914
4915
4916
4917
4918
4919
4920
4921
4922
4923
4924
4925
4926
4927
4928
4929
4930
4931
4932
4933
4934
4935
4936
4937
4938
4939
4940
4941
4942
4943
4944
4945
4946
4947
4948
4949
4950
4951
4952
4953
4954
4955
4956
4957
4958
4959
4960
4961
4962
4963
4964
4965
4966
4967
4968
4969
4970
4971
4972
4973
4974
4975
4976
4977
4978
4979
4980
4981
4982
4983
4984
4985
4986
4987
4988
4989
4990
4991
4992
4993
4994
4995
4996
4997
4998
4999
5000
5001
5002
5003
5004
5005
5006
5007
5008
5009
5010
5011
5012
5013
5014
5015
5016
5017
5018
5019
5020
5021
5022
5023
5024
5025
5026
5027
5028
5029
5030
5031
5032
5033
5034
5035
5036
5037
5038
5039
5040
5041
5042
5043
5044
5045
5046
5047
5048
5049
5050
5051
5052
5053
5054
5055
5056
5057
5058
5059
5060
5061
5062
5063
5064
5065
5066
5067
5068
5069
5070
5071
5072
5073
5074
5075
5076
5077
5078
5079
5080
5081
5082
5083
5084
5085
5086
5087
5088
5089
5090
5091
5092
5093
5094
5095
5096
5097
5098
5099
5100
5101
5102
5103
5104
5105
5106
5107
5108
5109
5110
5111
5112
5113
5114
5115
5116
5117
5118
5119
5120
5121
5122
5123
5124
5125
5126
5127
5128
5129
5130
5131
5132
5133
5134
5135
5136
5137
5138
5139
5140
5141
5142
5143
5144
5145
5146
5147
5148
5149
5150
5151
5152
5153
5154
5155
5156
5157
5158
5159
5160
5161
5162
5163
5164
5165
5166
5167
5168
5169
5170
5171
5172
5173
5174
5175
5176
5177
5178
5179
5180
5181
5182
5183
5184
5185
5186
5187
5188
5189
5190
5191
5192
5193
5194
5195
5196
5197
5198
5199
5200
5201
5202
5203
5204
5205
5206
5207
5208
5209
5210
5211
5212
5213
5214
5215
5216
5217
5218
5219
5220
5221
5222
5223
5224
5225
5226
5227
5228
5229
5230
5231
5232
5233
5234
5235
5236
5237
5238
5239
5240
5241
5242
5243
5244
5245
5246
5247
5248
5249
5250
5251
5252
5253
5254
5255
5256
5257
5258
5259
5260
5261
5262
5263
5264
5265
5266
5267
5268
5269
5270
5271
5272
5273
5274
5275
5276
5277
5278
5279
5280
5281
5282
5283
5284
5285
5286
5287
5288
5289
5290
5291
5292
5293
5294
5295
5296
5297
5298
5299
5300
5301
5302
5303
5304
5305
5306
5307
5308
5309
5310
5311
5312
5313
5314
5315
5316
5317
5318
5319
5320
5321
5322
5323
5324
5325
5326
5327
5328
5329
5330
5331
5332
5333
5334
5335
5336
5337
5338
5339
5340
5341
5342
5343
5344
5345
5346
5347
5348
5349
5350
5351
5352
5353
5354
5355
5356
5357
5358
5359
5360
5361
5362
5363
5364
5365
5366
5367
5368
5369
5370
5371
5372
5373
5374
5375
5376
5377
5378
5379
5380
5381
5382
5383
5384
5385
5386
5387
5388
5389
5390
5391
5392
5393
5394
5395
5396
5397
5398
5399
5400
5401
5402
5403
5404
5405
5406
5407
5408
5409
5410
5411
5412
5413
5414
5415
5416
5417
5418
5419
5420
5421
5422
5423
5424
5425
5426
5427
5428
5429
5430
5431
5432
5433
5434
5435
5436
5437
5438
5439
5440
5441
5442
5443
5444
5445
5446
5447
5448
5449
5450
5451
5452
5453
5454
5455
5456
5457
5458
5459
5460
5461
5462
5463
5464
5465
5466
5467
5468
5469
5470
5471
5472
5473
5474
5475
5476
5477
5478
5479
5480
5481
5482
5483
5484
5485
5486
5487
5488
5489
5490
5491
5492
5493
5494
5495
5496
5497
5498
5499
5500
5501
5502
5503
5504
5505
5506
5507
5508
5509
5510
5511
5512
5513
5514
5515
5516
5517
5518
5519
5520
5521
5522
5523
5524
5525
5526
5527
5528
5529
5530
5531
5532
5533
5534
5535
5536
5537
5538
5539
5540
5541
5542
5543
5544
5545
5546
5547
5548
5549
5550
5551
5552
5553
5554
5555
5556
5557
5558
5559
5560
5561
5562
5563
5564
5565
5566
5567
5568
5569
5570
5571
5572
5573
5574
5575
5576
5577
5578
5579
5580
5581
5582
5583
5584
5585
5586
5587
5588
5589
5590
5591
5592
5593
5594
5595
5596
5597
5598
5599
5600
5601
5602
5603
5604
5605
5606
5607
5608
5609
5610
5611
5612
5613
5614
5615
5616
5617
5618
5619
5620
5621
5622
5623
5624
5625
5626
5627
5628
5629
5630
5631
5632
5633
5634
5635
5636
5637
5638
5639
5640
5641
5642
5643
5644
5645
5646
5647
5648
5649
5650
5651
5652
5653
5654
5655
5656
5657
5658
5659
5660
5661
5662
5663
5664
5665
5666
5667
5668
5669
5670
5671
5672
5673
5674
5675
5676
5677
5678
5679
5680
5681
5682
5683
5684
5685
5686
5687
5688
5689
5690
5691
5692
5693
5694
5695
5696
5697
5698
5699
5700
5701
5702
5703
5704
5705
5706
5707
5708
5709
5710
5711
5712
5713
5714
5715
5716
5717
5718
5719
5720
5721
5722
5723
5724
5725
5726
5727
5728
5729
5730
5731
5732
5733
5734
5735
5736
5737
5738
5739
5740
5741
5742
5743
5744
5745
5746
5747
5748
5749
5750
5751
5752
5753
5754
5755
5756
5757
5758
5759
5760
5761
5762
5763
5764
5765
5766
5767
5768
5769
5770
5771
5772
5773
5774
5775
5776
5777
5778
5779
5780
5781
5782
5783
5784
5785
5786
5787
5788
5789
5790
5791
5792
5793
5794
5795
5796
5797
5798
5799
5800
5801
5802
5803
5804
5805
5806
5807
5808
5809
5810
5811
5812
5813
5814
5815
5816
5817
5818
5819
5820
5821
5822
5823
5824
5825
5826
5827
5828
5829
5830
5831
5832
5833
5834
5835
5836
5837
5838
5839
5840
5841
5842
5843
5844
5845
5846
5847
5848
5849
5850
5851
5852
5853
5854
5855
5856
5857
5858
5859
5860
5861
5862
5863
5864
5865
5866
5867
5868
5869
5870
5871
5872
5873
5874
5875
5876
5877
5878
5879
5880
5881
5882
5883
5884
5885
5886
5887
5888
5889
5890
5891
5892
5893
5894
5895
5896
5897
5898
5899
5900
5901
5902
5903
5904
5905
5906
5907
5908
5909
5910
5911
5912
5913
5914
5915
5916
5917
5918
5919
5920
5921
5922
5923
5924
5925
5926
5927
5928
5929
5930
5931
5932
5933
5934
5935
5936
5937
5938
5939
5940
5941
5942
5943
5944
5945
5946
5947
5948
5949
5950
5951
5952
5953
5954
5955
5956
5957
5958
5959
5960
5961
5962
5963
5964
5965
5966
5967
5968
5969
5970
5971
5972
5973
5974
5975
5976
5977
5978
5979
5980
5981
5982
5983
5984
5985
5986
5987
5988
5989
5990
5991
5992
5993
5994
5995
5996
5997
5998
5999
6000
6001
6002
6003
6004
6005
6006
6007
6008
6009
6010
6011
6012
6013
6014
6015
6016
6017
6018
6019
6020
6021
6022
6023
6024
6025
6026
6027
6028
6029
6030
6031
6032
6033
6034
6035
6036
6037
6038
6039
6040
6041
6042
6043
6044
6045
6046
6047
6048
6049
6050
6051
6052
6053
6054
6055
6056
6057
6058
6059
6060
6061
6062
6063
6064
6065
6066
6067
6068
6069
6070
6071
6072
6073
6074
6075
6076
6077
6078
6079
6080
6081
6082
6083
6084
6085
6086
6087
6088
6089
6090
6091
6092
6093
6094
6095
6096
6097
6098
6099
6100
6101
6102
6103
6104
6105
6106
6107
6108
6109
6110
6111
6112
6113
6114
6115
6116
6117
6118
6119
6120
6121
6122
6123
6124
6125
6126
6127
6128
6129
6130
6131
6132
6133
6134
6135
6136
6137
6138
6139
6140
6141
6142
6143
6144
6145
6146
6147
6148
6149
6150
6151
6152
6153
6154
6155
6156
6157
6158
6159
6160
6161
6162
6163
6164
6165
6166
6167
6168
6169
6170
6171
6172
6173
6174
6175
6176
6177
6178
6179
6180
6181
6182
6183
6184
6185
6186
6187
6188
6189
6190
6191
6192
6193
6194
6195
6196
6197
6198
6199
6200
6201
6202
6203
6204
6205
6206
6207
6208
6209
6210
6211
6212
6213
6214
6215
6216
6217
6218
6219
6220
6221
6222
6223
6224
6225
6226
6227
6228
6229
6230
6231
6232
6233
6234
6235
6236
6237
6238
6239
6240
6241
6242
6243
6244
6245
6246
6247
6248
6249
6250
6251
6252
6253
6254
6255
6256
6257
6258
6259
6260
6261
6262
6263
6264
6265
6266
6267
6268
6269
6270
6271
6272
6273
6274
6275
6276
6277
6278
6279
6280
6281
6282
6283
6284
6285
6286
6287
6288
6289
6290
6291
6292
6293
6294
6295
6296
6297
6298
6299
6300
6301
6302
6303
6304
6305
6306
6307
6308
6309
6310
6311
6312
6313
6314
6315
6316
6317
6318
6319
6320
6321
6322
6323
6324
6325
6326
6327
6328
6329
6330
6331
6332
6333
6334
6335
6336
6337
6338
6339
6340
6341
6342
6343
6344
6345
6346
6347
6348
6349
6350
6351
6352
6353
6354
6355
6356
6357
6358
6359
6360
6361
6362
6363
6364
6365
6366
6367
6368
6369
6370
6371
6372
6373
6374
6375
6376
6377
6378
6379
6380
6381
6382
6383
6384
6385
6386
6387
6388
6389
6390
6391
6392
6393
6394
6395
6396
6397
6398
6399
6400
6401
6402
6403
6404
6405
6406
6407
6408
6409
6410
6411
6412
6413
6414
6415
6416
6417
6418
6419
6420
6421
6422
6423
6424
6425
6426
6427
6428
6429
6430
6431
6432
6433
6434
6435
6436
6437
6438
6439
6440
6441
6442
6443
6444
6445
6446
6447
6448
6449
6450
6451
6452
6453
6454
6455
6456
6457
6458
6459
6460
6461
6462
6463
6464
6465
6466
6467
6468
6469
6470
6471
6472
6473
6474
6475
6476
6477
6478
6479
6480
6481
6482
6483
6484
6485
6486
6487
6488
6489
6490
6491
6492
6493
6494
6495
6496
6497
6498
6499
6500
6501
6502
6503
6504
6505
6506
6507
6508
6509
6510
6511
6512
6513
6514
6515
6516
6517
6518
6519
6520
6521
6522
6523
6524
6525
6526
6527
6528
6529
6530
6531
6532
6533
6534
6535
6536
6537
6538
6539
6540
6541
6542
6543
6544
6545
6546
6547
6548
6549
6550
6551
6552
6553
6554
6555
6556
6557
6558
6559
6560
6561
6562
6563
6564
6565
6566
6567
6568
6569
6570
6571
6572
6573
6574
6575
6576
6577
6578
6579
6580
6581
6582
6583
6584
6585
6586
6587
6588
6589
6590
6591
6592
6593
6594
6595
6596
6597
6598
6599
6600
6601
6602
6603
6604
6605
6606
6607
6608
6609
6610
6611
6612
6613
6614
6615
6616
6617
6618
6619
6620
6621
6622
6623
6624
6625
6626
6627
6628
6629
6630
6631
6632
6633
6634
6635
6636
6637
6638
6639
6640
6641
6642
6643
6644
6645
6646
6647
6648
6649
6650
6651
6652
6653
6654
6655
6656
6657
6658
6659
6660
6661
6662
6663
6664
6665
6666
6667
6668
6669
6670
6671
6672
6673
6674
6675
6676
6677
6678
6679
6680
6681
6682
6683
6684
6685
6686
6687
6688
6689
6690
6691
6692
6693
6694
6695
6696
6697
6698
6699
6700
6701
6702
6703
6704
6705
6706
6707
6708
6709
6710
6711
6712
6713
6714
6715
6716
6717
6718
6719
6720
6721
6722
6723
6724
6725
6726
6727
6728
6729
6730
6731
6732
6733
6734
6735
6736
6737
6738
6739
6740
6741
6742
6743
6744
6745
6746
6747
6748
6749
6750
6751
6752
6753
6754
6755
6756
6757
6758
6759
6760
6761
6762
6763
6764
6765
6766
6767
6768
6769
6770
6771
6772
6773
6774
6775
6776
6777
6778
6779
6780
6781
6782
6783
6784
6785
6786
6787
6788
6789
6790
6791
6792
6793
6794
6795
6796
6797
6798
6799
6800
6801
6802
6803
6804
6805
6806
6807
6808
6809
6810
6811
6812
6813
6814
6815
6816
6817
6818
6819
6820
6821
6822
6823
6824
6825
6826
6827
6828
6829
6830
6831
6832
6833
6834
6835
6836
6837
6838
6839
6840
6841
6842
6843
6844
6845
6846
6847
6848
6849
6850
6851
6852
6853
6854
6855
6856
6857
6858
6859
6860
6861
6862
6863
6864
6865
6866
6867
6868
6869
6870
6871
6872
6873
6874
6875
6876
6877
6878
6879
6880
6881
6882
6883
6884
6885
6886
6887
6888
6889
6890
6891
6892
6893
6894
6895
6896
6897
6898
6899
6900
6901
6902
6903
6904
6905
6906
6907
6908
6909
6910
6911
6912
6913
6914
6915
6916
6917
6918
6919
6920
6921
6922
6923
6924
6925
6926
6927
6928
6929
6930
6931
6932
6933
6934
6935
6936
6937
6938
6939
6940
6941
6942
6943
6944
6945
6946
6947
6948
6949
6950
6951
6952
6953
6954
6955
6956
6957
6958
6959
6960
6961
6962
6963
6964
6965
6966
6967
6968
6969
6970
6971
6972
6973
6974
6975
6976
6977
6978
6979
6980
6981
6982
6983
6984
6985
6986
6987
6988
6989
6990
6991
6992
6993
6994
6995
6996
6997
6998
6999
7000
7001
7002
7003
7004
7005
7006
7007
7008
7009
7010
7011
7012
7013
7014
7015
7016
7017
7018
7019
7020
7021
7022
7023
7024
7025
7026
7027
7028
7029
7030
7031
7032
7033
7034
7035
7036
7037
7038
7039
7040
7041
7042
7043
7044
7045
7046
7047
7048
7049
7050
7051
7052
7053
7054
7055
7056
7057
7058
7059
7060
7061
7062
7063
7064
7065
7066
7067
7068
7069
7070
7071
7072
7073
7074
7075
7076
7077
7078
7079
7080
7081
7082
7083
7084
7085
7086
7087
7088
7089
7090
7091
7092
7093
7094
7095
7096
7097
7098
7099
7100
7101
7102
7103
7104
7105
7106
7107
7108
7109
7110
7111
7112
7113
7114
7115
7116
7117
7118
7119
7120
7121
7122
7123
7124
7125
7126
7127
7128
7129
7130
7131
7132
7133
7134
7135
7136
7137
7138
7139
7140
7141
7142
7143
7144
7145
7146
7147
7148
7149
7150
7151
7152
7153
7154
7155
7156
7157
7158
7159
7160
7161
7162
7163
7164
7165
7166
7167
7168
7169
7170
7171
7172
7173
7174
7175
7176
7177
7178
7179
7180
7181
7182
7183
7184
7185
7186
7187
7188
7189
7190
7191
7192
7193
7194
7195
7196
7197
7198
7199
7200
7201
7202
7203
7204
7205
7206
7207
7208
7209
7210
7211
7212
7213
7214
7215
7216
7217
7218
7219
7220
7221
7222
7223
7224
7225
7226
7227
7228
7229
7230
7231
7232
7233
7234
7235
7236
7237
7238
7239
7240
7241
7242
7243
7244
7245
7246
7247
7248
7249
7250
7251
7252
7253
7254
7255
7256
7257
7258
7259
7260
7261
7262
7263
7264
7265
7266
7267
7268
7269
7270
7271
7272
7273
7274
7275
7276
7277
7278
7279
7280
7281
7282
7283
7284
7285
7286
7287
7288
7289
7290
7291
7292
7293
7294
7295
7296
7297
7298
7299
7300
7301
7302
7303
7304
7305
7306
7307
7308
7309
7310
7311
7312
7313
7314
7315
7316
7317
7318
7319
7320
7321
7322
7323
7324
7325
7326
7327
7328
7329
7330
7331
7332
7333
7334
7335
7336
7337
7338
7339
7340
7341
7342
7343
7344
7345
7346
7347
7348
7349
7350
7351
7352
7353
7354
7355
7356
7357
7358
7359
7360
7361
7362
7363
7364
7365
7366
7367
7368
7369
7370
7371
7372
7373
7374
7375
7376
7377
7378
7379
7380
7381
7382
7383
7384
7385
7386
7387
7388
7389
7390
7391
7392
7393
7394
7395
7396
7397
7398
7399
7400
7401
7402
7403
7404
7405
7406
7407
7408
7409
7410
7411
7412
7413
7414
7415
7416
7417
7418
7419
7420
7421
7422
7423
7424
7425
7426
7427
7428
7429
7430
7431
7432
7433
7434
7435
7436
7437
7438
7439
7440
7441
7442
7443
7444
7445
7446
7447
7448
7449
7450
7451
7452
7453
7454
7455
7456
7457
7458
7459
7460
7461
7462
7463
7464
7465
7466
7467
7468
7469
7470
7471
7472
7473
7474
7475
7476
7477
7478
7479
7480
7481
7482
7483
7484
7485
7486
7487
7488
7489
7490
7491
7492
7493
7494
7495
7496
7497
7498
7499
7500
7501
7502
7503
7504
7505
7506
7507
7508
7509
7510
7511
7512
7513
7514
7515
7516
7517
7518
7519
7520
7521
7522
7523
7524
7525
7526
7527
7528
7529
7530
7531
7532
7533
7534
7535
7536
7537
7538
7539
7540
7541
7542
7543
7544
7545
7546
7547
7548
7549
7550
7551
7552
7553
7554
7555
7556
7557
7558
7559
7560
7561
7562
7563
7564
7565
7566
7567
7568
7569
7570
7571
7572
7573
7574
7575
7576
7577
7578
7579
7580
7581
7582
7583
7584
7585
7586
7587
7588
7589
7590
7591
7592
7593
7594
7595
7596
7597
7598
7599
7600
7601
7602
7603
7604
7605
7606
7607
7608
7609
7610
7611
7612
7613
7614
7615
7616
7617
7618
7619
7620
7621
7622
7623
7624
7625
7626
7627
7628
7629
7630
7631
7632
7633
7634
7635
7636
7637
7638
7639
7640
7641
7642
7643
7644
7645
7646
7647
7648
7649
7650
7651
7652
7653
7654
7655
7656
7657
7658
7659
7660
7661
7662
7663
7664
7665
7666
7667
7668
7669
7670
7671
7672
7673
7674
7675
7676
7677
7678
7679
7680
7681
7682
7683
7684
7685
7686
7687
7688
7689
7690
7691
7692
7693
7694
7695
7696
7697
7698
7699
7700
7701
7702
7703
7704
7705
7706
7707
7708
7709
7710
7711
7712
7713
7714
7715
7716
7717
7718
7719
7720
7721
7722
7723
7724
7725
7726
7727
7728
7729
7730
7731
7732
7733
7734
7735
7736
7737
7738
7739
7740
7741
7742
7743
7744
7745
7746
7747
7748
7749
7750
7751
7752
7753
7754
7755
7756
7757
7758
7759
7760
7761
7762
7763
7764
7765
7766
7767
7768
7769
7770
7771
7772
7773
7774
7775
7776
7777
7778
7779
7780
7781
7782
7783
7784
7785
7786
7787
7788
7789
7790
7791
7792
7793
7794
7795
7796
7797
7798
7799
7800
7801
7802
7803
7804
7805
7806
7807
7808
7809
7810
7811
7812
7813
7814
7815
7816
7817
7818
7819
7820
7821
7822
7823
7824
7825
7826
7827
7828
7829
7830
7831
7832
7833
7834
7835
7836
7837
7838
7839
7840
7841
7842
7843
7844
7845
7846
7847
7848
7849
7850
7851
7852
7853
7854
7855
7856
7857
7858
7859
7860
7861
7862
7863
7864
7865
7866
7867
7868
7869
7870
7871
7872
7873
7874
7875
7876
7877
7878
7879
7880
7881
7882
7883
7884
7885
7886
7887
7888
7889
7890
7891
7892
7893
7894
7895
7896
7897
7898
7899
7900
7901
7902
7903
7904
7905
7906
7907
7908
7909
7910
7911
7912
7913
7914
7915
7916
7917
7918
7919
7920
7921
7922
7923
7924
7925
7926
7927
7928
7929
7930
7931
7932
7933
7934
7935
7936
7937
7938
7939
7940
7941
7942
7943
7944
7945
7946
7947
7948
7949
7950
7951
7952
7953
7954
7955
7956
7957
7958
7959
7960
7961
7962
7963
7964
7965
7966
7967
7968
7969
7970
7971
7972
7973
7974
7975
7976
7977
7978
7979
7980
7981
7982
7983
7984
7985
7986
7987
7988
7989
7990
7991
7992
7993
7994
7995
7996
7997
7998
7999
8000
8001
8002
8003
8004
8005
8006
8007
8008
8009
8010
8011
8012
8013
8014
8015
8016
8017
8018
8019
8020
8021
8022
8023
8024
8025
8026
8027
8028
8029
8030
8031
8032
8033
8034
8035
8036
8037
8038
8039
8040
8041
8042
8043
8044
8045
8046
8047
8048
8049
8050
8051
8052
8053
8054
8055
8056
8057
8058
8059
8060
8061
8062
8063
8064
8065
8066
8067
8068
8069
8070
8071
8072
8073
8074
8075
8076
8077
8078
8079
8080
8081
8082
8083
8084
8085
8086
8087
8088
8089
8090
8091
8092
8093
8094
8095
8096
8097
8098
8099
8100
8101
8102
8103
8104
8105
8106
8107
8108
8109
8110
8111
8112
8113
8114
8115
8116
8117
8118
8119
8120
8121
8122
8123
8124
8125
8126
8127
8128
8129
8130
8131
8132
8133
8134
8135
8136
8137
8138
8139
8140
8141
8142
8143
8144
8145
8146
8147
8148
8149
8150
8151
8152
8153
8154
8155
8156
8157
8158
8159
8160
8161
8162
8163
8164
8165
8166
8167
8168
8169
8170
8171
8172
8173
8174
8175
8176
8177
8178
8179
8180
8181
8182
8183
8184
8185
8186
8187
8188
8189
8190
8191
8192
8193
8194
8195
8196
8197
8198
8199
8200
8201
8202
8203
8204
8205
8206
8207
8208
8209
8210
8211
8212
8213
8214
8215
8216
8217
8218
8219
8220
8221
8222
8223
8224
8225
8226
8227
8228
8229
8230
8231
8232
8233
8234
8235
8236
8237
8238
8239
8240
8241
8242
8243
8244
8245
8246
8247
8248
8249
8250
8251
8252
8253
8254
8255
8256
8257
8258
8259
8260
8261
8262
8263
8264
8265
8266
8267
8268
8269
8270
8271
8272
8273
8274
8275
8276
8277
8278
8279
8280
8281
8282
8283
8284
8285
8286
8287
8288
8289
8290
8291
8292
8293
8294
8295
8296
8297
8298
8299
8300
8301
8302
8303
8304
8305
8306
8307
8308
8309
8310
8311
8312
8313
8314
8315
8316
8317
8318
8319
8320
8321
8322
8323
8324
8325
8326
8327
8328
8329
8330
8331
8332
8333
8334
8335
8336
8337
8338
8339
8340
8341
8342
8343
8344
8345
8346
8347
8348
8349
8350
8351
8352
8353
8354
8355
8356
8357
8358
8359
8360
8361
8362
8363
8364
8365
8366
8367
8368
8369
8370
8371
8372
8373
8374
8375
8376
8377
8378
8379
8380
8381
8382
8383
8384
8385
8386
8387
8388
8389
8390
8391
8392
8393
8394
8395
8396
8397
8398
8399
8400
8401
8402
8403
8404
8405
8406
8407
8408
8409
8410
8411
8412
8413
8414
8415
8416
8417
8418
8419
8420
8421
8422
8423
8424
8425
8426
8427
8428
8429
8430
8431
8432
8433
8434
8435
8436
8437
8438
8439
8440
8441
8442
8443
8444
8445
8446
8447
8448
8449
8450
8451
8452
8453
8454
8455
8456
8457
8458
8459
8460
8461
8462
8463
8464
8465
8466
8467
8468
8469
8470
8471
8472
8473
8474
8475
8476
8477
8478
8479
8480
8481
8482
8483
8484
8485
8486
8487
8488
8489
8490
8491
8492
8493
8494
8495
8496
8497
8498
8499
8500
8501
8502
8503
8504
8505
8506
8507
8508
8509
8510
8511
8512
8513
8514
8515
8516
8517
8518
8519
8520
8521
8522
8523
8524
8525
8526
8527
8528
8529
8530
8531
8532
8533
8534
8535
8536
8537
8538
8539
8540
8541
8542
8543
8544
8545
8546
8547
8548
8549
8550
8551
8552
8553
8554
8555
8556
8557
8558
8559
8560
8561
8562
8563
8564
8565
8566
8567
8568
8569
8570
8571
8572
8573
8574
8575
8576
8577
8578
8579
8580
8581
8582
8583
8584
8585
8586
8587
8588
8589
8590
8591
8592
8593
8594
8595
8596
8597
8598
8599
8600
8601
8602
8603
8604
8605
8606
8607
8608
8609
8610
8611
8612
8613
8614
8615
8616
8617
8618
8619
8620
8621
8622
8623
8624
8625
8626
8627
8628
8629
8630
8631
8632
8633
8634
8635
8636
8637
8638
8639
8640
8641
8642
8643
8644
8645
8646
8647
8648
8649
8650
8651
8652
8653
8654
8655
8656
8657
8658
8659
8660
8661
8662
8663
8664
8665
8666
8667
8668
8669
8670
8671
8672
8673
8674
8675
8676
8677
8678
8679
8680
8681
8682
8683
8684
8685
8686
8687
8688
8689
8690
8691
8692
8693
8694
8695
8696
8697
8698
8699
8700
8701
8702
8703
8704
8705
8706
8707
8708
8709
8710
8711
8712
8713
8714
8715
8716
8717
8718
8719
8720
8721
8722
8723
8724
8725
8726
8727
8728
8729
8730
8731
8732
8733
8734
8735
8736
8737
8738
8739
8740
8741
8742
8743
8744
8745
8746
8747
8748
8749
8750
8751
8752
8753
8754
8755
8756
8757
8758
8759
8760
8761
8762
8763
8764
8765
8766
8767
8768
8769
8770
8771
8772
8773
8774
8775
8776
8777
8778
8779
8780
8781
8782
8783
8784
8785
8786
8787
8788
8789
8790
8791
8792
8793
8794
8795
8796
8797
8798
8799
8800
8801
8802
8803
8804
8805
8806
8807
8808
8809
8810
8811
8812
8813
8814
8815
8816
8817
8818
8819
8820
8821
8822
8823
8824
8825
8826
8827
8828
8829
8830
8831
8832
8833
8834
8835
8836
8837
8838
8839
8840
8841
8842
8843
8844
8845
8846
8847
8848
8849
8850
8851
8852
8853
8854
8855
8856
8857
8858
8859
8860
8861
8862
8863
8864
8865
8866
8867
8868
8869
8870
8871
8872
8873
8874
8875
8876
8877
8878
8879
8880
8881
8882
8883
8884
8885
8886
8887
8888
8889
8890
8891
8892
8893
8894
8895
8896
8897
8898
8899
8900
8901
8902
8903
8904
8905
8906
8907
8908
8909
8910
8911
8912
8913
8914
8915
8916
8917
8918
8919
8920
8921
8922
8923
8924
8925
8926
8927
8928
8929
8930
8931
8932
8933
8934
8935
8936
8937
8938
8939
8940
8941
8942
8943
8944
8945
8946
8947
8948
8949
8950
8951
8952
8953
8954
8955
8956
8957
8958
8959
8960
8961
8962
8963
8964
8965
8966
8967
8968
8969
8970
8971
8972
8973
8974
8975
8976
8977
8978
8979
8980
8981
8982
8983
8984
8985
8986
8987
8988
8989
8990
8991
8992
8993
8994
8995
8996
8997
8998
8999
9000
9001
9002
9003
9004
9005
9006
9007
9008
9009
9010
9011
9012
9013
9014
9015
9016
9017
9018
9019
9020
9021
9022
9023
9024
9025
9026
9027
9028
9029
9030
9031
9032
9033
9034
9035
9036
9037
9038
9039
9040
9041
9042
9043
9044
9045
9046
9047
9048
9049
9050
9051
9052
9053
9054
9055
9056
9057
9058
9059
9060
9061
9062
9063
9064
9065
9066
9067
9068
9069
9070
9071
9072
9073
9074
9075
9076
9077
9078
9079
9080
9081
9082
9083
9084
9085
9086
9087
9088
9089
9090
9091
9092
9093
9094
9095
9096
9097
9098
9099
9100
9101
9102
9103
9104
9105
9106
9107
9108
9109
9110
9111
9112
9113
9114
9115
9116
9117
9118
9119
9120
9121
9122
9123
9124
9125
9126
9127
9128
9129
9130
9131
9132
9133
9134
9135
9136
9137
9138
9139
9140
9141
9142
9143
9144
9145
9146
9147
9148
9149
9150
9151
9152
9153
9154
9155
9156
9157
9158
9159
9160
9161
9162
9163
9164
9165
9166
9167
9168
9169
9170
9171
9172
9173
9174
9175
9176
9177
9178
9179
9180
9181
9182
9183
9184
9185
9186
9187
9188
9189
9190
9191
9192
9193
9194
9195
9196
9197
9198
9199
9200
9201
9202
9203
9204
9205
9206
9207
9208
9209
9210
9211
9212
9213
9214
9215
9216
9217
9218
9219
9220
9221
9222
9223
9224
9225
9226
9227
9228
9229
9230
9231
9232
9233
9234
9235
9236
9237
9238
9239
9240
9241
9242
9243
9244
9245
9246
9247
9248
9249
9250
9251
9252
9253
9254
9255
9256
9257
9258
9259
9260
9261
9262
9263
9264
9265
9266
9267
9268
9269
9270
9271
9272
9273
9274
9275
9276
9277
9278
9279
9280
9281
9282
9283
9284
9285
9286
9287
9288
9289
9290
9291
9292
9293
9294
9295
9296
9297
9298
9299
9300
9301
9302
9303
9304
9305
9306
9307
9308
9309
9310
9311
9312
9313
9314
9315
9316
9317
9318
9319
9320
9321
9322
9323
9324
9325
9326
9327
9328
9329
9330
9331
9332
9333
9334
9335
9336
9337
9338
9339
9340
9341
9342
9343
9344
9345
9346
9347
9348
9349
9350
9351
9352
9353
9354
9355
9356
9357
9358
9359
9360
9361
9362
9363
9364
9365
9366
9367
9368
9369
9370
9371
9372
9373
9374
9375
9376
9377
9378
9379
9380
9381
9382
9383
9384
9385
9386
9387
9388
9389
9390
9391
9392
9393
9394
9395
9396
9397
9398
9399
9400
9401
9402
9403
9404
9405
9406
9407
9408
9409
9410
9411
9412
9413
9414
9415
9416
9417
9418
9419
9420
9421
9422
9423
9424
9425
9426
9427
9428
9429
9430
9431
9432
9433
9434
9435
9436
9437
9438
9439
9440
9441
9442
9443
9444
9445
9446
9447
9448
9449
9450
9451
9452
9453
9454
9455
9456
9457
9458
9459
9460
9461
9462
9463
9464
9465
9466
9467
9468
9469
9470
9471
9472
9473
9474
9475
9476
9477
9478
9479
9480
9481
9482
9483
9484
9485
9486
9487
9488
9489
9490
9491
9492
9493
9494
9495
9496
9497
9498
9499
9500
9501
9502
9503
9504
9505
9506
9507
9508
9509
9510
9511
9512
9513
9514
9515
9516
9517
9518
9519
9520
9521
9522
9523
9524
9525
9526
9527
9528
9529
9530
9531
9532
9533
9534
9535
9536
9537
9538
9539
9540
9541
9542
9543
9544
9545
9546
9547
9548
9549
9550
9551
9552
9553
9554
9555
9556
9557
9558
9559
9560
9561
9562
9563
9564
9565
9566
9567
9568
9569
9570
9571
9572
9573
9574
9575
9576
9577
9578
9579
9580
9581
9582
9583
9584
9585
9586
9587
9588
9589
9590
9591
9592
9593
9594
9595
9596
9597
9598
9599
9600
9601
9602
9603
9604
9605
9606
9607
9608
9609
9610
9611
9612
9613
9614
9615
9616
9617
9618
9619
9620
9621
9622
9623
9624
9625
9626
9627
9628
9629
9630
9631
9632
9633
9634
9635
9636
9637
9638
9639
9640
9641
9642
9643
9644
9645
9646
9647
9648
9649
9650
9651
9652
9653
9654
9655
9656
9657
9658
9659
9660
9661
9662
9663
9664
9665
9666
9667
9668
9669
9670
9671
9672
9673
9674
9675
9676
9677
9678
9679
9680
9681
9682
9683
9684
9685
9686
9687
9688
9689
9690
9691
9692
9693
9694
9695
9696
9697
9698
9699
9700
9701
9702
9703
9704
9705
9706
9707
9708
9709
9710
9711
9712
9713
9714
9715
9716
9717
9718
9719
9720
9721
9722
9723
9724
9725
9726
9727
9728
9729
9730
9731
9732
9733
9734
9735
9736
9737
9738
9739
9740
9741
9742
9743
9744
9745
9746
9747
9748
9749
9750
9751
9752
9753
9754
9755
9756
9757
9758
9759
9760
9761
9762
9763
9764
9765
9766
9767
9768
9769
9770
9771
9772
9773
9774
9775
9776
9777
9778
9779
9780
9781
9782
9783
9784
9785
9786
9787
9788
9789
9790
9791
9792
9793
9794
9795
9796
9797
9798
9799
9800
9801
9802
9803
9804
9805
9806
9807
9808
9809
9810
9811
9812
9813
9814
9815
9816
9817
9818
9819
9820
9821
9822
9823
9824
9825
9826
9827
9828
9829
9830
9831
9832
9833
9834
9835
9836
9837
9838
9839
9840
9841
9842
9843
9844
9845
9846
9847
9848
9849
9850
9851
9852
9853
9854
9855
9856
9857
9858
9859
9860
9861
9862
9863
9864
9865
9866
9867
9868
9869
9870
9871
9872
9873
9874
9875
9876
9877
9878
9879
9880
9881
9882
9883
9884
9885
9886
9887
9888
9889
9890
9891
9892
9893
9894
9895
9896
9897
9898
9899
9900
9901
9902
9903
9904
9905
9906
9907
9908
9909
9910
9911
9912
9913
9914
9915
9916
9917
9918
9919
9920
9921
9922
9923
9924
9925
9926
9927
9928
9929
9930
9931
9932
9933
9934
9935
9936
9937
9938
9939
9940
9941
9942
9943
9944
9945
9946
9947
9948
9949
9950
9951
9952
9953
9954
9955
9956
9957
9958
9959
9960
9961
9962
9963
9964
9965
9966
9967
9968
9969
9970
9971
9972
9973
9974
9975
9976
9977
9978
9979
9980
9981
9982
9983
9984
9985
9986
9987
9988
9989
9990
9991
9992
9993
9994
9995
9996
9997
9998
9999
10000
10001
10002
10003
10004
10005
10006
10007
10008
10009
10010
10011
10012
10013
10014
10015
10016
10017
10018
10019
10020
10021
10022
10023
10024
10025
10026
10027
10028
10029
10030
10031
10032
10033
10034
10035
10036
10037
10038
10039
10040
10041
10042
10043
10044
10045
10046
10047
10048
10049
10050
10051
10052
10053
10054
10055
10056
10057
10058
10059
10060
10061
10062
10063
10064
10065
10066
10067
10068
10069
10070
10071
10072
10073
10074
10075
10076
10077
10078
10079
10080
10081
10082
10083
10084
10085
10086
10087
10088
10089
10090
10091
10092
10093
10094
10095
10096
10097
10098
10099
10100
10101
10102
10103
10104
10105
10106
10107
10108
10109
10110
10111
10112
10113
10114
10115
10116
10117
10118
10119
10120
10121
10122
10123
10124
10125
10126
10127
10128
10129
10130
<!DOCTYPE html>
<html lang="en" prefix="og: https://ogp.me/ns#">
    <head>
        <meta charset="utf-8"/>
        <title>Releases | GrapheneOS</title>
        <meta name="description" content="Official releases of GrapheneOS, a security and privacy focused mobile OS with Android app compatibility."/>
        <meta name="theme-color" content="#212121"/>
        <meta name="color-scheme" content="dark light"/>
        <meta name="msapplication-TileColor" content="#ffffff"/>
        <meta name="viewport" content="width=device-width, initial-scale=1"/>
        <meta name="twitter:site" content="@GrapheneOS"/>
        <meta name="twitter:creator" content="@GrapheneOS"/>
        <meta property="og:title" content="GrapheneOS releases"/>
        <meta property="og:description" content="Official releases of GrapheneOS, a security and privacy focused mobile OS with Android app compatibility."/>
        <meta property="og:type" content="website"/>
        <meta property="og:image" content="https://grapheneos.org/opengraph.png"/>
        <meta property="og:image:width" content="512"/>
        <meta property="og:image:height" content="512"/>
        <meta property="og:image:alt" content="GrapheneOS logo"/>
        <meta property="og:site_name" content="GrapheneOS"/>
        <meta property="og:url" content="https://grapheneos.org/releases"/>
        <link rel="canonical" href="https://grapheneos.org/releases"/>
        <link rel="alternate" type="application/atom+xml" href="/releases.atom"/>
        <link rel="icon" href="/favicon.ico"/>
        <link rel="icon" sizes="any" type="image/svg+xml" href="/favicon.svg"/>
        <link rel="mask-icon" href="[[path|/mask-icon.svg]]" color="#1a1a1a"/>
        <link rel="apple-touch-icon" href="/apple-touch-icon.png"/>
        [[css|/main.css]]
        <link rel="manifest" href="/manifest.webmanifest"/>
        <link rel="license" href="/LICENSE.txt"/>
        <link rel="me" href="https://grapheneos.social/@GrapheneOS"/>
        [[js|/js/releases.js]]
        [[js|/js/redirect.js]]
    </head>
    <body>
        {% with current_page="releases" %}
            {% include "header.html" %}
        {% endwith %}
        <main id="releases">
            <h1><a href="#releases">Releases</a></h1>

            <nav id="table-of-contents">
                <h2><a href="#table-of-contents">Table of contents</a></h2>
                <ul>
                    <li><a href="#about-the-releases">About the releases</a></li>
                    <li><a href="#release-announcements">Release announcements</a></li>
                    <li>
                        <a href="#devices">Devices</a>
                        <ul>
                            <li><a href="#tegu">Pixel 9a</a></li>
                            <li><a href="#comet">Pixel 9 Pro Fold</a></li>
                            <li><a href="#komodo">Pixel 9 Pro XL</a></li>
                            <li><a href="#caiman">Pixel 9 Pro</a></li>
                            <li><a href="#tokay">Pixel 9</a></li>
                            <li><a href="#akita">Pixel 8a</a></li>
                            <li><a href="#husky">Pixel 8 Pro</a></li>
                            <li><a href="#shiba">Pixel 8</a></li>
                            <li><a href="#felix">Pixel Fold</a></li>
                            <li><a href="#tangorpro">Pixel Tablet</a></li>
                            <li><a href="#lynx">Pixel 7a</a></li>
                            <li><a href="#cheetah">Pixel 7 Pro</a></li>
                            <li><a href="#panther">Pixel 7</a></li>
                            <li><a href="#bluejay">Pixel 6a</a></li>
                            <li><a href="#raven">Pixel 6 Pro</a></li>
                            <li><a href="#oriole">Pixel 6</a></li>
                            <li><a href="#barbet">Pixel 5a (legacy extended support)</a></li>
                            <li><a href="#redfin">Pixel 5 (legacy extended support)</a></li>
                            <li><a href="#bramble">Pixel 4a (5G) (legacy extended support)</a></li>
                            <li><a href="#sunfish">Pixel 4a (legacy extended support)</a></li>
                            <li><a href="#coral">Pixel 4 XL (legacy extended support)</a></li>
                            <li><a href="#flame">Pixel 4 (legacy extended support)</a></li>
                        </ul>
                    </li>
                    <li>
                        <a href="#changelog">Changelog</a>
                        <ul>
                            <li><a href="#2025051900">2025051900</a></li>
                            <li><a href="#2025050700">2025050700</a></li>
                            <li><a href="#2025050500">2025050500</a></li>
                            <li><a href="#2025050300">2025050300</a></li>
                            <li><a href="#2025042500">2025042500</a></li>
                            <li><a href="#2025041100">2025041100</a></li>
                            <li><a href="#2025040700">2025040700</a></li>
                            <li><a href="#2025040400">2025040400</a></li>
                            <li><a href="#2025032500">2025032500</a></li>
                            <li><a href="#2025032100">2025032100</a></li>
                            <li><a href="#2025031400">2025031400</a></li>
                            <li><a href="#2025031300">2025031300</a></li>
                            <li><a href="#2025030900">2025030900</a></li>
                            <li><a href="#2025030800">2025030800</a></li>
                            <li><a href="#2025030700">2025030700</a></li>
                            <li><a href="#2025030500">2025030500</a></li>
                            <li><a href="#2025030300">2025030300</a></li>
                            <li><a href="#2025030200">2025030200</a></li>
                            <li><a href="#2025030100">2025030100</a></li>
                            <li><a href="#2025022800">2025022800</a></li>
                            <li><a href="#2025022700">2025022700</a></li>
                            <li><a href="#2025021100">2025021100</a></li>
                            <li><a href="#2025020500">2025020500</a></li>
                            <li><a href="#2025020300">2025020300</a></li>
                            <li><a href="#2025020200">2025020200</a></li>
                            <li><a href="#2025012700">2025012700</a></li>
                            <li><a href="#2025012600">2025012600</a></li>
                            <li><a href="#2025011500">2025011500</a></li>
                            <li><a href="#2025010700">2025010700</a></li>
                            <li><a href="#2024123000">2024123000</a></li>
                            <li><a href="#2024121200">2024121200</a></li>
                            <li><a href="#2024120900">2024120900</a></li>
                            <li><a href="#2024120702">2024120702</a></li>
                            <li><a href="#2024120701">2024120701</a></li>
                            <li><a href="#2024120700">2024120700</a></li>
                            <li><a href="#2024120400">2024120400</a></li>
                            <li><a href="#2024120200">2024120200</a></li>
                            <li><a href="#2024112700">2024112700</a></li>
                            <li><a href="#2024111800">2024111800</a></li>
                            <li><a href="#2024111700">2024111700</a></li>
                            <li><a href="#2024110700">2024110700</a></li>
                            <li><a href="#2024110400">2024110400</a></li>
                            <li><a href="#2024103100">2024103100</a></li>
                            <li><a href="#2024102400">2024102400</a></li>
                            <li><a href="#2024102100">2024102100</a></li>
                            <li><a href="#2024102000">2024102000</a></li>
                            <li><a href="#2024101900">2024101900</a></li>
                            <li><a href="#2024101801">2024101801</a></li>
                            <li><a href="#2024101800">2024101800</a></li>
                            <li><a href="#2024101701">2024101701</a></li>
                            <li><a href="#2024101700">2024101700</a></li>
                            <li><a href="#2024101600">2024101600</a></li>
                            <li><a href="#2024101200">2024101200</a></li>
                            <li><a href="#2024100800">2024100800</a></li>
                            <li><a href="#2024092900">2024092900</a></li>
                            <li><a href="#2024091900">2024091900</a></li>
                            <li><a href="#2024091700">2024091700</a></li>
                            <li><a href="#2024090400">2024090400</a></li>
                            <li><a href="#2024083100">2024083100</a></li>
                            <li><a href="#2024082200">2024082200</a></li>
                            <li><a href="#2024082000">2024082000</a></li>
                            <li><a href="#2024080600">2024080600</a></li>
                            <li><a href="#2024080500">2024080500</a></li>
                            <li><a href="#2024080200">2024080200</a></li>
                            <li><a href="#2024080100">2024080100</a></li>
                            <li><a href="#2024073100">2024073100</a></li>
                            <li><a href="#2024072800">2024072800</a></li>
                            <li><a href="#2024071600">2024071600</a></li>
                            <li><a href="#2024071200">2024071200</a></li>
                            <li><a href="#2024070900">2024070900</a></li>
                            <li><a href="#2024070201">2024070201</a></li>
                            <li><a href="#2024070200">2024070200</a></li>
                            <li><a href="#2024062700">2024062700</a></li>
                            <li><a href="#2024062000">2024062000</a></li>
                            <li><a href="#2024061400">2024061400</a></li>
                            <li><a href="#2024061300">2024061300</a></li>
                            <li><a href="#2024061200">2024061200</a></li>
                            <li><a href="#2024060500">2024060500</a></li>
                            <li><a href="#2024060400">2024060400</a></li>
                            <li><a href="#2024053100">2024053100</a></li>
                            <li><a href="#2024052100">2024052100</a></li>
                            <li><a href="#2024051500">2024051500</a></li>
                            <li><a href="#2024050900">2024050900</a></li>
                            <li><a href="#2024050700">2024050700</a></li>
                            <li><a href="#2024050300">2024050300</a></li>
                            <li><a href="#2024042200">2024042200</a></li>
                            <li><a href="#2024042100">2024042100</a></li>
                            <li><a href="#2024042000">2024042000</a></li>
                            <li><a href="#2024040900">2024040900</a></li>
                            <li><a href="#2024040300">2024040300</a></li>
                            <li><a href="#2024040200">2024040200</a></li>
                            <li><a href="#2024032100">2024032100</a></li>
                            <li><a href="#2024031400">2024031400</a></li>
                            <li><a href="#2024031100">2024031100</a></li>
                            <li><a href="#2024030900">2024030900</a></li>
                            <li><a href="#2024030800">2024030800</a></li>
                            <li><a href="#2024030700">2024030700</a></li>
                            <li><a href="#2024030600">2024030600</a></li>
                            <li><a href="#2024030300">2024030300</a></li>
                            <li><a href="#2024022800">2024022800</a></li>
                            <li><a href="#2024022600">2024022600</a></li>
                            <li><a href="#2024022300">2024022300</a></li>
                            <li><a href="#2024020500">2024020500</a></li>
                            <li><a href="#2024012600">2024012600</a></li>
                            <li><a href="#2024011600">2024011600</a></li>
                            <li><a href="#2024011300">2024011300</a></li>
                            <li><a href="#2024010400">2024010400</a></li>
                            <li><a href="#2023123100">2023123100</a></li>
                            <li><a href="#2023123000">2023123000</a></li>
                            <li><a href="#2023121200">2023121200</a></li>
                            <li><a href="#2023120800">2023120800</a></li>
                            <li><a href="#2023120701">2023120701</a></li>
                            <li><a href="#2023120700">2023120700</a></li>
                            <li><a href="#2023120400">2023120400</a></li>
                            <li><a href="#2023112900">2023112900</a></li>
                            <li><a href="#2023112600">2023112600</a></li>
                            <li><a href="#2023111500">2023111500</a></li>
                            <li><a href="#2023110700">2023110700</a></li>
                            <li><a href="#2023103100">2023103100</a></li>
                            <li><a href="#2023103000">2023103000</a></li>
                            <li><a href="#2023102300">2023102300</a></li>
                            <li><a href="#2023101300">2023101300</a></li>
                            <li><a href="#2023101100">2023101100</a></li>
                            <li><a href="#2023100900">2023100900</a></li>
                            <li><a href="#2023100800">2023100800</a></li>
                            <li><a href="#2023100300">2023100300</a></li>
                            <li><a href="#2023100100">2023100100</a></li>
                            <li><a href="#2023091800">2023091800</a></li>
                            <li><a href="#2023090600">2023090600</a></li>
                            <li><a href="#2023090200">2023090200</a></li>
                            <li><a href="#2023080800">2023080800</a></li>
                            <li><a href="#2023080700">2023080700</a></li>
                            <li><a href="#2023072600">2023072600</a></li>
                            <li><a href="#2023072400">2023072400</a></li>
                            <li><a href="#2023071100">2023071100</a></li>
                            <li><a href="#2023070500">2023070500</a></li>
                            <li><a href="#2023062800">2023062800</a></li>
                            <li><a href="#2023062300">2023062300</a></li>
                            <li><a href="#2023061402">2023061402</a></li>
                            <li><a href="#2023061400">2023061400</a></li>
                            <li><a href="#2023060700">2023060700</a></li>
                            <li><a href="#2023052900">2023052900</a></li>
                            <li><a href="#2023052800">2023052800</a></li>
                            <li><a href="#2023051600">2023051600</a></li>
                            <li><a href="#2023050500">2023050500</a></li>
                            <li><a href="#2023050100">2023050100</a></li>
                            <li><a href="#2023042900">2023042900</a></li>
                            <li><a href="#2023041100">2023041100</a></li>
                            <li><a href="#2023040400">2023040400</a></li>
                            <li><a href="#2023032600">2023032600</a></li>
                            <li><a href="#2023032000">2023032000</a></li>
                            <li><a href="#2023031500">2023031500</a></li>
                            <li><a href="#2023031300">2023031300</a></li>
                            <li><a href="#2023030400">2023030400</a></li>
                            <li><a href="#2023022300">2023022300</a></li>
                            <li><a href="#2023021000">2023021000</a></li>
                            <li><a href="#2023020600">2023020600</a></li>
                            <li><a href="#2023020200">2023020200</a></li>
                            <li><a href="#2023012500">2023012500</a></li>
                            <li><a href="#2023011000">2023011000</a></li>
                            <li><a href="#2023010300">2023010300</a></li>
                            <li><a href="#2022122700">2022122700</a></li>
                            <li><a href="#2022122000">2022122000</a></li>
                            <li><a href="#2022121400">2022121400</a></li>
                            <li><a href="#2022121100">2022121100</a></li>
                            <li><a href="#2022120700">2022120700</a></li>
                            <li><a href="#2022120600">2022120600</a></li>
                            <li><a href="#2022120300">2022120300</a></li>
                            <li><a href="#2022113000">2022113000</a></li>
                            <li><a href="#2022112500">2022112500</a></li>
                            <li><a href="#2022111800">2022111800</a></li>
                            <li><a href="#2022111000">2022111000</a></li>
                            <li><a href="#2022110800">2022110800</a></li>
                            <li><a href="#2022110600">2022110600</a></li>
                            <li><a href="#2022110400">2022110400</a></li>
                            <li><a href="#2022102800">2022102800</a></li>
                            <li><a href="#2022102600">2022102600</a></li>
                            <li><a href="#2022102300">2022102300</a></li>
                            <li><a href="#2022101800">2022101800</a></li>
                            <li><a href="#2022101600">2022101600</a></li>
                            <li><a href="#2022101500">2022101500</a></li>
                            <li><a href="#2022101400">2022101400</a></li>
                            <li><a href="#2022101200">2022101200</a></li>
                            <li><a href="#2022100300">2022100300</a></li>
                            <li><a href="#2022092800">2022092800</a></li>
                            <li><a href="#2022092300">2022092300</a></li>
                            <li><a href="#2022092200">2022092200</a></li>
                            <li><a href="#2022092000">2022092000</a></li>
                            <li><a href="#2022091400">2022091400</a></li>
                            <li><a href="#2022091300">2022091300</a></li>
                            <li><a href="#2022090600">2022090600</a></li>
                            <li><a href="#2022090400">2022090400</a></li>
                            <li><a href="#2022083000">2022083000</a></li>
                            <li><a href="#2022082400">2022082400</a></li>
                            <li><a href="#2022082301">2022082301</a></li>
                            <li><a href="#2022082300">2022082300</a></li>
                            <li><a href="#2022082200">2022082200</a></li>
                            <li><a href="#2022082100">2022082100</a></li>
                            <li><a href="#2022081800">2022081800</a></li>
                            <li><a href="#2022081600">2022081600</a></li>
                            <li><a href="#2022080900">2022080900</a></li>
                            <li><a href="#2022080500">2022080500</a></li>
                            <li><a href="#2022080300">2022080300</a></li>
                            <li><a href="#2022073000">2022073000</a></li>
                            <li><a href="#2022072700">2022072700</a></li>
                            <li><a href="#2022072000">2022072000</a></li>
                            <li><a href="#2022071300">2022071300</a></li>
                            <li><a href="#2022071100">2022071100</a></li>
                            <li><a href="#2022070800">2022070800</a></li>
                            <li><a href="#2022070600">2022070600</a></li>
                            <li><a href="#2022063000">2022063000</a></li>
                            <li><a href="#2022062200">2022062200</a></li>
                            <li><a href="#2022061600">2022061600</a></li>
                            <li><a href="#2022060701">2022060701</a></li>
                            <li><a href="#2022060700">2022060700</a></li>
                            <li><a href="#2022053100">2022053100</a></li>
                            <li><a href="#2022052500">2022052500</a></li>
                            <li><a href="#2022051100">2022051100</a></li>
                            <li><a href="#2022050800">2022050800</a></li>
                            <li><a href="#2022050700">2022050700</a></li>
                            <li><a href="#2022050301">2022050301</a></li>
                            <li><a href="#2022050300">2022050300</a></li>
                            <li><a href="#2022043000">2022043000</a></li>
                            <li><a href="#2022042600">2022042600</a></li>
                            <li><a href="#2022042000">2022042000</a></li>
                            <li><a href="#2022041900">2022041900</a></li>
                            <li><a href="#2022041600">2022041600</a></li>
                            <li><a href="#2022041300">2022041300</a></li>
                            <li><a href="#2022041100">2022041100</a></li>
                            <li><a href="#2022040400">2022040400</a></li>
                            <li><a href="#2022033013">2022033013</a></li>
                            <li><a href="#2022032715">2022032715</a></li>
                            <li><a href="#2022032110">2022032110</a></li>
                            <li><a href="#2022031103">2022031103</a></li>
                            <li><a href="#2022030801">2022030801</a></li>
                            <li><a href="#2022030501">2022030501</a></li>
                            <li><a href="#2022030219">2022030219</a></li>
                            <li><a href="#2022022818">2022022818</a></li>
                            <li><a href="#2022021721">2022021721</a></li>
                            <li><a href="#2022021602">2022021602</a></li>
                            <li><a href="#2022021415">2022021415</a></li>
                            <li><a href="#2022021314">2022021314</a></li>
                            <li><a href="#2022020800">2022020800</a></li>
                            <li><a href="#2022013120">2022013120</a></li>
                            <li><a href="#2022013010">2022013010</a></li>
                            <li><a href="#2022011423">2022011423</a></li>
                            <li><a href="#2022011009">2022011009</a></li>
                            <li><a href="#2022010500">2022010500</a></li>
                            <li><a href="#2021122018">2021122018</a></li>
                            <li><a href="#2021121602">2021121602</a></li>
                            <li><a href="#2021121012">2021121012</a></li>
                            <li><a href="#2021120717">2021120717</a></li>
                            <li><a href="#2021112404">2021112404</a></li>
                            <li><a href="#2021112123">2021112123</a></li>
                            <li><a href="#2021112021">2021112021</a></li>
                            <li><a href="#2021111414">2021111414</a></li>
                            <li><a href="#2021110617">2021110617</a></li>
                            <li><a href="#2021110507">2021110507</a></li>
                            <li><a href="#2021110122">2021110122</a></li>
                            <li><a href="#2021102613">2021102613</a></li>
                            <li><a href="#2021102503">2021102503</a></li>
                            <li><a href="#2021102300">2021102300</a></li>
                            <li><a href="#2021102203">2021102203</a></li>
                            <li><a href="#2021102020">2021102020</a></li>
                            <li><a href="#2021100606">2021100606</a></li>
                            <li><a href="#2021100502">2021100502</a></li>
                            <li><a href="#2021100103">2021100103</a></li>
                            <li><a href="#2021092612">2021092612</a></li>
                            <li><a href="#2021092220">2021092220</a></li>
                            <li><a href="#2021091407">2021091407</a></li>
                            <li><a href="#2021090819">2021090819</a></li>
                            <li><a href="#2021090401">2021090401</a></li>
                            <li><a href="#2021082501">2021082501</a></li>
                            <li><a href="#2021081822">2021081822</a></li>
                            <li><a href="#2021081411">2021081411</a></li>
                            <li><a href="#2021.08.09.02">2021.08.09.02</a></li>
                            <li><a href="#2021.08.03.03">2021.08.03.03</a></li>
                            <li><a href="#2021.07.26.20">2021.07.26.20</a></li>
                            <li><a href="#2021.07.19.18">2021.07.19.18</a></li>
                            <li><a href="#2021.07.16.19">2021.07.16.19</a></li>
                            <li><a href="#2021.07.07.19">2021.07.07.19</a></li>
                            <li><a href="#2021.06.20.20">2021.06.20.20</a></li>
                            <li><a href="#2021.06.09.13">2021.06.09.13</a></li>
                            <li><a href="#2021.06.08.06">2021.06.08.06</a></li>
                            <li><a href="#2021.05.29.09">2021.05.29.09</a></li>
                            <li><a href="#2021.05.19.06">2021.05.19.06</a></li>
                            <li><a href="#2021.05.16.04">2021.05.16.04</a></li>
                            <li><a href="#2021.05.04.01">2021.05.04.01</a></li>
                            <li><a href="#2021.04.22.20">2021.04.22.20</a></li>
                            <li><a href="#2021.04.16.04">2021.04.16.04</a></li>
                            <li><a href="#2021.04.05.20">2021.04.05.20</a></li>
                            <li><a href="#2021.03.30.02">2021.03.30.02</a></li>
                            <li><a href="#2021.03.19.14">2021.03.19.14</a></li>
                            <li><a href="#2021.03.06.00">2021.03.06.00</a></li>
                            <li><a href="#2021.03.02.10">2021.03.02.10</a></li>
                            <li><a href="#2021.02.26.16">2021.02.26.16</a></li>
                            <li><a href="#2021.02.23.15">2021.02.23.15</a></li>
                            <li><a href="#2021.02.19.15">2021.02.19.15</a></li>
                            <li><a href="#2021.02.07.17">2021.02.07.17</a></li>
                            <li><a href="#2021.02.06.05">2021.02.06.05</a></li>
                            <li><a href="#2021.02.02.09">2021.02.02.09</a></li>
                            <li><a href="#2021.01.23.03">2021.01.23.03</a></li>
                            <li><a href="#2021.01.05.03">2021.01.05.03</a></li>
                            <li><a href="#2020.12.12.03">2020.12.12.03</a></li>
                            <li><a href="#2020.12.08.08">2020.12.08.08</a></li>
                            <li><a href="#2020.11.27.15">2020.11.27.15</a></li>
                            <li><a href="#2020.11.25.22">2020.11.25.22</a></li>
                            <li><a href="#2020.11.05.18">2020.11.05.18</a></li>
                            <li><a href="#2020.11.03.03">2020.11.03.03</a></li>
                            <li><a href="#2020.10.23.04">2020.10.23.04</a></li>
                            <li><a href="#2020.10.06.02">2020.10.06.02</a></li>
                            <li><a href="#2020.10.01.23">2020.10.01.23</a></li>
                            <li><a href="#2020.09.29.20">2020.09.29.20</a></li>
                            <li><a href="#2020.09.25.00">2020.09.25.00</a></li>
                            <li><a href="#2020.09.18.13">2020.09.18.13</a></li>
                            <li><a href="#2020.09.11.14">2020.09.11.14</a></li>
                            <li><a href="#2020.09.10.05">2020.09.10.05</a></li>
                            <li><a href="#2020.08.07.01">2020.08.07.01</a></li>
                            <li><a href="#2020.08.03.22">2020.08.03.22</a></li>
                            <li><a href="#2020.07.06.20">2020.07.06.20</a></li>
                            <li><a href="#2020.06.22.21">2020.06.22.21</a></li>
                            <li><a href="#2020.06.02.02">2020.06.02.02</a></li>
                            <li><a href="#2020.05.29.00">2020.05.29.00</a></li>
                            <li><a href="#2020.05.23.12">2020.05.23.12</a></li>
                            <li><a href="#2020.05.05.02">2020.05.05.02</a></li>
                            <li><a href="#2020.04.14.23">2020.04.14.23</a></li>
                            <li><a href="#2020.04.13.21">2020.04.13.21</a></li>
                            <li><a href="#2020.04.07.10">2020.04.07.10</a></li>
                            <li><a href="#2020.03.23.22">2020.03.23.22</a></li>
                            <li><a href="#2020.03.04.16">2020.03.04.16</a></li>
                            <li><a href="#2020.03.03.03">2020.03.03.03</a></li>
                            <li><a href="#2020.02.07.19">2020.02.07.19</a></li>
                            <li><a href="#2020.02.04.01">2020.02.04.01</a></li>
                            <li><a href="#2020.01.06.21">2020.01.06.21</a></li>
                            <li><a href="#2019.12.02.23">2019.12.02.23</a></li>
                            <li><a href="#2019.11.05.23">2019.11.05.23</a></li>
                            <li><a href="#2019.11.04.23">2019.11.04.23</a></li>
                            <li><a href="#2019.10.07.21">2019.10.07.21</a></li>
                            <li><a href="#2019.09.25.00">2019.09.25.00</a></li>
                            <li><a href="#2019.09.23.19">2019.09.23.19</a></li>
                            <li><a href="#2019.09.21.18">2019.09.21.18</a></li>
                            <li><a href="#2019.09.18.14">2019.09.18.14</a></li>
                            <li><a href="#2019.08.25.15">2019.08.25.15</a></li>
                            <li><a href="#2019.08.05.19">2019.08.05.19</a></li>
                            <li><a href="#2019.07.16.22">2019.07.16.22</a></li>
                            <li><a href="#2019.07.01.21">2019.07.01.21</a></li>
                            <li><a href="#2019.06.23.05">2019.06.23.05</a></li>
                            <li><a href="#2019.06.14.02">2019.06.14.02</a></li>
                            <li><a href="#2019.06.03.18">2019.06.03.18</a></li>
                            <li><a href="#2019.05.18.20">2019.05.18.20</a></li>
                            <li><a href="#2019.05.08.15">2019.05.08.15</a></li>
                            <li><a href="#2019.05.07.00">2019.05.07.00</a></li>
                            <li><a href="#2019.04.01.19">2019.04.01.19</a></li>
                            <li><a href="#2019.03.05.03">2019.03.05.03</a></li>
                        </ul>
                    </li>
                </ul>
            </nav>

            <section id="about-the-releases">
                <h2><a href="#about-the-releases">About the releases</a></h2>

                <p>These releases are available as both tags in the source code repositories and
                official builds.</p>

                <p>The factory images are used for the initial installation and can be verified with
                signify. See the <a href="/install/">installation page</a> for details.</p>

                <p>GrapheneOS uses automatic over-the-air updates, but full update packages are listed
                below for uncommon use cases like never connecting the device to the internet. A full
                update package can upgrade from any past version to the new version. The over-the-air
                updates use delta update packages when available. Those aren't currently linked below
                but may be in the future once they're being used more consistently. Update packages
                are not for performing the initial installation and you should ignore incorrect guides
                trying to use them to install the OS.</p>

                <p>The update packages have an internal signature verified by the update client (or
                recovery when sideloading). Downgrade attacks are also prevented, and downgrades
                cannot be done unless a special downgrade update package has been signed with the
                release key. The internal payload for <code>update_engine</code> is also signed,
                providing another layer of signature verification and downgrade protection. Verified
                boot and the hardware-backed keystore also act as a final layer of protection.</p>

                <p>Releases are tested by the developers and are then pushed out via the Alpha
                channel. The release is then pushed out via the Beta channel shortly afterwards.
                Finally, the release is then pushed out via the Stable channel after being tested
                by users using the Beta channel. In some cases, problems are caught during Beta
                channel testing and a new release is made via the Beta channel to replace the
                aborted one. In general, it's not possible to downgrade unless a downgrade update
                package is generated, so use the Stable channel if you cannot tolerate dealing with
                temporary issues while a new release for the Beta channel is being created.</p>
            </section>

            <section id="release-announcements">
                <h2><a href="#release-announcements">Release announcements</a></h2>

                <p>Releases are announced on this page and included in an <a
                href="/releases.atom">atom feed</a> usable from any standard
                feed reader app. A release announcement indicates that the
                source code tags are available and that the official builds
                will soon be pushed out via the Alpha channel.</p>

                <p>The main place to discuss the releases are the
                threads posted on our <a href="https://discuss.grapheneos.org">our discussion forum</a>
                with the <a href="https://discuss.grapheneos.org/t/announcements">Announcements tag</a>.</p>

                <p>The announcements are also posted from the <a
                href="https://x.com/GrapheneOS">@GrapheneOS X account</a>, the <a
                href="https://grapheneos.social/@GrapheneOS">@GrapheneOS Mastodon account</a>, the
                <a href="https://bsky.app/profile/grapheneos.org"> @grapheneos.org Bluesky
                account</a>, the <a href="https://reddit.com/r/GrapheneOS"> official subreddit</a>,
                and in the official <a href="/contact#community">GrapheneOS chat rooms</a> including
                the dedicated releases room/channel on the respective chat platform (Matrix,
                Discord, Telegram). Each of these links to the main discussion thread on our
                discussion forum.</p>
            </section>

            <section id="devices">
                <h2><a href="#devices">Devices</a></h2>

                {% with codename="tegu", name="Pixel 9a", split=True %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="comet", name="Pixel 9 Pro Fold" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="komodo", name="Pixel 9 Pro XL" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="caiman", name="Pixel 9 Pro" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="tokay", name="Pixel 9" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="akita", name="Pixel 8a" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="husky", name="Pixel 8 Pro" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="shiba", name="Pixel 8" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="felix", name="Pixel Fold" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="tangorpro", name="Pixel Tablet" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="lynx", name="Pixel 7a" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="cheetah", name="Pixel 7 Pro" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="panther", name="Pixel 7" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="bluejay", name="Pixel 6a" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="raven", name="Pixel 6 Pro" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="oriole", name="Pixel 6" %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="barbet", name="Pixel 5a (legacy extended support)", split=True %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="redfin", name="Pixel 5 (legacy extended support)", split=True %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="bramble", name="Pixel 4a (5G) (legacy extended support) ", split=True %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="sunfish", name="Pixel 4a (legacy extended support)", install="factory", split=True %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="coral", name="Pixel 4 XL (legacy extended support)", install="factory", split=True %}
                    {% include "device.html" %}
                {% endwith %}
                {% with codename="flame", name="Pixel 4 (legacy extended support)", install="factory", split=True %}
                    {% include "device.html" %}
                {% endwith %}
            </section>

            <section id="changelog">
                <h2><a href="#changelog">Changelog</a></h2>

                <p>List of tagged releases. Snapshot releases without tags such as early releases of
                the project and early device support releases are not listed.</p>

                <p>The changelog is also available as an <a href="/releases.atom">atom feed</a>
                usable in any standard feed reader.</p>

                <p>The <a href="/history/legacy-changelog">legacy changelog page</a> has the
                release notes from before the rebranding of the project in 2018 and 2019.</p>

                <!--
                <article id="2025051900">
                    <h3><a href="#2025051900">2025051900</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025051900">2025051900</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025051900 release:</p>

                    <ul>
                    </ul>
                </article>
                -->

                <article id="2025051900">
                    <h3><a href="#2025051900">2025051900</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025051900">2025051900</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025050700 release:</p>

                    <ul>
                        <li>add NFC auto-turn-off setting to go along with the existing addition of Wi-Fi and Bluetooth auto-turn-off settings</li>
                        <li>Private Space: add new setting for disabling delayed locking of storage to make locking work like secondary user end session feature we enable, similar to the toggle we add for disabling secondary users running in the background (standard Private Space doesn't work this way to keep fingerprint unlock available after it's locked/stopped)</li>
                        <li>Private Space: add new setting for blocking sharing the clipboard to and/or from the parent profile and other nested profiles within it</li>
                        <li>Private Space: add support for the Install available apps feature we currently enable to support installing apps available in the Owner user to secondary users</li>
                        <li>Private Space: add support for secondary users including all standard features with the exception of auto-locking support since our implementation of that is too complex/invasive to properly review and test while we're focused on Android 16 porting</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.138</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.89</li>
                        <li>Keyboard: move the emoji key to the left of the space bar for the phone layout instead of putting it behind a long press or replacing the enter key with it when put into the emoji mode by apps like AOSP Messaging</li>
                        <li>Keyboard: stop replacing the emoji key with the .com key for the email and URL input types</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/136.0.7103.125.0">version 136.0.7103.125.0</a></li>
                        <li>add support for testing Android 16 Beta 4.1 feature flags for development builds</li>
                    </ul>
                </article>

                <article id="2025050700">
                    <h3><a href="#2025050700">2025050700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025050700">2025050700</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025050500 release:</p>

                    <ul>
                        <li>full 2025-05-05 security patch level</li>
                        <li>rebased onto BP1A.250505.005.D1 Android Open Source Project release</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/136.0.7103.87.0">version 136.0.7103.87.0</a></li>
                    </ul>
                </article>

                <article id="2025050500">
                    <h3><a href="#2025050500">2025050500</a></h3>

                    <p>This is an early May security update release based on the May 2025 security
                    patch backports since the monthly Android Open Source Project and stock Pixel OS
                    release scheduled for this month hasn't been published yet. </p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025050500">2025050500</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025050300 release:</p>

                    <ul>
                        <li>full 2025-05-01 security patch level</li>
                    </ul>
                </article>

                <article id="2025050300">
                    <h3><a href="#2025050300">2025050300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025050300">2025050300</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025042500 release:</p>

                    <ul>
                        <li>extend security state manager service to support the official Auditor release (based on the signing key) obtaining additional security state (currently the configuration for auto-reboot, USB-C port and pogo pins control, OEM unlocking and user count)</li>
                        <li>Auditor: add default enabled data saver exemption</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): switch to synchronous mode for the Hardware Tag-Based KASAN implementation to improve security and error reporting (we'll continue using asymmetric mode in userspace where it provides very comparable security and error reporting to synchronous mode with lower overhead)</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.1): revert upstream Linux kernel change attempting to work around frame drops caused by a workaround used by video players on X11-based platforms (irrelevant to Android) due to it breaking DisplayPort alternate mode audio</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.88</li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/29">version 29</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/30">version 30</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/136.0.7103.60.0">version 136.0.7103.60.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-157">version 157</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-158">version 158</a></li>
                    </ul>
                </article>

                <article id="2025042500">
                    <h3><a href="#2025042500">2025042500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025042500">2025042500</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025041100 release:</p>

                    <ul>
                        <li>Bluetooth: backport upstream fixes for compatibility with certain Bluetooth peripherals caused by a recent security fix for Bluetooth encryption</li>
                        <li>avoid granting special runtime permissions (Network, Sensors) added by GrapheneOS when unarchiving an app</li>
                        <li>use our restricted setting infrastructure to restrict system app access to our notification forwarding setting too</li>
                        <li>Settings: prevent disabling system Dialer app since it's always required for emergency calls</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.134</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.87</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/135.0.7049.100.0">version 135.0.7049.100.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/135.0.7049.111.0">version 135.0.7049.111.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/136.0.7103.44.0">version 136.0.7103.44.0</a></li>
                    </ul>
                </article>

                <article id="2025041100">
                    <h3><a href="#2025041100">2025041100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025041100">2025041100</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025040700 release:</p>

                    <ul>
                        <li>full 2025-04-05 security patch level</li>
                        <li>rebased onto BP1A.250405.007.D1 Android Open Source Project release</li>
                        <li>remove code for Qualcomm XTRA (PSDS) privacy improvements since we no longer have any devices with Qualcomm GNSS and we can add it back in the future if we need it again rather than porting it forward under the assumption we'll be using it</li>
                        <li>fix upstream RecoverySystem.verifyPackage(...) vulnerability (this was not directly exploitable due to there being 2 layers of update package signature verification and downgrade protection, but the first layer of protection should work properly to avoid a vulnerability in the 2nd layer being exploited)</li>
                        <li>Android Debug Bridge: more complete fix for upstream use-after-free bug for network-based connections which is being caught by our always enabled hardware memory tagging support for the base OS in hardened_malloc</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.83</li>
                        <li>Seedvault: update to 15-5.5 (will be replaced with a better backup implementation in the future)</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/135.0.7049.79.0">version 135.0.7049.79.0</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/88">version 88</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/27">version 27</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/28">version 28</a></li>
                    </ul>
                </article>

                <article id="2025040700">
                    <h3><a href="#2025040700">2025040700</a></h3>

                    <p>This is an early April security update release based on the April 2025
                    security patch backports since the monthly Android Open Source Project and stock
                    Pixel OS release scheduled for this month hasn't been published yet. </p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025040700">2025040700</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025040400 release:</p>

                    <ul>
                        <li>full 2025-04-01 security patch level</li>
                    </ul>
                </article>

                <article id="2025040400">
                    <h3><a href="#2025040400">2025040400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025040400">2025040400</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025032500 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: remove StatsManager from hidden services and replace that approach with stubbing out all of the methods since Play services recently introduced new code using it that's missing a null check and triggers a null pointer exception which has blocked us from pushing out the newer versions of Play services beyond our App Store's Alpha channel</li>
                        <li>Network Location: switch to making at most a single request to the service per position estimation by requesting up to 40 Wi-Fi APs at once</li>
                        <li>Network Location: optimize making requests to the service for Wi-Fi AP data</li>
                        <li>Network Location: optimize Rust JNI bindings to the point that it no longer causes a noticeable overhead without introducing unsafe code (it could be optimized further with unsafe code to cache more JNI binding work but the difference is insignificant so we don't plan to do it)</li>
                        <li>Network Location: use correct Accept header value to more closely match macOS to avoid future compatibility issues</li>
                        <li>fix upstream system_server crash from null pointer exception in F2fsUtils</li>
                        <li>add infrastructure for more restricted access to global and per-user settings instead of allowing all system apps to read them and all privileged systems apps with the WRITE_SECURE_SETTINGS privileged permission to write them</li>
                        <li>further restrict access to all global and per-user settings added by GrapheneOS with our new infrastructure</li>
                        <li>replace disabling the unused ADD_USERS_WHEN_LOCKED and ENABLE_EPHEMERAL_FEATURE settings at boot with a new approach of making settings immutable in the code, which we can expand in the future to other problematic settings not used by GrapheneOS</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.131</li>
                        <li>kernel (6.1): drop revert for upstream USB fix causing DisplayPort alternate mode regression due to another upstream patch successfully fixing it</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/135.0.7049.38.0">version 135.0.7049.38.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-155">version 155</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-156">version 156</a></li>
                    </ul>
                </article>

                <article id="2025032500">
                    <h3><a href="#2025032500">2025032500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025032500">2025032500</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025032100 release:</p>

                    <ul>
                        <li>Network Location: rewrite position estimation in Rust (from Kotlin) with a new algorithm based on Expectation-Maximization (EM) always using 3D (altitude) to provide much better accuracy, robustness and performance (this new 3D implementation performs better than the previous implementation in the 2D mode we were stuck using due to 3D being far too CPU intensive)</li>
                        <li>Network Location: improve RSSI-based (signal strength) distance estimation including tuning it separately for 2.4GHz vs. 5GHz/6GHz and take distance variance into account for position estimation (Wi-Fi Round-Trip-Time support will be added in the future for Access Points supporting it)</li>
                        <li>Network Location: add support for 6GHz Wi-Fi networks via Reduced Neighbor Report (RNR)</li>
                        <li>Network Location: increase the number of closest APs we explicitly request data for from 5 to 15</li>
                        <li>Network Location: request data for up to 4 APs at a time instead of only 1 to improve networking efficiency</li>
                        <li>Network Location: make our requests more closely match a current macOS release to avoid future compatibility issues and to get Apple's service to provide more than only 2.4GHz networks as nearby networks in response to queries</li>
                        <li>Network Location: reduce requesting data for 100 additional nearby Wi-Fi APs down to 8 APs when a decent amount of additional results were returned from a recent request for up to 100 in the past 10 seconds</li>
                        <li>backport upstream brightness fluctuation fix from Android 16 Beta 3.1</li>
                        <li>Sandboxed Google Play compatibility layer: fix Location Accuracy link with Play services 25.09 and later so we can ship it as an update for users with sandboxed Google Play installed</li>
                        <li>Sandboxed Google Play compatibility layer: remove no longer supported "Configure Play Store updates" settings since we always handle updates ourselves via our App Store now</li>
                        <li>fix an upstream screenshot process crash in ScrollCaptureController</li>
                        <li>Terminal (virtual machine management app): backport upstream improvements including detecting an outdated image to providing an upgrade path and removing the artificial cap on disk resize</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/134.0.6998.135.0">version 134.0.6998.135.0</a></li>
                        <li>only block installing out-of-band APEX updates on production (user) builds since it's useful for development</li>
                        <li>add support for testing Android 16 Beta 3 feature flags for development builds</li>
                        <li>begin porting our changes to work with Android 16 feature flags</li>
                    </ul>
                </article>

                <article id="2025032100">
                    <h3><a href="#2025032100">2025032100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025032100">2025032100</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025031400 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: improve support for overriding Gservices flags to avoid situations where our overrides aren't used leading to compatibility issues (this should fix a recent Play services crash that's being reported)</li>
                        <li>Sandboxed Google Play compatibility layer: improve support for overriding phenotype flags and fix flag overrides not being applied in some cases</li>
                        <li>fix 2 upstream lockscreen layout bugs with split shade used on folding phones (for the inner screen) and tablets</li>
                        <li>fix upstream lockscreen layout bug with placement of alarm and Do Not Disturb information</li>
                        <li>fix upstream lockscreen layout bug hiding date text when media is playing</li>
                        <li>enable support for the new desktop mode as an additional developer option toggle (Pixel Tablet already has this as the main toggle)</li>
                        <li>Terminal (virtual machine management app): backport upstream improvements</li>
                        <li>System Updater: raise download buffer size</li>
                        <li>System Updater: delete update package immediately after completion</li>
                        <li>System Updater: fall back to downloading and installing a full update if an incremental (delta) update fails initialization which occurs when a firmware or OS image has been corrupted (extremely rare edge case due to verified boot)</li>
                        <li>System Updater: retry faster if installation fails</li>
                        <li>System Updater: improve error checking to provide better error messages</li>
                        <li>System Updater: close update package zip file earlier</li>
                        <li>Network Location: require TLSv1.3 for GrapheneOS services instead of either TLSv1.2 or TLSv1.3</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision</li>
                        <li>Seedvault: update to 15-5.4 (will be replaced with a better backup implementation in the future)</li>
                        <li>stop disabling inclusion of device diagnostics functionality now that it's available in the Android Open Source Project</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/134.0.6998.108.0">version 134.0.6998.108.0</a></li>
                    </ul>
                </article>

                <article id="2025031400">
                    <h3><a href="#2025031400">2025031400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025031400">2025031400</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025031300 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: add back default values to the API definitions for our reimplementation of the Google Play location service since dropping them in the previous release (2025031300) broke compatibility with a subset of apps and prevented us moving it past our Alpha channel (all the improvements from the previous release are still present)</li>
                        <li>adevtool: fix support for checking stock OS kernel revision</li>
                    </ul>
                </article>

                <article id="2025031300">
                    <h3><a href="#2025031300">2025031300</a></h3>

                    <p>This release greatly improves the experimental virtual machine management app
                    with many backports from the Android Open Source Project main branch. You'll
                    need to install Android's latest Debian-based image in order to continue using
                    it. You'll be prompted to do this at startup after it fails to start with the
                    old setup with an opportunity to back up the data. The data inside it should
                    continue to be treated as disposable rather than relying on it not losing it
                    from a bug or a backwards incompatible update.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025031300">2025031300</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025030900 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: overhaul our default enabled reimplementation of the Google Play location service (location request rerouting) to provide much better compatibility for apps depending on network-based location by always telling apps that the Google Improve Location Accuracy toggle is enabled and providing fallback to GNSS for low power location requests when the OS network location service is disabled as it is by default (unlike Google Play services, which has no fallback, but apps assume users enable the feature)</li>
                        <li>fix Storage Scopes related null pointer exception in the permissions manager</li>
                        <li>Bluetooth: backport fix for empty adapter name handling in Android 15 QPR2 to avoid crashes when the name is set to an empty value or whitespace</li>
                        <li>Terminal (virtual machine management app): backport a large set of improvements including terminal tabs, working port forwarding, GUI support with opt-in GPU hardware acceleration (ANGLE-based VirGL until GPU virtualization support is available), speaker/microphone support and fixes for a bunch of bugs including overly aggressive timeouts</li>
                        <li>Settings: add Terminal app toggle to System category when developer options are enabled (requirement will be dropped when it's no longer experimental) so it can be enabled in other users (it's still currently only possible to use 1 instance at a time due to conflicting use of an internal network specific to virtual machine management)</li>
                        <li>Pixel 8 Pro, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold: fix support for enabling UWB (ultra wideband) radio by adding missing SELinux policy to avoid the UWB service chain crashing and burning CPU</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.130</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.82</li>
                        <li>Seedvault: update to 15-5.3 (will be replaced with a better backup implementation in the future)</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/134.0.6998.95.0">version 134.0.6998.95.0</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/83">version 83</a></li>
                    </ul>
                </article>

                <article id="2025030900">
                    <h3><a href="#2025030900">2025030900</a></h3>

                    <p>This release adds support for the experimental virtual machine management app
                    introduced in Android 15 QPR2. It currently only provides support for managing a
                    single VM and interacting with it via a WebView-based terminal. Android is in
                    the process of adding support for graphics and GPU acceleration for a future
                    release. For now, it's only available in developer options due to being highly
                    experimental. We don't recommend using developer options on a production device,
                    but you can temporarily enable it to turn on this feature and turn them back off
                    without it being disabled like most developer options. The data inside it should
                    currently be treated as disposable rather than relying on it not losing it from
                    a bug or a backwards incompatible update. We plan to support choosing other
                    guest operating systems beyond the Debian-based image provided by Android along
                    with taking far more advantage of the virtualization infrastructure.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025030900">2025030900</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025030800 release:</p>

                    <ul>
                        <li>SystemUI: re-enable migrate_clocks_to_blueprint and communal_hub flags with workarounds for upstream issues when using standard AOSP UI components instead of Pixel OS components</li>
                        <li>Android Debug Bridge: fix upstream crash caused by a race condition that sometimes unregistered a closed file descriptor from epoll</li>
                        <li>Sandboxed Google Play compatibility layer: fix issue breaking RPC transactions which impacts the Terminal app</li>
                        <li>Sandboxed Google Play compatibility layer: add implementation of isGoogleLocationAccuracyEnabled() to the location rerouting implementation always returning true to fix compatibility with apps checking for it</li>
                        <li>Sandboxed Google Play compatibility layer: fix definition of IStatusCallback.onCompletion() to slightly improve performance</li>
                        <li>allow Terminal app to use WebView JIT since it requires WebAssembly</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.80</li>
                    </ul>
                </article>

                <article id="2025030800">
                    <h3><a href="#2025030800">2025030800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025030800">2025030800</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025030700 release:</p>

                    <ul>
                        <li>SystemUI: temporarily disable migrate_clocks_to_blueprint and communal_hub flags again to avoid upstream Android 15 QPR1 lockscreen layout regressions which are still present in Android 15 QPR2 until we resolve them, which will be prioritized now</li>
                        <li>SystemUI: make screenshot sound use sound effects setting again (our change stopped working from the Android 15 QPR2 port)</li>
                    </ul>
                </article>

                <article id="2025030700">
                    <h3><a href="#2025030700">2025030700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025030700">2025030700</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025030500 release:</p>

                    <ul>
                        <li>Wallpaper Picker: backport upstream fix for an Android 15 QPR2 bug causing the UI for picking the wallpaper to be blank</li>
                        <li>fix upstream system_server crash introduced in Android 15 QPR2 related to Bluetooth telephony integration</li>
                        <li>backport upstream fixes for 13 different system_server null pointer exception crashes, an array out of bounds system_server exception and an NFC resolver activity null pointer exception</li>
                        <li>backport upstream fix for voice volume adjustments in certain apps</li>
                        <li>adevtool (Pixel Tablet): remove unintentional deviation from standard memory pinning configuration</li>
                        <li>adevtool: remove unnecessary PersistentBackgroundServices app</li>
                        <li>adevtool: filter out config_pluginAllowlist SystemUI overlay to avoid breaking the clock layout by referring to non-AOSP SystemUI clocks</li>
                        <li>Sandboxed Google Play compatibility layer: fix Google Play Services for AR not being installable from the Play Store anymore</li>
                        <li>Sandboxed Google Play compatibility layer: fix development option for installing the Pixel Thermometer (Pixel Health) app</li>
                        <li>add inet group for vmnic (virtual machine networking functionality) to make it compatible with our group-based Network permission enforcement used as another layer of security</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/82">version 82</a></li>
                    </ul>
                </article>

                <article id="2025030500">
                    <h3><a href="#2025030500">2025030500</a></h3>

                    <p>This release is based on Android 15 QPR2, the second quarterly release of
                    Android 15. All of the supported devices are now using the Linux 6.1 LTS branch
                    so the 5.10 and 5.15 branches are retired for GrapheneOS. 6.6 continues to be
                    used for microdroid virtual machines on devices and for emulator builds, which
                    will likely move to 6.12 this year.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025030500">2025030500</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025030300 release:</p>

                    <ul>
                        <li>full 2025-03-05 security patch level</li>
                        <li>rebased onto BP1A.250305.020.T2 Android Open Source Project release (initial Android 15 QPR2 release)</li>
                        <li>Settings: replace our approach to making the Unrestricted battery mode more visible due to changes in Android 15 QPR2</li>
                        <li>drop 8 downstream GrapheneOS patches for upstream Android bugs which should no longer be required due to upstream fixes in Android 15 QPR2</li>
                        <li>kernel (Pixel 7a): temporarily disable RANDSTRUCT due to a Qualcomm Wi-Fi driver incompatibility (only the Pixel 7a uses Qualcomm Wi-Fi and RANDSTRUCT wasn't enabled before Android 15 QPR2 for 6th/7th/8th gen Pixels since they weren't on 6.1 yet)</li>
                    </ul>
                </article>

                <article id="2025030300">
                    <h3><a href="#2025030300">2025030300</a></h3>

                    <p>This is an early March security update release based on the March 2025
                    security patch backports since the quarterly Android Open Source Project and
                    stock Pixel OS release (Android 15 QPR2) scheduled for this month hasn't been
                    published yet. </p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025030300">2025030300</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025030200 release:</p>

                    <ul>
                        <li>full 2025-03-01 security patch level</li>
                        <li>Network Location: temporarily disable using altitude in trilateration for now because 3D trilateration is using an excessive amount of CPU time and we need to greatly optimize it with algorithm level improvements, porting it to Rust and other optimizations before we can use 3D</li>
                        <li>App Store: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/29">version 29</a></li>
                        <li>App Store: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/30">version 30</a></li>
                    </ul>
                </article>

                <article id="2025030200">
                    <h3><a href="#2025030200">2025030200</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025030200">2025030200</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025030100 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: remove requestLocationSettingsDialog() implementation due to apps implicitly depending on it behaving in a very specific way</li>
                        <li>Sandboxed Google Play compatibility layer: add isHybridLocationServiceEnabled() API</li>
                        <li>Sandboxed Google Play compatibility layer: skip redundant location settings check activity when rerouting is on</li>
                    </ul>
                </article>

                <article id="2025030100">
                    <h3><a href="#2025030100">2025030100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025030100">2025030100</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025022800 release:</p>

                    <ul>
                        <li>Network Location: improve integration of altitude into trilateration to properly account for not all networks providing it including avoiding an edge case null pointer exception</li>
                        <li>Network Location: add default enabled data saver exemption</li>
                        <li>Network Location: use hideFromAppOps as documented by the Android API documentation for a network location service to match how the AOSP satellite-based location services and the Play services location services in the stock OS work (this likely avoids the need for the exemption from the GrapheneOS location indicator but we're keeping that for now to avoid wasting development time determining it)</li>
                    </ul>
                </article>

                <article id="2025022800">
                    <h3><a href="#2025022800">2025022800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025022800">2025022800</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025022700 release:</p>

                    <ul>
                        <li>restrict "5G only" mode to carriers with 5G standalone support to avoid setting the option silently failing</li>
                        <li>fix ancient upstream bug causing system_server crashes when flushing an inactive location provider which was uncovered by us adding our own network location provider</li>
                        <li>exclude network location provider from the GrapheneOS location indicator since it's meant to be shown for apps requesting location rather than showing users when the OS location services listen for GNSS satellite broadcasts and scan nearby networks</li>
                        <li>Sandboxed Google Play compatibility layer: fix issues in our requestLocationSettingsDialog() implementation which were uncovered by providing our own network location provider (this is part of our reimplementation of the Google Play location service used when rerouting Google Play location requests to the OS is enabled which is the default)</li>
                        <li>Network Location: add built-in battery optimization exception to avoid being blocked from accessing the network from the background in some cases</li>
                        <li>Network Location: incorporate altitude into trilateration when available to replace basic altitude support based on averages which wasn't taken into account for the latitude/longitude estimation (i.e. it now operates in 3D instead of 2D)</li>
                        <li>Network Location: add TLS key pinning for gs-loc.apple.grapheneos.org</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision</li>
                    </ul>
                </article>

                <article id="2025022700">
                    <h3><a href="#2025022700">2025022700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025022700">2025022700</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025021100 release:</p>

                    <ul>
                        <li>add opt-in GrapheneOS network location implementation available via Settings > Location > Location services based on using the Apple Wi-Fi positioning API either through a GrapheneOS proxy or directly via Apple's service, which will be extended with much more functionality in the near future including incorporating altitude into trilateration, using cell towers if it provides a better estimate than Wi-Fi and using our own network location database either via a service or offline database downloads (we're in the process of building our own database initially based on collecting most of the data from Apple's service and have already done a test run obtaining essentially all the cell tower data along with lots of Wi-Fi data)</li>
                        <li>fix Wi-Fi APEX issues preventing an OS network location service from doing Wi-Fi scans without the INTERACT_ACROSS_USERS / INTERACT_ACROSS_USERS_FULL privileged permissions</li>
                        <li>Sandboxed Google Play compatibility layer: add support for using an OS network location provider for the default enabled rerouting of Google Play location requests to the OS location service</li>
                        <li>add support for "5G only" and "4G or 5G only" modes in addition to our existing "4G only" mode</li>
                        <li>enable support for blocking callers not in Contacts</li>
                        <li>resolve regression for secondary user SMS in Android 15 QPR1 by enabling partial upstream fix since we dropped this part of our fix for the issues but the upstream fix wasn't actually active</li>
                        <li>fix Storage Scopes / Contact Scopes app settings link not working for apps in nested profiles in some cases</li>
                        <li>Launcher: limit 4x5 grid option to phones</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.79</li>
                        <li>backport mainline APEX module patches for DocumentsUI, Media Provider and Network Stack</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/133.0.6943.89.0">version 133.0.6943.89.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/133.0.6943.121.0">version 133.0.6943.121.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/133.0.6943.137.0">version 133.0.6943.137.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/134.0.6998.39.0">version 134.0.6998.39.0</a></li>
                        <li>App Store: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/27">version 27</a></li>
                        <li>App Store: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/28">version 28</a></li>
                        <li>Messaging: update to <a href="https://github.com/GrapheneOS/Messaging/releases/tag/5">version 5</a></li>
                        <li>Messaging: update to <a href="https://github.com/GrapheneOS/Messaging/releases/tag/6">version 6</a></li>
                        <li>Messaging: update to <a href="https://github.com/GrapheneOS/Messaging/releases/tag/7">version 7</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/21">version 21</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/22">version 22</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/23">version 23</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/24">version 24</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/25">version 25</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/26">version 26</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/79">version 79</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/80">version 80</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/81">version 81</a></li>
                    </ul>
                </article>

                <article id="2025021100">
                    <h3><a href="#2025021100">2025021100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025021100">2025021100</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025020500 release:</p>

                    <ul>
                        <li>kernel (5.10, 5.15, 6.1, 6.6): zero memory in early boot in case it wasn't zeroed by the OS as part of a clean reboot or shutdown since there isn't fully encrypted RAM with a per-boot key yet (early boot zeroing is implemented by Pixel boot firmware since April 2024 for booting into fastboot mode but not booting into the OS since they only partially implemented our January 2024 reset attack protection proposal, so we need to handle the OS part ourselves)</li>
                        <li>kernel (6.1): add back revert for upstream Linux kernel fix which was reapplied in our <a href="#2025020200">2025020200</a> release without any reports of issues for days because it has been found to break DisplayPort alternate mode on 9th generation Pixels</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.128</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.76</li>
                        <li>kernel (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): backport Wi-Fi driver patch from Android 15 QPR2 Beta 3 in an attempt to avoid a rare invalid read-after-free detected by hardware memory tagging</li>
                        <li>Launcher: add 4x5 grid option</li>
                        <li>remove infrastructure for our legacy software-based USB peripheral blocking since we've replaced it with <a href="https://grapheneos.org/features#usb-c-port-and-pogo-pins-control">a far better feature using both hardware and software USB connection/data blocking</a> across all supported devices</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/78">version 78</a></li>
                    </ul>
                </article>

                <article id="2025020500">
                    <h3><a href="#2025020500">2025020500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025020500">2025020500</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025020300 release:</p>

                    <ul>
                        <li>full 2025-02-05 security patch level</li>
                        <li>rebased onto AP4A.250205.002 Android Open Source Project release</li>
                        <li>drop our workaround for upstream audio routing permission bug impacting Android Auto and likely other apps that's no longer required due to an upstream fix in the monthly February release</li>
                        <li>kernel (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): switch to Mali GPU kernel driver from Android 15 QPR2 Beta 3 to include additional security fixes</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/133.0.6943.49.0">version 133.0.6943.49.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-154">version 154</a></li>
                    </ul>
                </article>

                <article id="2025020300">
                    <h3><a href="#2025020300">2025020300</a></h3>

                    <p>This is an early February security update release based on the February 2025
                    security patch backports since the monthly Android Open Source Project and stock
                    Pixel OS release scheduled for this month hasn't been published yet. </p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025020300">2025020300</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025020200 release:</p>

                    <ul>
                        <li>full 2025-02-01 security patch level</li>
                    </ul>
                </article>

                <article id="2025020200">
                    <h3><a href="#2025020200">2025020200</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025020200">2025020200</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025012700 release:</p>

                    <ul>
                        <li>reimplement our fix for an upstream audio routing regression in Android 15 QPR1 impacting sandboxed Android Auto and likely other apps to avoid blocking another subset of apps from changing audio routing when granted permission</li>
                        <li>Sandboxed Google Play compatibility layer: add support for enabling Google's credential service via Settings > Passwords, passkeys &amp; accounts by making it function as an unprivileged service (non-Chromium-based apps tend to require this to use Google as the passkey service and it's needed by certain apps for their Sign in with Google option despite Android intending to fully support other credential services)</li>
                        <li>Sandboxed Google Play compatibility layer: allow disabling all Play Integrity API notifications instead of only disabling them per-app</li>
                        <li>Sandboxed Google Play compatibility layer: override Play services update owner value to the GrapheneOS App Store to fully handle updates for it ourselves</li>
                        <li>work around upstream Android issue caused by an optimization which was adding a 10 second delay to certain setting changes before they kick in for background system packages</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.126</li>
                        <li>kernel (6.1): drop revert for upstream USB fix causing DisplayPort alternate mode regression to test if it's still needed due to lots of other backported changes</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.74</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/133.0.6943.39.0">version 133.0.6943.39.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/133.0.6943.39.1">version 133.0.6943.39.1</a></li>
                        <li>remove same version ABI stability check not useful for GrapheneOS</li>
                    </ul>
                </article>

                <article id="2025012700">
                    <h3><a href="#2025012700">2025012700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025012700">2025012700</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025012600 release:</p>

                    <ul>
                        <li>fix regression in the previous release for configuring per-app settings added by GrapheneOS for apps in the work profile or Private Space when the Settings app is launched from the Owner user rather than the work profile or Private Space (this was caught during Alpha channel testing and is why it didn't proceed to Beta channel testing)</li>
                        <li>avoid Settings app crashing when opening the per-app Play Integrity API menu for an already uninstalled app via a leftover notification</li>
                        <li>Sandboxed Google Play compatibility layer: improve Play Integrity API description</li>
                    </ul>
                </article>

                <article id="2025012600">
                    <h3><a href="#2025012600">2025012600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025012600">2025012600</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025011500 release:</p>

                    <ul>
                        <li>disable standard Android feature holding a 10 minute screen wake lock after the screen brightness is raised at least 2 times within 5 minutes since this is confusing for users and it's far better if keep awake is done explicitly</li>
                        <li>always show Linux kernel crash notifications from hardware memory tagging (Hardware Tag-Based KASAN) instead of only when system crash reporting is enabled by users</li>
                        <li>Messaging: begin under the hood overhaul including fully porting to target API 35 (Android 15)</li>
                        <li>recovery: remove spurious warning after sideloading an update fails on A/B update devices</li>
                        <li>change build username and hostname to match the stock Pixel OS format instead of setting both to grapheneos due to bad actors using it to ban using GrapheneOS</li>
                        <li>return green as the value of ro.boot.verifiedbootstate for user installed apps (not the base OS or system apps) due to bad actors using it to ban using GrapheneOS</li>
                        <li>SettingsIntelligence: don't show preference summaries in search results since it doesn't work properly for ones depending on dynamic string formatting and isn't done by SettingsIntelligenceGoogle on the stock Pixel OS</li>
                        <li>Contact Scopes: fix spoofing of OP_GET_CONTACTS for apps not requesting WRITE_CONTACTS</li>
                        <li>Sandboxed Google Play compatibility layer: improve infrastructure</li>
                        <li>Sandboxed Google Play compatibility layer: allow blocking the Sandboxed Google Play is running notification</li>
                        <li>Sandboxed Google Play compatibility layer: add per-app Play Integrity menu in the per-app Settings configuration that's shown after an app uses the Play Integrity API</li>
                        <li>Sandboxed Google Play compatibility layer: add per-app toggle for blocking using the Play Integrity API via the per-app Play Integrity menu as a workaround for apps which ban devices based on it but don't require providing it to their service yet</li>
                        <li>Sandboxed Google Play compatibility layer: add shortcut to the per-app Play Integrity API menu for contacting the app developer by leaving a review through the Play Store page</li>
                        <li>Sandboxed Google Play compatibility layer: add menu for viewing all apps which have used the Play Integrity API with a shortcut in the per-app Play Integrity API menu</li>
                        <li>Sandboxed Google Play compatibility layer: show optional notification upon detection of Play Integrity usage providing a shortcut to the per-app Play Integrity API menu and another for hiding further notifications for the app which is also available as a toggle in the per-menu</li>
                        <li>hardened_malloc: update libdivide to 5.2.0</li>
                        <li>TalkBack (screen reader): update dependencies</li>
                        <li>TalkBack (screen reader): make builds fully reproducible by removing the use of __DATE__ and __TIME__ by brltty along with making the liblouis translation table zip use deterministic file order and timestamps</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.124</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.68</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/132.0.6834.79.0">version 132.0.6834.79.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/132.0.6834.79.1">version 132.0.6834.79.1</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/132.0.6834.79.2">version 132.0.6834.79.2</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/132.0.6834.122.0">version 132.0.6834.122.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-153">version 153</a></li>
                    </ul>
                </article>

                <article id="2025011500">
                    <h3><a href="#2025011500">2025011500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025011500">2025011500</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2025010700 release:</p>

                    <ul>
                        <li>fix upstream Android lockscreen bug triggered by the combination of fully disabling animations (via Settings > Accessibility > Color and motion > Remove animations) and enabling always-on display (Settings > Display > Lock screen > Always show time and info) which results in the locking process getting stuck and not considering the device locked until it wakes again due to not skipping animations as intended (this did not create a lockscreen bypass but did result in valid biometric unlock credentials skipping restrictions)</li>
                        <li>add protection against upstream lockscreen bugs bypassing restrictions on biometric unlocking while the device is asleep including the standard restrictions and our recently added 2-factor fingerprint unlock feature</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): enable hardware memory tagging for the main kernel allocators via the upstream Hardware Tag-Based KASAN implementation (which is intended for production usage, unlike the other KASAN modes)</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): switch KASAN fault handling from report to panic to use it as a hardening feature instead of only a bug finding tool</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): switch KASAN hardware memory tagging mode from synchronous to asymmetric for the initial deployment to reduce the performance cost and match our existing hardware memory tagging usage in userspace (synchronous mode is potentially more useful in the kernel than it is for userspace which is something we can investigate and potentially offer as an option)</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): disable our slab canary feature since it's incompatible with the kernel's hardware memory tagging and will be fully obsolete after we've made basic improvements to the upstream hardware memory tagging implementation</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.233</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.176</li>
                        <li>kernel (5.15): merge latest GKI tag to incorporate important security and other patches including the patch for CVE-2024-56556 which are not included in the latest kernel.org release (5.15.176) or the latest GKI LTS branch revision</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision</li>
                        <li>Updater: require TLSv1.3 instead of either TLSv1.2 or TLSv1.3</li>
                        <li>Seedvault: update to a newer revision (will be replaced with a better backup implementation in the future)</li>
                        <li>System UI Tuner: opt-out of Android 15 edge-to-edge since it's not properly supported yet (upstream bug)</li>
                        <li>make eng builds more consistent with user/userdebug builds by extending the GrapheneOS additions of the ro.control_privapp_permissions=enforce, net.tethering.noprovisioning=true and ro.sys.time_detector_update_diff=50 system properties to all build variants</li>
                        <li>show a system error notification for privileged permission allowlist violations in development builds (userdebug and eng builds) instead of breaking booting the device to make developing device support and porting to new OS versions easier</li>
                    </ul>
                </article>

                <article id="2025010700">
                    <h3><a href="#2025010700">2025010700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2025010700">2025010700</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024123000 release:</p>

                    <ul>
                        <li>full 2025-01-05 security patch level</li>
                        <li>rebased onto AP4A.250105.002 Android Open Source Project release</li>
                        <li>provide standard haptic feedback for fingerprint authentication success when 2nd factor PIN is enabled</li>
                        <li>add workaround for upstream SystemServiceManager.newTargetUser null pointer exception bug crashing system_server</li>
                        <li>add workaround for upstream BatteryStatsImpl.updateWifiBatteryStats divide by zero bug crashing system_server</li>
                        <li>Contacts: improve dark theme contrast for empty contacts list background</li>
                        <li>backport mainline APEX module patches for Media Provider, Network Stack and Wi-Fi</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.175</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.123</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.65</li>
                        <li>Sandboxed Google Play compatibility layer: fix implementation of getCurrentLocation() to return SUCCESS even when the result is null to avoid some edge case issues</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/76">version 76</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/77">version 77</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/131.0.6778.260.0">version 131.0.6778.260.0</a></li>
                    </ul>
                </article>

                <article id="2024123000">
                    <h3><a href="#2024123000">2024123000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024123000">2024123000</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024121200 release:</p>

                    <ul>
                        <li>add support for adding a PIN as a 2nd factor to fingerprint unlock to enable our new recommended high threat model configuration of a random diceware passphrase as the primary unlock method and fingerprint+PIN with a random 4-6 digit PIN as the regularly used secondary unlock method (the usual limitations of secondary unlock only being usable for 48 hours after successful primary unlock and our limit of 5 total secondary unlock attempts apply)</li>
                        <li>add support for limiting charging the battery to 80% with support for bypass charging similar to the new Android 15 QPR1 stock Pixel OS feature, although unlike the stock Pixel OS our implementation still works while using a secondary user (the limit is currently hard-wired to 80% due to that being what's fully supported for the stock OS usage, but we can eventually make it configurable)</li>
                        <li>add support for disabling dynamic code loading via storage for all user installed apps by default as we already do for the dynamic code loading via memory setting instead of only being able to opt-in to the restriction on a per-app basis</li>
                        <li>allow dynamic code loading from storage by default for apps depending on Play services due to the legacy dynamite module implementation not yet being fully replaced by split APKs to avoid users encountering a huge number of issues if they disable it by default for user installed apps (users can still disable it for these apps manually and we won't need to keep this exception forever since Google is moving to split APKs for dynamite modules)</li>
                        <li>add support for partially recompiling apps (speed-profile) in the Finalizing step of OS updates to skip partially recompiling them during boot, but while still doing most of the work after boot in the background (speed) to avoid slowing down OS update installation too much</li>
                        <li>remove adding back boot-time display of app compilation progress now that it's no longer heavily used</li>
                        <li>use 2 threads instead of 1 for background compilation of apps</li>
                        <li>switch to the new upstream default of 4 threads for compiling apps during boot instead of our previous 2 threads which we set to replace the previous upstream default of a single thread</li>
                        <li>Settings: add back battery optimization settings link to Battery screen which was removed by Android a long time ago</li>
                        <li>Settings: don't disable App info > Battery usage item while its summary is loading</li>
                        <li>Settings: temporarily stop showing battery usage info in App info item summary due to an upstream regression causing it to take more than 5 seconds to load in many cases</li>
                        <li>add back our fix for an upstream Android bug causing null pointer exception system_server crash in InputMethodManagerService triggered when ending user sessions because it turns out to still be required after Android 15 QPR1</li>
                        <li>fix upstream Android bug causing null pointer exception system_server crash in NotificationManagerService</li>
                        <li>Contacts: improve dark theme color contrast</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.232</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.173</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.119</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.61</li>
                        <li>kernel (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): fix very minor Android 15 QPR1 regression causing the kernel commit hash to be omitted from the kernel version string and the Unix epoch to be used as the build time instead of the kernel commit timestamp</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/75">version 75</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/131.0.6778.200.0">version 131.0.6778.200.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-152">version 152</a></li>
                        <li>add developer option to log binder transactions</li>
                        <li>fix ignoring harmless fingerprint-service.goodix crash for our system service crash reporting</li>
                    </ul>
                </article>

                <article id="2024121200">
                    <h3><a href="#2024121200">2024121200</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024121200">2024121200</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024120900 release:</p>

                    <ul>
                        <li>SystemUI: disable migrate_clocks_to_blueprint and communal_hub flags to avoid upstream Android 15 QPR1 lockscreen layout regressions</li>
                        <li>fix upstream bug causing the Microphone (RECORD_AUDIO) permission to be required for for local audio routing via REMOTE_SUBMIX instead of only the MODIFY_AUDIO_ROUTING permission with this explicit purpose (this caused Android Auto to require the Microphone permission for routing audio on both the stock OS and GrapheneOS, but it impacts GrapheneOS more due to permissions not being granted by default to Android Auto and most people not wanting to give it the Microphone permission)</li>
                        <li>Settings: show current app battery usage mode in summary of App battery usage item</li>
                        <li>Settings: add back Unrestricted battery usage option to App battery usage screen to undo the usability regression introduced by Android 14 QPR2 where Optimized vs. Unrestricted was hidden away in an inner mode accessed by pressing the text next to an allow background toggle for controlling the Restricted mode (they likely did this to discourage users enabling Unrestricted, but GrapheneOS users need this much more than stock OS users especially if they don't use sandboxed Google Play and the new UI is very confusing/misleading instead of simply giving users a direct choice between the 3 modes)</li>
                        <li>Dialer: add proper dark mode support for dialogs</li>
                        <li>Android Debug Bridge: fix upstream use-after-free bug for network-based connections which is being caught by our always enabled hardware memory tagging support for the base OS in hardened_malloc</li>
                        <li>Android Debug Bridge: backport support for v4 signatures in streaming app installs from Android's development branch to support updating GrapheneOS apps directly with the streaming-based ADB install commands instead of needing to push them to the device and then install them (this stopped working after Android 15 since we had to replace signed fs-verity metadata with v4 signatures for our implementation of extending verified boot to system APK updates to close a major security hole in standard Android verified boot)</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/131.0.6778.135.0">version 131.0.6778.135.0</a></li>
                    </ul>
                </article>

                <article id="2024120900">
                    <h3><a href="#2024120900">2024120900</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024120900">2024120900</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024120702 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: fix Android Auto Bluetooth audio regressions from Android 15 QPR1</li>
                        <li>CarrierConfig2 (app created by GrapheneOS to replace Google CarrierSettings): add support for new ICCID MVNO type in Android 15 QPR1</li>
                        <li>CarrierConfig2: add support for new ApnItem fields Android 15 QPR1</li>
                        <li>CarrierConfig2: change user-facing carrier settings version string prefix to match Google Carrier Settings to avoid confusion when comparing to the stock OS</li>
                        <li>delay activation of the Allow button for the Android Debug Bridge USB authorization dialog by 1 second to make it much harder to accidentally grant access</li>
                        <li>Permission Controller: delay activation of the Allow button(s) for runtime permission dialogs by 1 second to make it much harder to accidentally grant access</li>
                        <li>Permission Controller: disable all caps text theme by default to match the Settings app style</li>
                        <li>Permission Controller: move "Turn off" action from overflow menu to the toolbar for both Storage Scopes and Contact Scopes</li>
                        <li>Permission Controller: fix Contact Scopes UI issue where "Allow" could still be selected in the permission menu with Contacts Scopes enabled which would not actually disable Contact Scopes and allow the permission</li>
                        <li>Settings: add a dedicated App info > Storage > Manage storage button for apps with a manage storage space activity instead of replacing the standard user interface with it especially since the app's own implementation may not support clearing all storage and may not work at all</li>
                        <li>Settings: fix minor back navigation issue for our duress PIN/password UI where it would open a new authentication activity instead of going back to the previous screen</li>
                        <li>prevent crashes caused by upstream Android bugs when a Mock Location provider is added or removed by avoiding ever removing location providers at runtime by keeping them around as disabled providers</li>
                        <li>stop temporarily always enabling system crash notifications since the initial Android 15 QPR1 testing is completed</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.228</li>
                        <li>adevtool: update carrier_settings and carrier_list protobuf parsers for Android 15 QPR1</li>
                    </ul>
                </article>

                <article id="2024120702">
                    <h3><a href="#2024120702">2024120702</a></h3>

                    <p>This release is specific to 9th generation Pixels and is being published to
                    provide a proper fix for the GPU driver regression we ran into with Android 15
                    QPR1 so we can switch back to the standard GrapheneOS Linux 6.1 GKI LTS
                    branch.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024120702">2024120702</a> (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold)</li>
                    </ul>

                    <p>Changes since the 2024120701 release:</p>

                    <ul>
                        <li>kernel (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): switch back to standard GrapheneOS 6.1 kernel based on 6.1.118 instead of the tag based on 6.1.84 for AOSP and the stock OS which was used as a workaround for a Mali GPU kernel driver bug in the previous OS release</li>
                        <li>kernel (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): switch to Mali GPU kernel driver from Android 15 QPR2 Beta 1 which includes a fix for the massive mmap bug which caused lag and both app/system wide stalls/crashes with a newer LTS kernel revision</li>
                    </ul>
                </article>

                <article id="2024120701">
                    <h3><a href="#2024120701">2024120701</a></h3>

                    <p>This release is specific to 9th generation Pixels and is being published to
                    provide a temporary workaround for a major Mali GPU kernel driver issue
                    introduced in Android 15 QPR1. The issue was caught during our Alpha channel
                    testing and resulted in the last release being cancelled for 9th generation
                    Pixels.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024120701">2024120701</a> (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold)</li>
                    </ul>

                    <p>Changes since the 2024120700 release:</p>

                    <ul>
                        <li>kernel (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): temporarily switch to a dedicated GKI kernel branch based on the much older revision used by the stock OS and AOSP (6.1.84 instead of 6.1.118) to resolve major Mali GPU kernel driver regressions, which can then be narrowed down further after we have an initial workaround for the crashes/stalls caused by the driver changes</li>
                    </ul>
                </article>

                <article id="2024120700">
                    <h3><a href="#2024120700">2024120700</a></h3>

                    <p>This release is based on Android 15 QPR1, the first quarterly release of Android 15.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024120700">2024120700</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024120400 release:</p>

                    <ul>
                        <li>full 2024-12-05 security patch level</li>
                        <li>rebased onto AP4A.241205.013 Android Open Source Project release (December quarterly release of Android 15)</li>
                        <li>temporarily always enable system crash notifications to help users find Android 15 QPR1 regressions</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.227</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.1): add back one of the two f2fs defragmentation patches we reverted now that it's backported in Android 15 QPR1, since the other change was the source of the major regression rather than this one and it now has broad testing upstream without the broken change we still have reverted</li>
                        <li>kernel (Pixel Tablet): make SYN43752 Wi-Fi/Bluetooth driver build reproducible by dropping Broadcom's inclusion of the absolute path to the build directory as we've already done for all other 6th/7th/8th generation Pixels</li>
                        <li>kernel (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold): make BCM4390 Wi-Fi/Bluetooth driver build reproducible by dropping Broadcom's inclusion of the absolute path to the build directory as we've already done for 6th/7th/8th generation Pixels</li>
                    </ul>
                </article>

                <article id="2024120400">
                    <h3><a href="#2024120400">2024120400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024120400">2024120400</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024120200 release:</p>

                    <ul>
                        <li>Gallery: remove the Delete option for items that represent multiple images since the UI is badly designed and makes it too easy to accidentally delete images, especially since the app doesn't support the Trash API</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/131.0.6778.104.0">version 131.0.6778.104.0</a></li>
                        <li>switch back to correct APK for Vanadium Config to fix using our full content filter list and to unblock out-of-band updates (this regressed in the <a href="#2024112700">2024112700</a> OS release and was noticed with the new Vanadium release)</li>
                        <li>envsetup.sh: reuse BUILD_DATETIME and BUILD_NUMBER from environment to make automation for reproducible builds slightly simpler instead of needing to export them after sourcing envsetup.sh</li>
                    </ul>
                </article>

                <article id="2024120200">
                    <h3><a href="#2024120200">2024120200</a></h3>

                    <p>This is an early December security update release based on the December 2024
                    security patch backports since the quarterly Android Open Source Project and
                    stock Pixel OS release (Android 15 QPR1) scheduled for this month hasn't been
                    published yet. </p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024120200">2024120200</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024112700 release:</p>

                    <ul>
                        <li>full 2024-12-01 security patch level</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.118</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.58</li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/20">version 20</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-151">version 151</a></li>
                    </ul>
                </article>

                <article id="2024112700">
                    <h3><a href="#2024112700">2024112700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024112700">2024112700</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024111800 release:</p>

                    <ul>
                        <li>Settings: revert our previous attempt at disabling Bluetooth contact sharing by default for hands-free calling devices in our <a href="#2024111700">2024111700</a> release because it didn't address an upstream Android security bug and having the toggle off by default caused the upstream bug to impact pairing directly in the Settings app (foreground) if the user would have toggled it off instead of only outside the Settings app such as through the Bluetooth Quick Tile (background)</li>
                        <li>Settings: fix an upstream Android security bug causing Bluetooth contact sharing to be enabled for hands-free calling devices even though the dialog shows it will be disabled, which only previously occurred for pairing invoked from outside the Settings app but also began impacting pairing from within it due to disabling the contact sharing setting by default</li>
                        <li>Settings: always disable Bluetooth contact sharing by default instead of enabling it by default for pairing requests made by the user in the foreground where the user can choose to disable it</li>
                        <li>fix upstream bug breaking in-call service components provided by packages only installed in secondary users, which was mainly occurring with user installed Android Auto which unlike the stock OS isn't installed in Owner by default to mask this bug</li>
                        <li>Sandboxed Google Play compatibility layer: allow Android Auto foreground services to have while-in-use permissions when wired and/or wireless Android Auto special permissions are granted by the user to fix voice commands in some cases</li>
                        <li>Sandboxed Google Play compatibility layer: make Google text-to-speech app queryable by other apps in the same profile by default as it is on the stock OS since libraries using it don't declare the query explicitly (note apps and their libraries can declare any queries they want including for any app with a launcher activity and there's no approval along with there being other ways to detect apps)</li>
                        <li>Sandboxed Google Play compatibility layer: show the notification for Play services not having Unrestricted battery usage enabled one more time for existing users since not having it now causes more severe delays FCM push messaging including notifications or more urgent events such as incoming calls to an app like Signal which uses FCM for this when available</li>
                        <li>Sandboxed Google Play compatibility layer: add notification about Play services having background data usage restricted which will break FCM when only mobile data is available (no Wi-Fi access)</li>
                        <li>Sandboxed Google Play compatibility layer: don't show battery usage notification for Play services when it has the Network toggle revoked since the user clearly doesn't want the functionality depending on Unrestricted background power usage</li>
                        <li>Settings: opt-out of Android 15 edge-to-edge for the developer options app picker activity since it's not properly supported yet (upstream bug)</li>
                        <li>Setup Wizard: avoid incredibly rare edge case crash (uncaught exception) when trying to disable OEM unlocking when it's already disabled and not allowed to be disabled by the carrier</li>
                        <li>fix avoiding reporting harmless fingerprint-related crash with our added crash reporting</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.57</li>
                        <li>Seedvault: update to a newer revision (will be replaced with a better backup implementation in the future)</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/131.0.6778.81.0">version 131.0.6778.81.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-150">version 150</a></li>
                    </ul>
                </article>

                <article id="2024111800">
                    <h3><a href="#2024111800">2024111800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024111800">2024111800</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024111700 release:</p>

                    <ul>
                        <li>temporarily revert putting Private Space data at rest when locking it because some users want to be able to unlock it with their fingerprint so we need to make this into a toggle rather than hard-wired (will be added back in a near future release as an option)</li>
                        <li>switch default display color mode to Natural for fresh installs for more accurate image/video colors and to avoid bugs tied to the other options</li>
                    </ul>
                </article>

                <article id="2024111700">
                    <h3><a href="#2024111700">2024111700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024111700">2024111700</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024110700 release:</p>

                    <ul>
                        <li>Private Space: put data at rest immediately after stopping the profile to match user profile behavior instead of only on reboot</li>
                        <li>fix Mock Location on devices without any standard location providers (only Pixel Tablet)</li>
                        <li>backport mainline APEX module patches for ART, DNS Resolver, DocumentsUI, Media, Media Provider, Network Stack, PermissionController, Remote Key Provisioning and Wi-Fi</li>
                        <li>raise maximum running users from the standard 3 to 4 for 6GB memory, 6 for 8GB memory, 10 for 12GB memory and 14 for 16GB memory</li>
                        <li>Settings: disable Bluetooth contact sharing by default for hands-free calling devices</li>
                        <li>Settings: fix Private Space handling in Passwords &amp; accounts > Additional services</li>
                        <li>Settings: fix multiple cases of missing user profiles handling for added settings</li>
                        <li>Dialer: fix RTT related crash from not using the correct theme configuration</li>
                        <li>Contacts Provider: work around upstream bug causing deadlock with contact scopes</li>
                        <li>temporarily don't report harmless fingerprint-service.goodix crash</li>
                        <li>temporarily disable hardened_malloc for vendor audio service due to Pixel Tablet bug</li>
                        <li>Sandboxed Google Play compatibility layer: significantly rework client side compatibility layer to avoid deadlocks and to avoid allowing starting apps with no exported components (i.e. not even a launcher activity)</li>
                        <li>Sandboxed Google Play compatibility layer: overhaul approach to raising Google Play components to the foreground to avoid it always being considered in the foreground while also solving an issue triggered in a rare edge case at startup</li>
                        <li>Sandboxed Google Play compatibility layer: stop Play Store from attempting to auto-install some system component packages, such as "Android System SafetyCore" (com.google.android.safetycore) and "Android System Key Verifier" (com.google.android.contactkeys)</li>
                        <li>Sandboxed Google Play compatibility layer: fix Android Auto voice commands not working in some cases</li>
                        <li>Sandboxed Google Play compatibility layer: fix one of the Android Auto permission toggle checks for companion devices</li>
                        <li>Sandboxed Google Play compatibility layer: extend opt-in Android Auto "Allow permissions for handling phone calls" toggle to allow access to Bluetooth adapter hardware address access for hands-free audio support with wired Android Auto rather than only wireless Android Auto where the baseline toggle already grants access to that</li>
                        <li>Sandboxed Google Play compatibility layer: don't stop apps that use Dynamite modules when Play services stops since the new version of the Dynamite client library handles dynamic re-connection without app restart and older ones will handle this by stopping</li>
                        <li>kernel (5.10, 5.15, 6.1, 6.6): disable unused TIPC protocol support</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.170</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.115</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision</li>
                        <li>System Updater: show failure notification for update_engine errors</li>
                        <li>System Updater: add missing UpdateEngine.unbind() to avoid extra callbacks for progress and error reporting</li>
                        <li>System Updater: avoid treating non-404 errors such as a connection failure as lack of an incremental update</li>
                        <li>System Updater: handle a partially downloaded incremental update being removed from the server by falling back to the full update instead of retrying resuming the incremental download until the next update (this will allow us to remove an incremental for the latest available version to save storage space or work around a potential update_engine bug without it causing download resumption errors)</li>
                        <li>System Updater: delete stale update from a failed download of a previous release slightly earlier</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/130.0.6723.102.1">version 130.0.6723.102.1</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/131.0.6778.39.0">version 131.0.6778.39.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-149">version 149</a></li>
                    </ul>
                </article>

                <article id="2024110700">
                    <h3><a href="#2024110700">2024110700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024110700">2024110700</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024110400 release:</p>

                    <ul>
                        <li>full 2024-11-05 security patch level</li>
                        <li>rebased onto AP3A.241105.007 Android Open Source Project release (November monthly release of Android 15)</li>
                        <li>ignore Person.Builder.setUri() when Contact Scopes is enabled since apps can't access the contact's URI with Contact Scopes enabled (this resolves the incompatibility between Contact Scopes and apps attaching contact information to notifications which was introduced by a November Android Security Bulletin patch)</li>
                        <li>fix "App info" uninstall dialog link added by GrapheneOS not working in some cases for secondary profile apps</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-147">version 147</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/130.0.6723.102.0">version 130.0.6723.102.0</a></li>
                    </ul>
                </article>

                <article id="2024110400">
                    <h3><a href="#2024110400">2024110400</a></h3>

                    <p>This is an early November security update release based on the November 2024
                    security patch backports since a monthly Android Open Source Project and stock
                    Pixel OS release hasn't been published yet.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024110400">2024110400</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024103100 release:</p>

                    <ul>
                        <li>full 2024-11-01 security patch level</li>
                        <li>fix a bunch of upstream Android bugs breaking SMS and MMS functionality in secondary profiles, including both Android 15 regressions and pre-existing issues</li>
                        <li>backport upstream Android fix for UsageStatsDatabase locking from the AOSP main branch</li>
                        <li>Sandboxed Google Play compatibility layer: fix flag overrides being partly ignored on recent versions</li>
                        <li>add workaround for rare system_server null pointer exception crash in showShutdownDialog()</li>
                        <li>add missing null handling for extended application error report</li>
                        <li>fix upstream bug causing App Not Responding link to not work properly outside of Owner</li>
                        <li>Settings: avoid opening parent user log viewer in nested profiles (Private Space, work profile)</li>
                        <li>System Updater, GmsCompat: reduce included SettingsLib components to reduce the size of these apps from around 10MB each to below 4MB each</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-146">version 146</a></li>
                    </ul>
                </article>

                <article id="2024103100">
                    <h3><a href="#2024103100">2024103100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024103100">2024103100</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024102400 release:</p>

                    <ul>
                        <li>improve our existing fix for an upstream Android bug impacting apps using the telephony service in secondary users to fix support for disabling re-routing of Google Play location requests to the OS for fresh installs of sandboxed Google Play since the release of Android 15</li>
                        <li>Sandboxed Google Play compatibility layer: extend wired Android Auto toggle to additional methods used in edge cases</li>
                        <li>fix changing USB-C port control setting to a lower security level not fully applying until after locking and unlocking</li>
                        <li>Settings: fix per-app exploit protection toggles for Private Space</li>
                        <li>Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold: disable Wi-Fi HAL debug logging to avoid memory corruption caught by hardware memory tagging on GrapheneOS</li>
                        <li>raise system log buffer size from 256KiB to 512KiB to make logs obtained by users reporting issues more useful</li>
                        <li>enable stamp configuration for microdroid kernel builds to set LOCALVERSION based on version control information as expected</li>
                        <li>kernel (6.6): disable unused hibernation support</li>
                        <li>kernel (6.6): disable unused TIOCSTI ioctl (already blocked via standard Android SELinux ioctl filtering)</li>
                        <li>kernel (6.6): disable unused cachestat system call (already blocked for apps via standard Android seccomp-bpf policy)</li>
                        <li>kernel (6.6): enable random kmalloc caches for x86_64 and microdroid too, not only bare metal arm64</li>
                        <li>kernel (6.6): enable full struct randomization for x86_64 and microdroid too, not only bare metal arm64</li>
                        <li>kernel (6.6): enable DEBUG_SG for microdroid too, not only bare metal</li>
                        <li>kernel (6.6): enable FORTIFY_SOURCE for microdroid too, not only bare metal</li>
                        <li>kernel (6.6): disable BINFMT_MISC for microdroid too, not only bare metal</li>
                        <li>kernel (6.6): disable RSEQ for microdroid too, not only bare metal</li>
                        <li>kernel (6.6): add SYSRQ restrictions for microdroid too, not only bare metal</li>
                        <li>kernel (6.6): use the same KFENCE configuration for microdroid as bare metal</li>
                        <li>mark Sensors permission as implicitly added</li>
                        <li>avoid adding Sensors permission to hasCode=false packages</li>
                        <li>improve our implementation of extending verified boot to out-of-band shared library APK updates</li>
                        <li>Log Viewer: add userType line to header in non-Owner users</li>
                        <li>Log Viewer: add targetSdk and sharedUid to package info header</li>
                        <li>System Updater: update minimum and target API level to 35 (Android 15)</li>
                        <li>adevtool: update carrier settings</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/130.0.6723.86.0">version 130.0.6723.86.0</a></li>
                        <li>Info: update to <a href="https://github.com/GrapheneOS/Info/releases/tag/5">version 5</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/87">version 87</a></li>
                        <li>Sandboxed Google Play compatibility layer: fix development support in OS debug builds</li>
                    </ul>
                </article>

                <article id="2024102400">
                    <h3><a href="#2024102400">2024102400</a></h3>

                    <p>Notice which will not impact most users: apps which were only installed in
                    secondary users but not Owner before updating to Android 15 and which were then
                    installed in Owner after updating to Android 15 will have a one-time revocation
                    of their Network/Sensors permissions after updating to this release as a minor
                    consequence of migrating them from Android 14 again.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024102400">2024102400</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024102100 release:</p>

                    <ul>
                        <li>switch back our original stricter approach to DNS leak blocking from our <a href="#2024050900">2024050900</a> release with an additional fix for an Android DNS routing bug causing requests to the VPN DNS servers to be routed incorrectly, which should avoid the compatibility issues experienced with certain VPN apps when we tried to ship it before</li>
                        <li>avoid resetting Network or Sensors back to the global default after app updates in a specific case when migrating the state from Android 14 or earlier</li>
                        <li>add an extra one-time migration of Network and Sensors being disabled in Android 14 to Android 15 to work around an issue with the previous migration of the permission state which occurred for some users with some of their apps</li>
                        <li>fix ancient Android bug causing widgets to disappear from the user's home screen when the user stops, which was a major usability issue for secondary users</li>
                        <li>Keyboard: extend fix for upstream layout bug in landscape mode to fully fix it for 3-button navigation in addition to the default gesture navigation</li>
                        <li>Gallery: fix upstream cropping activity bug when both the input and output URI is the same to fix setting profile pictures for user profiles</li>
                        <li>raise backup service transport (Seedvault) timeout from 10 minutes / 5 minutes to 60 minutes / 30 minutes to handle very large backups, particularly for the device-to-device mode which includes nearly all app data</li>
                        <li>temporarily revert enforcing minimum 64kiB stack guard size for arm64 since Facebook recently included a buggy stack overflow check for the React Native Hermes runtime that's incompatible with larger gap sizes and beginning to be shipped by apps (revert was not applied for Android 15 port)</li>
                        <li>Sandboxed Google Play compatibility layer: add stubs for update_engine wrapper API to avoid potential Play services crashes if the existing approaches to disable the update service fail</li>
                        <li>Pixel 8, Pixel 8 Pro, Pixel 8a: disable Wi-Fi HAL debug logging to avoid memory corruption caught by hardware memory tagging on GrapheneOS</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision</li>
                        <li>use hardened GrapheneOS 6.6 LTS kernel for microdroid virtual machines for both arm64 and x86_64</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/130.0.6723.73.0">version 130.0.6723.73.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-144">version 144</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-145">version 145</a></li>
                    </ul>
                </article>

                <article id="2024102100">
                    <h3><a href="#2024102100">2024102100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024102100">2024102100</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024102000 release:</p>

                    <ul>
                        <li>Keyboard: fix upstream bug triggered by Android 15 causing layout to be cut off in landscape mode on devices with a display cutout</li>
                        <li>enforce stack clash protection for arm64</li>
                    </ul>
                </article>

                <article id="2024102000">
                    <h3><a href="#2024102000">2024102000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024102000">2024102000</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024101900 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: adjust one of the stubs for the NearbyManager API to resolve a remaining issue</li>
                        <li>Sandboxed Google Play compatibility layer: use per-network MAC randomization and enable send device name for wireless Android Auto networks to avoid introducing compatibility issues by default for certain cars with either our per-connection MAC randomization feature or default disabled DHCP device name</li>
                        <li>adjust hasSendDhcpHostnameEnabledChanged() based on new "Send device name" setting value to avoid introducing a permission issue</li>
                        <li>temporarily disable memory tagging for the Pixel Camera Services app until memory corruption bugs are resolved</li>
                        <li>extend one-time removal of leftover Vanadium library state to handle it for Alpha/Beta users who removed it from Owner themselves but still have it in other users</li>
                    </ul>
                </article>

                <article id="2024101900">
                    <h3><a href="#2024101900">2024101900</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024101900">2024101900</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024101801 release:</p>

                    <ul>
                        <li>drop existing "Send device name" setting value for all Wi-Fi networks to start from our default of disabled for all users including people who updated to the Beta and Alpha releases already (we already switched the default to off for new networks in <a href="#2024101800">2024101800</a>)</li>
                        <li>limit removal of shared library updates as part of our system APK verified boot feature to those equal to the OS version since older versions are already dealt with and removing them this way leaves behind stale package state cluttering the UI</li>
                        <li>run a one-time task to remove leftover Vanadium library state to avoid showing a list of old versions</li>
                        <li>Settings: fix upstream Android 15 bug causing a crash for the network privacy menu when the AP name has special characters</li>
                        <li>Sandboxed Google Play compatibility layer: add stubs for NearbyManager API to avoid crashes from Find My Device feature</li>
                        <li>Dialer: fix new upstream crashes in Android 15 caused by R8 optimization</li>
                        <li>fix upstream Android 15 bug causing a Wallet quick tile provided by a user installed app to be automatically added, which isn't intended</li>
                        <li>fix upstream Android bug causing crash when showing app's first confirmation prompt for PackageInstaller</li>
                    </ul>
                </article>

                <article id="2024101801">
                    <h3><a href="#2024101801">2024101801</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024101801">2024101801</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024101800 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: only check for SET_BIOMETRIC_DIALOG_ADVANCED permission for GmsCompat apps to avoid causing crashes elsewhere</li>
                    </ul>
                </article>

                <article id="2024101800">
                    <h3><a href="#2024101800">2024101800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024101800">2024101800</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024101701 release:</p>

                    <ul>
                        <li>stop enabling the new Android 15 "Send device name" toggle for Wi-Fi networks by default to continue avoiding sending the device model (default) or user configured device name as a DHCP client hostname (Alpha channel testers on our previous Android 15 releases need to toggle it off for each existing network themselves if they don't want it)</li>
                        <li>Sandboxed Google Play compatibility layer: handle lack of SET_BIOMETRIC_DIALOG_ADVANCED permission</li>
                    </ul>
                </article>

                <article id="2024101701">
                    <h3><a href="#2024101701">2024101701</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024101701">2024101701</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024101700 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: declare C2DM SEND permission ourselves in addition to the already covered READ_GSERVICES and C2DM RECEIVE to avoid issues with Firebase Cloud Messaging for fresh installs of sandboxed Google Play without the Google Services Framework (GSF) app that's no longer a dependency in our App Store for Android 15</li>
                        <li>Settings: enable our per-connection Wi-Fi MAC randomization feature by default for new networks again on Android 15 instead of the standard per-network approach</li>
                        <li>Settings: extend change in the previous release for hiding inaccurate Private Space information</li>
                        <li>persist GrapheneOS-specific package state when archiving an app</li>
                        <li>Radio Info, Wi-Fi testing (Settings): opt-out of Android 15 edge-to-edge since it's not properly supported yet (upstream bug)</li>
                        <li>stop excluding Gallery from Private Space</li>
                    </ul>
                </article>

                <article id="2024101700">
                    <h3><a href="#2024101700">2024101700</a></h3>

                    <p>This is the second release of GrapheneOS based on Android 15 based on the
                    October 15th stable release of Android 15. It fixes nearly all of the reported
                    regressions, but we have a couple more things to fix in another release later
                    today before the release will be able to reach Beta and Stable.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024101700">2024101700</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024101600 release:</p>

                    <ul>
                        <li>fix upstream Android 15 bug in InputMethodManagerService.resetDefaultImeLocked() causing system_server crash from null pointer exception</li>
                        <li>fix upstream Android 15 bug in KeyguardUpdateMonitor.onPostureChanged() causing SystemUI crash on foldable devices from null pointer exception due to GrapheneOS currently only having fingerprint unlock and not face unlock</li>
                        <li>Messaging: add new permissions needed on Android 15 (READ_CELL_BROADCASTS and RECEIVE_WAP_PUSH) which avoids it prompting to be set as the default app instead of completing certain actions requiring privileges it was missing</li>
                        <li>Settings: port our default enabled per-connection MAC randomization option to the new Compose-based UI in Android 15 so the default mode displays properly and it can be restored back to the default value</li>
                        <li>fix Android 15 port of our toggle for disabling granting our Sensors permission by default</li>
                        <li>Storage Manager, Emergency Info: opt-out of Android 15 edge-to-edge since it's not properly supported yet (upstream bugs)</li>
                        <li>Sandboxed Google Play compatibility layer: replace GmsCompatConfig Bluetooth stubs with in-place checks for improved reliability and readability</li>
                        <li>ignore the standard stock OS configured Factory Reset Protection since installing GrapheneOS implies the ability to bypass it via the device being unlocked and if we added our own anti-theft system it would not use the same approach using Google account recovery</li>
                        <li>disable temporary unconditional system crash notifications since we've gotten the initial feedback we needed via the previous release</li>
                        <li>Launcher: remove "Install in private" shortcut for now since the standard behavior of opening the app in the first party app store isn't currently useful on GrapheneOS right now and is confusing to users</li>
                        <li>Settings: hide inaccurate "access private space when hidden" text that's not currently relevant to GrapheneOS since AOSP doesn't have this launcher feature yet</li>
                        <li>Keyboard: remove launcher icon to avoid it temporarily showing up in new users/profiles (not a recent regression)</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-142">version 142</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-143">version 143</a></li>
                    </ul>
                </article>

                <article id="2024101600">
                    <h3><a href="#2024101600">2024101600</a></h3>

                    <p>This is the initial release of GrapheneOS based on Android 15 based on the
                    October 15th stable release of Android 15. We had previously ported all of our
                    features to Android 15 based on the Beta releases and have been finishing it up
                    based on the early September release of the source code for Android 15. Our
                    initial port of all our features was completed on September 3rd and we've been
                    polishing it up while we've been working on regular development.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024101600">2024101600</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024101200 release:</p>

                    <ul>
                        <li>full 2024-10-05 security patch level since the Pixel patches were disclosed in the Pixel Update Bulletin today</li>
                        <li>rebased onto AP3A.241005.015 Android Open Source Project release (Android 15)</li>
                        <li>full port of GrapheneOS features to Android 15 including integration of our features with the new Android 15 features including Private Space</li>
                        <li>Sandboxed Google Play compatibility layer: add stubs to fully remove the need for the Google Services Framework (GSF) app for fresh installs of sandboxed Google Play, which has been removed as a dependency in our app repository for Android 15+, but it should still be kept for existing installs to avoid potential issues</li>
                        <li>Pixel 9 Pro Fold: add assorted device-specific Settings and SystemUI changes to better match the stock OS</li>
                        <li>disable Bluetooth auto-on feature by default</li>
                        <li>temporarily enable system crash notifications unconditionally for the initial release based on Android 15 release</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.56</li>
                        <li>Seedvault: update to a newer revision (will be replaced with a better backup implementation in the future)</li>
                        <li>Seedvault: minor changes to prepare for a complete fork and overhaul in the future</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/130.0.6723.58.0">version 130.0.6723.58.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-141">version 141</a></li>
                    </ul>
                </article>

                <article id="2024101200">
                    <h3><a href="#2024101200">2024101200</a></h3>

                    <p>Pixel 4a (5G), Pixel 5 and Pixel 5a are end-of-life and shouldn't be used
                    anymore due to lack of security patches for firmware and drivers. We provide
                    extended support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024101200-redfin">2024101200-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024101200">2024101200</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024101200-caimito">2024101200-caimito</a> (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold)</li>
                    </ul>

                    <p>Changes since the 2024100800 release:</p>

                    <ul>
                        <li>hardened_malloc: preserve hardware memory tagging enforcement flag for slab mappings when releasing free slabs</li>
                        <li>hardened_malloc: improve accuracy of probability hint for hardware memory tagging branches</li>
                        <li>temporarily revert enforcing minimum 64kiB stack guard size for arm64 since Facebook recently included a buggy stack overflow check for the React Native Hermes runtime that's incompatible with larger gap sizes and beginning to be shipped by apps</li>
                        <li>Log Viewer: add "bootloader unlocked" and "dev options enabled" flags to header</li>
                        <li>Log Viewer: add "More info" button to native crash reports</li>
                        <li>Log Viewer: include contents of App Not Responding (ANR) stack traces file in ANR error reports</li>
                        <li>Log Viewer: omit processUptime header line when it's unknown</li>
                        <li>Settings Intelligence (Settings search): fix upstream bug resulting in corruption of the query history database which leads to the search crashing</li>
                        <li>Launcher: mark 2x2 workspace option as being for phones</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.54</li>
                        <li>adevtool: update carrier settings</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/129.0.6668.100.0">version 129.0.6668.100.0</a></li>
                    </ul>
                </article>

                <article id="2024100800">
                    <h3><a href="#2024100800">2024100800</a></h3>

                    <p>This is an early October security update release based on the October 2024
                    security patch backports since a monthly Android Open Source Project and stock
                    Pixel OS release based on Android 14 QPR3 hasn't been published yet. Android 15
                    is scheduled for release around October 15th and they may not have a monthly
                    release based on Android 14 QPR3 before then.</p>

                    <p>Pixel 4a (5G), Pixel 5 and Pixel 5a are end-of-life and shouldn't be used
                    anymore due to lack of security patches for firmware and drivers. We provide
                    extended support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024100800-redfin">2024100800-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024100800">2024100800</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024100800-caimito">2024100800-caimito</a> (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold)</li>
                    </ul>

                    <p>Changes since the 2024092900 release:</p>

                    <ul>
                        <li>full 2024-10-01 security patch level</li>
                        <li>overhaul the implementation of our USB-C port control feature to improve robustness and error reporting</li>
                        <li>fix an upstream Android Bluetooth use-after-free bug uncovered by GrapheneOS hardware memory tagging that's triggered when obtaining internet access from another device via Bluetooth</li>
                        <li>fix an upstream Android race condition bug in handling of system error files to avoid using the wrong timestamps for system errors and then reporting them as new errors after reboot</li>
                        <li>work around an upstream Android bug causing our Log Viewer feature to stop working after system_server restarts</li>
                        <li>add handling for early boot-time system journal notifications</li>
                        <li>kernel (5.10, 5.15, 6.1, 6.6): backport upstream patch fixing a hole in SELinux W^X enforcement</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.226</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.167</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.112</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.53</li>
                        <li>TalkBack (screen reader): update dependencies</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/129.0.6668.81.0">version 129.0.6668.81.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-140">version 140</a></li>
                    </ul>
                </article>

                <article id="2024092900">
                    <h3><a href="#2024092900">2024092900</a></h3>

                    <p>Pixel 4a (5G), Pixel 5 and Pixel 5a are end-of-life and shouldn't be used
                    anymore due to lack of security patches for firmware and drivers. We provide
                    extended support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024092900-redfin">2024092900-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024092900">2024092900</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024092900-caimito">2024092900-caimito</a> (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold)</li>
                    </ul>

                    <p>Changes since the 2024091900 release:</p>

                    <ul>
                        <li>extend standard Android eBPF filter to prevent apps sending multicast packets outside of the VPN tunnel either directly or indirectly via kernel-generated multicast traffic (IGMP, MLD) when leak blocking is enabled (2nd generation implementation with improved app compatibility)</li>
                        <li>add netfilter-based multicast firewall only permitting sending multicast packets to permitted tunnel interfaces for the process to prevent apps sending multicast packets through a VPN tunnel for another profile (2nd generation implementation with improved IPv6 and app compatibility)</li>
                        <li>Sandboxed Google Play compatibility layer: add stub for Bluetooth AdvertisingSetParameters.setOwnAddressType() API needed for receiving files through Quick Share</li>
                        <li>Sandboxed Google Play compatibility layer: ignore GattServer in BTLeAdvertiser.startAdvertisingSet() needed for receiving files through Quick Share</li>
                        <li>Auditor: add battery optimization exception to avoid delays for the opt-in scheduled remote verification since users rarely interact with the app resulting in it being placed into semi-restricted standby buckets</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/86">version 86</a></li>
                        <li>App Store: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/26">version 26</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/129.0.6668.70.0">version 129.0.6668.70.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-138">version 138</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-139">version 139</a></li>
                    </ul>
                </article>

                <article id="2024091900">
                    <h3><a href="#2024091900">2024091900</a></h3>

                    <p>Pixel 4a (5G), Pixel 5 and Pixel 5a are end-of-life and shouldn't be used
                    anymore due to lack of security patches for firmware and drivers. We provide
                    extended support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024091900-redfin">2024091900-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024091900">2024091900</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024091900-caimito">2024091900-caimito</a> (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold)</li>
                    </ul>

                    <p>Changes since the 2024091700 release:</p>

                    <ul>
                        <li>temporarily revert multicast leak blocking firewall due to causing legacy 5th gen devices to lose compatibility with IPv6-only carriers along with causing certain compatibility issues with IPv6 on Wi-Fi</li>
                        <li>temporarily revert multicast leak blocking eBPF filter extensions until app compatibility is addressed in a similar way as the Network permission mimics non-security errors</li>
                    </ul>
                </article>

                <article id="2024091700">
                    <h3><a href="#2024091700">2024091700</a></h3>

                    <p>Pixel 4a (5G), Pixel 5 and Pixel 5a are end-of-life and shouldn't be used
                    anymore due to lack of security patches for firmware and drivers. We provide
                    extended support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024091700-redfin">2024091700-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024091700">2024091700</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024091700-caimito">2024091700-caimito</a> (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold)</li>
                    </ul>

                    <p>Changes since the 2024090400 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: handle the updated client dynamite module initialization sequence</li>
                        <li>extend standard Android eBPF filter to prevent apps sending multicast packets outside of the VPN tunnel either directly or indirectly via kernel-generated multicast traffic (IGMP, MLD) when leak blocking is enabled</li>
                        <li>add netfilter-based multicast firewall only permitting sending multicast packets to permitted interfaces for the process to prevent apps sending multicast packets through a disallowed interface such as a VPN tunnel for another profile</li>
                        <li>exclude com.android.rkpdapp from backup/restore to avoid breaking key provisioning for hardware key attestation including for Auditor (users can clear RemoteProvisioner system app data via Settings if they restored data for it and have this issue)</li>
                        <li>Pixel 9 Fold Pro: temporarily manually add resource overlays not yet automatically handled by adevtool from the stock Pixel OS to use the correct layout for quick settings, status bar, etc. and to provide the split folded/unfolded auto-rotate settings (this will be replaced by adevtool improvements before the end of the month since we'll need it for more resources in Android 15)</li>
                        <li>hardened_malloc: fix microdroid virtual machine compatibility by using armv8a+dotprod+memtag when enabling memory tagging instead of armv9+memtag</li>
                        <li>init: disable auto-reboot setup for microdroid virtual machines</li>
                        <li>expat: backport patches for CVE-2024-28757, CVE-2024-45490, CVE-2024-45491 and CVE-2024-45492 (none of these is exploitable on official GrapheneOS since the DoS bug involves a feature Android doesn't use, the integer overflows require that size_t is 32-bit which is never going to be the case due to the code only being used in 64-bit processes and the negative parameter API issue requires a usage pattern not done by Android, but the integer overflows would be exploitable on an official build for a 32-bit device or a 64-bit device still partially using 32-bit drivers)</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.225</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.165</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.104</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.51</li>
                        <li>TalkBack (screen reader): update dependencies</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/128.0.6613.127.0">version 128.0.6613.127.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/128.0.6613.146.0">version 128.0.6613.146.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/129.0.6668.54.0">version 129.0.6668.54.0</a></li>
                        <li>App Store: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/25">version 25</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/85">version 85</a></li>
                        <li>Info: update to <a href="https://github.com/GrapheneOS/Info/releases/tag/4">version 4</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-136">version 136</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-137">version 137</a></li>
                    </ul>
                </article>

                <article id="2024090400">
                    <h3><a href="#2024090400">2024090400</a></h3>

                    <p>Pixel 4a (5G), Pixel 5 and Pixel 5a are end-of-life and shouldn't be used
                    anymore due to lack of security patches for firmware and drivers. We provide
                    extended support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024090400-redfin">2024090400-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024090400">2024090400</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024090400-caimito">2024090400-caimito</a> (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold)</li>
                    </ul>

                    <p>Changes since the 2024083100 release:</p>

                    <ul>
                        <li>full 2024-09-05 security patch level</li>
                        <li>rebased onto AP2A.240905.003 (generic) and AD1A.240905.004 (caimito) Android Open Source Project releases</li>
                        <li>Sandboxed Google Play compatibility layer: add support for using GSF 34 on SDK 35 (Android 15) to handle the case where users have just upgraded the OS but haven't yet updated GSF</li>
                        <li>Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold: fix an upstream use-after-free bug present in 2 drivers</li>
                        <li>allow Pixel Thermometer and Fitbit to see each other as a special case</li>
                        <li>allow current launcher to see the Pixel Thermometer app as a special case</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.47</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-134">version 134</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-135">version 135</a></li>
                    </ul>
                </article>

                <article id="2024083100">
                    <h3><a href="#2024083100">2024083100</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024083100-redfin">2024083100-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024083100">2024083100</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024083100-caimito">2024083100-caimito</a> (Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold)</li>
                    </ul>

                    <p>Changes since the 2024082200 release:</p>

                    <ul>
                        <li>don't hide Exploit protection Safety Center item in secondary users</li>
                        <li>Settings: improve UI for GrapheneOS app toggles including adding a screen for viewing the values across apps for each toggle</li>
                        <li>add more infrastructure for blocking dynamic code loading</li>
                        <li>Settings: add per-app memory dynamic code loading restriction toggle (applies to both native code and Android Runtime class loading for Java/Kotlin)</li>
                        <li>Settings: add per-app storage dynamic code loading restriction toggle (applies to both native code and Android Runtime class loading for Java/Kotlin), temporarily without a global toggle until Google phases out the old dynamite module system for Google Play due to many apps temporarily depending on this through it</li>
                        <li>Settings: add per-app WebView JIT restriction toggle</li>
                        <li>add production support for the Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL and Pixel 9 Pro Fold</li>
                        <li>add support for enabling app association restrictions without exemptions (currently for use with Pixel Thermometer)</li>
                        <li>add support for Pixel Thermometer app available from our App Store for the Pixel 8 Pro, Pixel 9 Pro and Pixel 9 Pro XL with strict isolation from other apps</li>
                        <li>add missing feature compatibility matrix definitions (mainly for 9th generation Pixels)</li>
                        <li>Contact Scopes: explicitly set initialization order after ContactsProvider2 to avoid uncaught exceptions from a race</li>
                        <li>kernel (6.1): disable unused hibernation support</li>
                        <li>kernel (6.1, 6.6): enable struct randomization in the full mode with a deterministic seed based on kernel commit timestamp (we plan to also incorporate the device family and eventually make the seed specific to each device model, but it will increase our build/testing workload)</li>
                        <li>kernel (6.6): enable random kmalloc caches</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.96</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.46</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/128.0.6613.88.1">version 128.0.6613.88.1</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/128.0.6613.99.0">version 128.0.6613.99.0</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/84">version 84</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-131">version 131</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-132">version 132</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-133">version 133</a></li>
                        <li>drop restriction on modifying GrapheneOS-specific per-package settings via ADB shell since it makes certain important testing require debug builds and has no real security value</li>
                        <li>flash-all.sh: restore POSIX sh compatibility to allow using sh instead of bash on systems where sh is dash or another non-bash-compatible shell</li>
                        <li>add support for using backslashes in the passphrases for encrypting the keys for signing OS releases</li>
                    </ul>
                </article>

                <article id="2024082200">
                    <h3><a href="#2024082200">2024082200</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024082200-redfin">2024082200-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024082200">2024082200</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024082000 release:</p>

                    <ul>
                        <li>Settings: fix regression in the previous release which blocked it reaching the Stable channel by making the duress PIN/password configuration unavailable in secondary users again (it was only usable when the secondary user had the same unlock PIN/password as the Owner user)</li>
                        <li>adevtool: remove non-functional repair mode support</li>
                        <li>adevtool: remove non-functional digital car key support (requires privileged Google Play)</li>
                        <li>adevtool: remove invalid clock font family overlay (google-sans-clock font not included)</li>
                        <li>adevtool: update carrier settings</li>
                        <li>Pixel 8a: add Let's Encrypt (ISRG) roots for Samsung gnssd SUPL connections via adevtool instead to share the implementation with 9th generation Pixels</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/83">version 83</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/128.0.6613.88.0">version 128.0.6613.88.0</a></li>
                    </ul>
                </article>

                <article id="2024082000">
                    <h3><a href="#2024082000">2024082000</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024082000-redfin">2024082000-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024082000">2024082000</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024080600 release:</p>

                    <ul>
                        <li>Settings: enable Safety Center and port all of the relevant GrapheneOS settings to it both to provide the more modern user interface and to prepare for the release of Android 15</li>
                        <li>hide Safety Center camera extensions fallback toggle when it's not relevant (not used on Pixels)</li>
                        <li>Package Installer: fix upstream bug causing null pointer exception in rare edge cases including a rare race condition</li>
                        <li>require Owner user credential to check whether a duress PIN/password is enabled as hardening against potential UI bugs such as the upstream predictive back gesture issue we patched in the Settings app</li>
                        <li>apply upstream change for 6th generation Pixels making snapuserd available in recovery to avoid a problem in a rare edge case where a factory reset occurs before finishing booting a new update</li>
                        <li>apply minor upstream fixes for Settings which were temporarily only shipped for certain Pixels</li>
                        <li>add fastboot to otatools.zip for optimized factory images generation</li>
                        <li>flash-all: raise minimum fastboot version to 35.0.1</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.223</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.164</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.95</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.45</li>
                        <li>remove duplicate Android.bp from unpacked otatools.zip to avoid breaking subsequent builds when it's unpacked in the source tree</li>
                        <li>add Android 15 Beta build configuration for early development/testing of our Android 15 port via an ap2f release configuration enabling all of the available Android 15 feature flags</li>
                        <li>port GrapheneOS changes to new code for Android 15 used by our Android 15 Beta build configuration</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/127.0.6533.104.0">version 127.0.6533.104.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/127.0.6533.104.1">version 127.0.6533.104.1</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/127.0.6533.104.2">version 127.0.6533.104.2</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/127.0.6533.104.3">version 127.0.6533.104.3</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-128">version 128</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-129">version 129</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-130">version 130</a></li>
                    </ul>
                </article>

                <article id="2024080600">
                    <h3><a href="#2024080600">2024080600</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024080600-redfin">2024080600-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024080600">2024080600</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024080500 release:</p>

                    <ul>
                        <li>full 2024-08-05 security patch level</li>
                        <li>rebased onto AP2A.240805.005 Android Open Source Project release</li>
                        <li>adevtool: update dependencies</li>
                        <li>adevtool: improve code quality</li>
                        <li>adevtool: use fastboot packs to extract firmware images to avoid the need to download over-the-air updates, which also removes the dependency on python and python-protobuf for extracting vendor files</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/127.0.6533.103.0">version 127.0.6533.103.0</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/74">version 74</a></li>
                    </ul>
                </article>

                <article id="2024080500">
                    <h3><a href="#2024080500">2024080500</a></h3>

                    <p>This is an early August security update release based on the August 2024
                    security patch backports. This month's release of the Android Open Source
                    Project and stock Pixel OS should be available later today or tomorrow and we'll
                    quickly release an update based on it following this one.</p>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024080500-redfin">2024080500-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024080500">2024080500</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024080200 release:</p>

                    <ul>
                        <li>full 2024-08-01 security patch level</li>
                        <li>suppress crash notifications for 2 harmless crashes occuring on service shutdown for the Android Bluetooth service and Pixel wifi_ext service</li>
                        <li>enable memory tagging for the Pixel wifi_ext service again</li>
                        <li>Settings: disable predictive back gesture in PIN/password input activities to fix an upstream Android vulnerability</li>
                        <li>flash-all: remove unnecessary sleep after flashing AVB key</li>
                        <li>flash-all: exit on errors</li>
                        <li>flash-all.sh: avoid false negative for device model check</li>
                        <li>flash-all.bat: pause before exiting after an error</li>
                        <li>fastboot: add support for CLI install with the GrapheneOS optimized factory images format already used by the web installer (will reduce memory/storage usage for CLI installs and will reduce storage usage on the update servers by avoiding multiple factory image formats)</li>
                        <li>hardened_malloc: update libdivide to 5.1</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.43</li>
                    </ul>
                </article>

                <article id="2024080200">
                    <h3><a href="#2024080200">2024080200</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024080200-redfin">2024080200-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024080200">2024080200</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024080100 release:</p>

                    <ul>
                        <li>prevent VPN apps from having leaks to non-VPN DNS servers while not yet strictly preventing leaks to VPN DNS outside the VPN tunnel due to multiple VPN apps including Proton VPN not connecting reliably with stricter enforcement (in a future release, we can do strict blocking by default with an opt-out toggle and a list of known incompatible apps such as Proton VPN until the compatibility issue is resolved)</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-126">version 126</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-127">version 127</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/73">version 73</a></li>
                    </ul>
                </article>

                <article id="2024080100">
                    <h3><a href="#2024080100">2024080100</a></h3>

                    <p><strong>This release is only for the Alpha channel to replace the previous release.</strong></p>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024080100-redfin">2024080100-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024080100">2024080100</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024073100 release:</p>

                    <ul>
                        <li>revert VPN DNS leak protection again since it's still partially incompatible with Proton VPN and certain other apps for unknown reasons, although we did avoid a lot of the compatibility issues from last time</li>
                    </ul>
                </article>

                <article id="2024073100">
                    <h3><a href="#2024073100">2024073100</a></h3>

                    <p><strong>This release was only pushed out to the Alpha channel.</strong></p>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024073100-redfin">2024073100-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024073100">2024073100</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024072800 release:</p>

                    <ul>
                        <li>add back our change to prevent app-based VPN implementations from leaking DNS requests when the VPN is down/connecting but without enforcement for VPN apps without DNS configured to avoid breaking compatibility in rare cases (our previous implementation in <a href="#2024050900">2024050900</a> had to be reverted before it reached Stable)</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/72">version 72</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/127.0.6533.84.0">version 127.0.6533.84.0</a></li>
                    </ul>
                </article>

                <article id="2024072800">
                    <h3><a href="#2024072800">2024072800</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024072800-redfin">2024072800-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024072800">2024072800</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024071600 release:</p>

                    <ul>
                        <li>avoid isolating eUICC LPA (eSIM activation) app from third party apps to allow carrier activation apps to work (we still block communication with Google Play to avoid sending telemetry data to Google services when sandboxed Google Play is installed)</li>
                        <li>Pixel 8a: fix GNSS configuration to avoid occasional crashes of the service (Pixel 8a is currently the only Samsung GNSS device)</li>
                        <li>Settings: don't allow disabling user installed apps when uninstall is disallowed</li>
                        <li>Settings: drop code for supporting the legacy Settings UI</li>
                        <li>Sandboxed Google Play compatibility layer: avoid infinite wait for GmsCompatConfig update when call to App Store fails</li>
                        <li>enforce stack clash protection for x86_64</li>
                        <li>enforce minimum 64kiB stack guard size for arm64 due to the standard stack probe size of 64kiB</li>
                        <li>future proof our Bionic libc changes for dynamic 64k pages (hardened_malloc still doesn't support it)</li>
                        <li>flash-all: remove unnecessary reboot after flashing Android Verified Boot (AVB) key</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.222</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.163</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.92</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.42</li>
                        <li>adevtool: update to latest carrier settings</li>
                        <li>App Store: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/24">version 24</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/69">version 69</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/70">version 70</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/71">version 71</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/81">version 81</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/82">version 82</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/127.0.6533.64.0">version 127.0.6533.64.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/127.0.6533.64.1">version 127.0.6533.64.1</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-124">version 124</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-125">version 125</a></li>
                        <li>fastboot: add support for generating web installer optimized factory images zip for an improved web install approach not requiring fastbootd</li>
                        <li>integrate generating web installation optimized factory images zip into release signing script</li>
                        <li>split script/release.sh to remove dependency on build output and the OS source tree (see the new instructions for signing releases)</li>
                        <li>rename script/release.sh to script/generate-release.sh</li>
                        <li>add script/generate-releases.sh wrapper script</li>
                    </ul>
                </article>

                <article id="2024071600">
                    <h3><a href="#2024071600">2024071600</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024071600-redfin">2024071600-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024071600">2024071600</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024071200 release:</p>

                    <ul>
                        <li>fix touch-to-unlock setting on devices with a power button fingerprint scanner (Pixel Fold, Pixel Tablet) which is normally always active with AOSP</li>
                        <li>avoid race for setting USB port mode when the lock method is set to none (lockscreen disabled)</li>
                        <li>Pixel Tablet: add non-standard toggle for enabling touchscreen frequency hopping to reduce ghost touches for users with problematic touchscreen hardware</li>
                        <li>kernel (5.10, 5.15): revert a USB change backported to kernel.org LTS that's causing DisplayPort alternate mode compatibility issues</li>
                        <li>Pixel 8a: fix GNSS configuration to avoid occasional crashes of the service (Pixel 8a is currently the only Samsung GNSS device)</li>
                        <li>backport mainline APEX module patches for Media Provider, Network Stack, Remote Key Provisioning and Wi-Fi</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.221</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.161</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-123">version 123</a></li>
                    </ul>
                </article>

                <article id="2024071200">
                    <h3><a href="#2024071200">2024071200</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024071200-redfin">2024071200-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024071200">2024071200</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024070900 release:</p>

                    <ul>
                        <li>kernel (Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a): temporarily revert disabling 32-bit ABI support due to rare cases of apps using a buggy anti-tampering library incorrectly calling 32-bit versions of system calls from 64-bit code even on devices with no 32-bit support in hardware</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.160</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.38</li>
                        <li>TalkBack (screen reader): update dependencies</li>
                        <li>TalkBack (screen reader): remove more unused resources</li>
                        <li>TalkBack (screen reader): drop 32-bit OS support</li>
                    </ul>
                </article>

                <article id="2024070900">
                    <h3><a href="#2024070900">2024070900</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024070900-redfin">2024070900-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024070900">2024070900</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024070201 release:</p>

                    <ul>
                        <li>Settings: extend standard fingerprint enrollment stages with proper support for devices with power button fingerprint scanners (Pixel Fold, Pixel Tablet) which is not present in AOSP (Pixel Fold was still usable, but it had become incredibly hard to successfully register new fingerprints on the Pixel Tablet)</li>
                        <li>improve warning for 32-bit-only apps by explaining why the warning is shown, how to resolve it for apps that are still developed and that we plan to phase out support for it on 5th/6th generation Pixels where it's still available</li>
                        <li>show warning for 32-bit-only apps on each launch instead of only once</li>
                        <li>kernel (Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a): disable 32-bit ABI support to substantially decrease kernel size and attack surface and raise mmap_min_addr to the standard 65536 for 64-bit-only ARM</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.158</li>
                        <li>adevtool: update file removal for 8th gen Pixels to skip Family Space related files</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-122">version 122</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/126.0.6478.122.3">version 126.0.6478.122.3</a></li>
                    </ul>
                </article>

                <article id="2024070201">
                    <h3><a href="#2024070201">2024070201</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024070201">2024070201</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024070200 release:</p>

                    <ul>
                        <li>full 2024-07-05 security patch level</li>
                        <li>rebased onto AP2A.240705.005 Android Open Source Project release</li>
                        <li>avoid skipping toggling USB port after unlock in certain edge cases to make sure devices connected while locked are always detected when unlocking</li>
                        <li>fix upstream bug causing first party app stores using the package install dialog to be blocked when the user isn't allowed to install apps from third party sources</li>
                        <li>fix notification suppression check in currently unused code to prepare for our per-app clipboard toggle</li>
                        <li>adevtool: download and use latest Pixel carrier settings from the API for use by our CarrierConfig2 app instead of using the snapshot included in the latest Pixel stock OS release since it lags months behind</li>
                        <li>Settings: fully fix regression permitting disabling apps when it shouldn't be allowed due to device manager policy</li>
                        <li>Sandboxed Google Play compatibility layer: stub out reads of hidden system settings in Google's speech services app to avoid uncaught security exceptions</li>
                        <li>Sandboxed Google Play compatibility layer: don't allow the Play Store to abort pending package installation to avoid it cancelling install/update attempts after 10 minutes of waiting for requested user approval it hasn't been designed to handle</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.218</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.155</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.36</li>
                    </ul>
                </article>

                <article id="2024070200">
                    <h3><a href="#2024070200">2024070200</a></h3>

                    <p>This is an early July security update release based on the July 2024 security
                    patch backports. This month's release of the Android Open Source Project and
                    stock Pixel OS will be available later today and we'll quickly release an update
                    based on it following this one.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024070200">2024070200</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024062700 release:</p>

                    <ul>
                        <li>full 2024-07-01 security patch level</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/126.0.6478.122.1">version 126.0.6478.122.1</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/126.0.6478.122.2">version 126.0.6478.122.2</a></li>
                        <li>Info: update to <a href="https://github.com/GrapheneOS/Info/releases/tag/3">version 3</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-121">version 121</a></li>
                    </ul>
                </article>

                <article id="2024062700">
                    <h3><a href="#2024062700">2024062700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024062700">2024062700</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024062000 release:</p>

                    <ul>
                        <li>add new GrapheneOS Info app through which you can get information about the latest releases of GrapheneOS, links to our community spaces, and details on how to make donations</li>
                        <li>Pixel 8a: add Let's Encrypt roots to Samsung gnssd CA root store for supl.grapheneos.org</li>
                        <li>Pixel 8a: configure Samsung gnssd to use TLSv1.2 for SUPL instead of TLSv1.1 (TLSv1.3 would work but the config doesn't offer it)</li>
                        <li>Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold: fully remove 32-bit ARM support to significantly reduce build time and update download size with no loss of functionality (7th gen Pixels launched with 32-bit app support disabled after several years of the Play Store blocking uploading 32-bit-only apps or installing them on 64-bit devices, and 8th gen Pixels use 2nd gen ARMv9 cores with no 32-bit support)</li>
                        <li>Settings: fix several cases of UI state being lost when resuming activity after configuration changes, etc. for GrapheneOS settings</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.216</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.90</li>
                        <li>kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.35</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/126.0.6478.122.0">version 126.0.6478.122.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-120">version 120</a></li>
                    </ul>
                </article>

                <article id="2024062000">
                    <h3><a href="#2024062000">2024062000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024062000">2024062000</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024061400 release:</p>

                    <ul>
                        <li>remove our USB peripheral security setting on devices supporting our much better USB-C port mode (Pixel 6 and later)</li>
                        <li>extend USB-C port setting to also handle pogo pins on the Pixel Tablet</li>
                        <li>kernel (5.10, 5.15, 6.1, 6.6): replace our deny_new_usb feature with a new deny_new_usb2 feature also disabling USB gadgets</li>
                        <li>extend USB-C port setting to enable deny_new_usb2 as a second layer of defense disabling new USB connections in the kernel (the existing implementation disables new connections and USB data at a hardware level via the USB controller, which disables more attack surface, but we want to keep around the higher level kernel approach too)</li>
                        <li>Files: fix upstream null pointer exception triggered on resuming activity</li>
                        <li>Settings: require user authentication for changing auto-reboot, USB peripheral and USB-C port security settings</li>
                        <li>Settings: avoid prompting for user authentication when selecting the same value as before for GrapheneOS settings requiring it</li>
                        <li>temporarily add back memory tagging exception for Pixel wifi_ext service</li>
                        <li>simplify implementation of our auto-reboot feature and properly handle the first lock after the user first sets up a lock method</li>
                        <li>avoid resetting USB-C port after first unlock if it was already connected Before First Unlock (fix for regression caused by upstream changes)</li>
                        <li>add GrapheneOS Linux kernel port to the 6.6 GKI LTS branch</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.215</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.87</li>
                        <li>kernel (6.1, 6.6): add script for building emulator kernel</li>
                        <li>kernel (6.1, 6.6): enable forced module signing for x86_64 (emulator builds)</li>
                        <li>System Updater: increase update check interval to 6 hours from 4 hours</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/126.0.6478.110.0">version 126.0.6478.110.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-118">version 118</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-119">version 119</a></li>
                        <li>fix cast in GrapheneOS package management infrastructure needed for upcoming App Communication Scopes work</li>
                    </ul>
                </article>

                <article id="2024061400">
                    <h3><a href="#2024061400">2024061400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024061400">2024061400</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024061300 release:</p>

                    <ul>
                        <li>revert upstream refactoring of the device association code in Android 14 QPR3 due to it introducing a chain crash bug at boot in edge cases with associated devices such as paired Android Wear devices</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/126.0.6478.71.0">version 126.0.6478.71.0</a></li>
                    </ul>
                </article>

                <article id="2024061300">
                    <h3><a href="#2024061300">2024061300</a></h3>

                    <p>We've found at least one new issue with the Android Open Source Project 14
                    QPR3 Bluetooth module and are already working on resolving it. We'll have a
                    quick follow-up release fixing the Bluetooth regression and other issues
                    discovered during public Alpha and Beta testing.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024061300">2024061300</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024061200 release:</p>

                    <ul>
                        <li>fix upstream Android 14 QPR3 regression which breaks updating certain apps with our app repository client</li>
                        <li>fix boot-time optimizing apps progress UI with Android 14 QPR3 and enable it again</li>
                        <li>fix regression in our Android 14 QPR3 port resulting in PIN scrambling in secondary users being determined by the Owner user setting</li>
                        <li>revert upstream Android 14 QPR3 Internet quick tile overhaul since it broke the functionality in secondary users</li>
                        <li>temporarily add back disabling memory tagging and hardened_malloc for surfaceflinger since Android 14 QPR3 didn't fix it as expected</li>
                        <li>disable temporary unconditional system crash notifications since we've gotten the initial feedback we needed via the previous release</li>
                        <li>add additional null check for eSIM wiping done as part of the duress PIN/password wipe implementation to avoid harmless exception</li>
                        <li>Settings: remove blank illustration from "Screen resolution" screen</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/126.0.6478.50.1">version 126.0.6478.50.1</a></li>
                        <li>make duress PIN/password tests faster and more reliable</li>
                    </ul>
                </article>

                <article id="2024061200">
                    <h3><a href="#2024061200">2024061200</a></h3>

                    <p>This is the first release of GrapheneOS based on Android 14 QPR3, the 3rd
                    quarterly maintenance/feature release for Android 14.</p>

                    <p>We've found at least one new issue with the Android Open Source Project 14
                    QPR3 Bluetooth module and are already working on resolving it. We'll have a
                    quick follow-up release fixing the Bluetooth regression and other issues
                    discovered during public Alpha testing.</p>

                    <p>Pixel 8a is now supported as part of the standard Android releases instead of
                    having a device branch based on Android 14 QPR1. We've had stable releases for
                    it available since May 15th (1 day after launch) based on our last QPR1-based
                    release (2024030300). Pixel 8a users will be getting the GrapheneOS improvements
                    from March, April, May and June along with the Android 14 QPR2 and QPR3
                    improvements so it's a much larger release for the Pixel 8a.</p>

                    <p>Since Android 14 QPR3 is a major release, the end-of-life Pixel 4a (5G) and
                    Pixel 5 receiving extended support releases from GrapheneOS will need to be
                    ported to it with additional work in a future release, which is done as a low
                    priority. Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used
                    anymore due to lack of security patches for firmware and drivers. We provide
                    extended support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024061200">2024061200</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024060500 release:</p>

                    <ul>
                        <li>full 2024-06-05 security patch level</li>
                        <li>rebased onto AP2A.240605.024 Android Open Source Project release, which is the 3rd quarterly maintenance/feature release for Android 14 (QPR3)</li>
                        <li>temporarily disable boot-time optimizing apps progress UI due to upstream Android 14 QPR3 regression (our own post-boot background optimizing apps progress notification works fine)</li>
                        <li>temporarily enable system crash notifications unconditionally for the initial QPR3-based release</li>
                        <li>change default USB-C port mode to "Charging-only when locked" from "Charging-only when locked, except before first unlock"</li>
                        <li>stop disabling memory tagging and hardened_malloc for surfaceflinger</li>
                        <li>Settings: fix regression permitting disabling apps when it shouldn't be allowed due to device manager policy</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/126.0.6478.50.0">version 126.0.6478.50.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-117">version 117</a></li>
                    </ul>
                </article>

                <article id="2024060500">
                    <h3><a href="#2024060500">2024060500</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024060500-redfin">2024060500-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024060500">2024060500</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024060400 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: adjust to DynamiteLoader changes being deployed with a new feature flag in Play services 24.22</li>
                        <li>stop treating pressing the spacebar on a physical keyboard as submitting the lockscreen password since it prevents entering passphrases with spaces (upstream Android bug which has existed for around 8.5 years)</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/125.0.6422.165.0">version 125.0.6422.165.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-116">version 116</a></li>
                    </ul>
                </article>

                <article id="2024060400">
                    <h3><a href="#2024060400">2024060400</a></h3>

                    <p>This is an early June security update release based on the June 2024 security
                    patch backports since this month's release of the Android Open Source Project
                    and stock Pixel OS with Android 14 QPR3 isn't available yet.</p>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024060400-redfin">2024060400-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024060400">2024060400</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024053100 release:</p>

                    <ul>
                        <li>full 2024-06-01 security patch level</li>
                        <li>extend the standard wipe-without-reboot implementation beyond wiping the hardware keystores (which prevents recovering any OS data by preventing deriving the key encryption keys) by also wiping the secdiscardable data on the SSD needed to derive key encryption keys, the encrypted storage keys on the SSD and the Weaver slots in the secure element needed to derive per-user key encryption keys via a secure element erase</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision</li>
                    </ul>
                </article>

                <article id="2024053100">
                    <h3><a href="#2024053100">2024053100</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024053100-redfin">2024053100-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024053100">2024053100</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024052100 release:</p>

                    <ul>
                        <li>add support for setting a duress password and PIN for quickly wiping all hardware keystore keys including keys used as part of deriving the key encryption keys for disk encryption to make all OS data unrecoverable followed by wiping eSIMs and then shutting down</li>
                        <li>disable unused adoptable storage support since it would complicate duress password feature (can be added if we ever support a device able to use it)</li>
                        <li>increase default max password length to 128 to improve support for strong diceware passphrases, which will become more practical for people who don't want biometric-only secondary unlock with our upcoming 2-factor fingerprint unlock feature</li>
                        <li>disable camera lockscreen shortcut functionality when camera access while locked is disabled to avoid the possibility of misconfiguration by adding the camera lockscreen shortcut and then forgetting to remove it when disabling camera access</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.153</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/125.0.6422.72.0">version 125.0.6422.72.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/125.0.6422.72.1">version 125.0.6422.72.1</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/125.0.6422.113.0">version 125.0.6422.113.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/125.0.6422.147.0">version 125.0.6422.147.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-112">version 112</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-113">version 113</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-114">version 114</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-115">version 115</a></li>
                        <li>make SystemUI tests compatible with GrapheneOS changes</li>
                    </ul>
                </article>

                <article id="2024052100">
                    <h3><a href="#2024052100">2024052100</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024052100-redfin">2024052100-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024052100">2024052100</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024051500 release:</p>

                    <ul>
                        <li>add backport of the upstream Android implementation of wipe-without-reboot, which is the full fix for the ability to interrupt factory resets triggered by device admin apps (CVE-2024-29748 reported by GrapheneOS) and provides the infrastructure needed for our upcoming duress PIN/password feature in a much simpler way via existing HAL APIs</li>
                        <li>temporarily disable memory tagging for the Pixel camera provider and wifi_ext services due to incompatibilities found by users which should be addressed in an upcoming release of AOSP and the stock Pixel OS</li>
                        <li>Pixel 4a (5G), Pixel 5: omit Pixel Camera Services since it doesn't provide useful functionality and is broken due to these devices not being supported anymore by the current releases</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.214</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.152</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.84</li>
                        <li>Setup Wizard: fix typo in data restore description</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-111">version 111</a></li>
                    </ul>
                </article>

                <article id="2024051500">
                    <h3><a href="#2024051500">2024051500</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024051500-redfin">2024051500-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024051500">2024051500</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024050900 release:</p>

                    <ul>
                        <li>revert our initial approach to blocking DNS leaks with third party Android VPN apps since it changed the behavior in a slightly different way than intended and caused compatibility issues with certain apps (particularly Proton VPN) which blocked us from releasing 2024050900 to the Stable channel (will be replaced in the near future with another approach)</li>
                        <li>improve GrapheneOS Predicted Satellite Data Service (PSDS) infrastructure with better logging, cleaner code and more generic code to support Samsung PSDS for the Pixel 8a in addition to Qualcomm and Broadcom PSDS</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/80">version 80</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-110">version 110</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/125.0.6422.51.0">version 125.0.6422.51.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/125.0.6422.53.0">version 125.0.6422.53.0</a></li>
                    </ul>
                </article>

                <article id="2024050900">
                    <h3><a href="#2024050900">2024050900</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024050900-redfin">2024050900-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024050900">2024050900</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024050700 release:</p>

                    <ul>
                        <li>prevent app-based VPN implementations from leaking DNS requests when the VPN is down/connecting (this is a preliminary defense against this issue and more research is required, along with apps preventing the leaks on their end or they'll still have leaks outside of GrapheneOS)</li>
                        <li>exclude Settings app from visible Location indicator too since it gets triggered from accessing Wi-Fi data when enabling Wi-Fi hotspot and potentially other info tied to Wi-Fi and Bluetooth</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/125.0.6422.35.0">version 125.0.6422.35.0</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/19">version 19</a></li>
                    </ul>
                </article>

                <article id="2024050700">
                    <h3><a href="#2024050700">2024050700</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024050700-redfin">2024050700-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024050700">2024050700</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024050300 release:</p>

                    <ul>
                        <li>full 2024-05-05 security patch level</li>
                        <li>rebased onto AP1A.240505.005 Android Open Source Project release</li>
                        <li>update our backports of mainline APEX Health Fitness patches</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.213</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.151</li>
                        <li>TalkBack (screen reader): update dependencies</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/124.0.6367.159.0">version 124.0.6367.159.0</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/18">version 18</a></li>
                    </ul>
                </article>

                <article id="2024050300">
                    <h3><a href="#2024050300">2024050300</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024050300-redfin">2024050300-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024050300">2024050300</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024042200 release:</p>

                    <ul>
                        <li>remove special handling of the resolver activity ("Open with..." dialog) which was added to Android in order to support instant apps as preparation for our in-development App Communication Scopes feature</li>
                        <li>fix Google Fi eSIM activation</li>
                        <li>improve isolation of the eSIM activation apps</li>
                        <li>improve GrapheneOS infrastructure for per-app state</li>
                        <li>enable heap memory tagging for vendor processes by default, remove the user-facing toggle in the Settings and restrict toggling the value to debug builds</li>
                        <li>disable most handling for instant apps in the package manager as attack surface reduction</li>
                        <li>disable out-of-band APEX updates as attack surface reduction</li>
                        <li>only allow first party app source and shell to update system packages</li>
                        <li>improve robustness of original-package handling</li>
                        <li>Settings: hide GNSS SUPL and PSDS settings on devices without GNSS hardware</li>
                        <li>fix regression from our Android 14 QPR2 port causing Storage/Contact Scopes link to disappear after going back to the permissions screen</li>
                        <li>improve setup wizard theme to more closely match the stock Pixel OS configuration</li>
                        <li>backport mainline APEX module patches for Android Health, Media Provider, Network Stack, and Wi-Fi</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision including update to 5.10.212</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.150</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.80</li>
                        <li>Log Viewer: use human readable UTC time for logcat timestamps</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-105">version 105</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-106">version 106</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-107">version 107</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-108">version 108</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-109">version 109</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/124.0.6367.82.0">version 124.0.6367.82.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/124.0.6367.82.1">version 124.0.6367.82.1</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/124.0.6367.82.2">version 124.0.6367.82.2</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/124.0.6367.113.0">version 124.0.6367.113.0</a></li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/23">version 23</a></li>
                        <li>work around our app repository client taking ownership of updates for the debug toggle we use to test new Android Auto releases</li>
                        <li>fix debug build option for testing same versionCode package updates</li>
                    </ul>
                </article>

                <article id="2024042200">
                    <h3><a href="#2024042200">2024042200</a></h3>

                    <p>This release is only being done for the Pixel 8 and Pixel 8 Pro due to lack
                    of changes relevant to other devices.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024042200">2024042200</a> (Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024042100 release:</p>

                    <ul>
                        <li>kernel (5.15): revert another broken f2fs change from the 5.15.149 release (entirely separate from what was fixed in our last release)</li>
                    </ul>
                </article>

                <article id="2024042100">
                    <h3><a href="#2024042100">2024042100</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024042100-redfin">2024042100-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024042100">2024042100</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024042000 release:</p>

                    <ul>
                        <li>kernel (5.10): update to latest GKI LTS branch revision</li>
                        <li>kernel (5.15): backport upstream f2fs patch for a kernel panic caused by another upstream f2fs patch included in the last GKI LTS update (this fix is not included in any Linux stable release yet but rather only the release candidates for Linux 6.9)</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.78</li>
                    </ul>
                </article>

                <article id="2024042000">
                    <h3><a href="#2024042000">2024042000</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024042000-redfin">2024042000-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024042000">2024042000</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024040900 release:</p>

                    <ul>
                        <li>for devices with hardware memory tagging support, add a toggle in Settings > Security for opting into memory tagging in vendor processes currently excluded from it with the end goal of having it force enabled without a toggle as we do for the rest of the base OS</li>
                        <li>allow eSIM activation app to interact with Google Fi app when installed to fix Google Fi activation</li>
                        <li>use ro.vendor.build.svn system property from adevtool instead of AOSP to make sure it always matches the stock OS</li>
                        <li>Pixel Fold: update to AP1A.240405.002.A2 vendor files</li>
                        <li>Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel 8, Pixel 8 Pro: update to AP1A.240405.002.B1 vendor files</li>
                        <li>Log Viewer: include kernel log buffer in default log output</li>
                        <li>Log Viewer: show "Save" instead of "Copy" button for logs that are over ~50 KB</li>
                        <li>Log Viewer: improve handling of log saving</li>
                        <li>backport mainline APEX module patches for Android Health, ART, DNS Resolver, Media Provider, Network Stack, PermissionController and Wi-Fi</li>
                        <li>TalkBack (screen reader): update base code to 14.1 and massively overhaul our changes to it</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision including update to 5.15.149</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.76</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/123.0.6312.118.0">version 123.0.6312.118.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/124.0.6367.42.0">version 124.0.6367.42.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/124.0.6367.54.0">version 124.0.6367.54.0</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/67">version 67</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/68">version 68</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/79">version 79</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-103">version 103</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-104">version 104</a></li>
                        <li>Setup Wizard: layout and style improvements</li>
                        <li>Setup Wizard: add functionality for testing on debug builds</li>
                    </ul>
                </article>

                <article id="2024040900">
                    <h3><a href="#2024040900">2024040900</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024040900-redfin">2024040900-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024040900">2024040900</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024040300 release:</p>

                    <ul>
                        <li>rebased onto AP1A.240405.002.A1 Android Open Source Project release (includes a launcher taskbar improvement)</li>
                        <li>avoid crashes in Chromium-based web browsers and the WebView in their sandboxed processes caused by an incompatibility between exec-based spawning and the new userfaultfd-based garbage collector enabled by Android 14 QPR2</li>
                        <li>DNS resolver: fix upstream bug resulting in NUL byte being included in the random string for the DNS-over-TLS test query</li>
                        <li>allow privileged installers to use getSharedLibraries(MATCH_ANY_USER) in order to enable Apps to handle an edge case involving shared libraries (Vanadium Trichrome library) updated in other users while avoiding adding the INTERACT_ACROSS_USERS permission used for this purpose by the Play Store</li>
                        <li>kernel (5.10, 6.1): update to latest GKI LTS branch revision</li>
                        <li>kernel (5.10): reapply reverted upstream f2fs and irq changes now that the regressions are resolved</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-102">version 102</a></li>
                        <li>fix our infrastructure for testing our CarrierConfig2 app</li>
                    </ul>
                </article>

                <article id="2024040300">
                    <h3><a href="#2024040300">2024040300</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024040300-redfin">2024040300-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024040300">2024040300</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024040200 release:</p>

                    <ul>
                        <li>full 2024-04-05 security patch level</li>
                        <li>rebased onto AP1A.240405.002 Android Open Source Project release</li>
                        <li>fix upstream OS limitation preventing using emergency dialer from setup wizard in secondary users</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/123.0.6312.99.0">version 123.0.6312.99.0</a></li>
                    </ul>
                </article>

                <article id="2024040200">
                    <h3><a href="#2024040200">2024040200</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024040200-redfin">2024040200-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024040200">2024040200</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024032100 release:</p>

                    <ul>
                        <li>full 2024-04-01 security patch level (early release based on AOSP 14 April security backports since the official April AOSP and stock Pixel OS monthly releases aren't available yet)</li>
                        <li>fix race condition for Wi-Fi and Bluetooth auto-turn-off leading to the first auto-turn-off timer after the first Wi-Fi or Bluetooth state update potentially not being scheduled</li>
                        <li>fix Wi-Fi auto-turn-off no longer handling Wi-Fi state change events not involving a Wi-Fi network</li>
                        <li>DocumentsUI (Files): do not delegate handling of downloaded APKs to DownloadProvider to avoid confusing install permission prompt</li>
                        <li>flash-all: raise minimum fastboot version to 34.0.5</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro): sign vendor modules after building them instead of only signing generic (GKI) modules</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision</li>
                        <li>fix upstream bug breaking pressing power button 5 times to make an emergency call</li>
                        <li>fix upstream bug causing 5 second delay to start the emergency dialer for the first time</li>
                        <li>CarrierConfig2 (app created by GrapheneOS to replace Google CarrierSettings): add stub implementation of VendorConfigProvider</li>
                        <li>Setup Wizard: use new API for emergency calls</li>
                        <li>Setup Wizard: add prompt for unlocked bootloader triggering reboot to fastboot mode to lock</li>
                        <li>Setup Wizard: add prompt for disabling OEM unlocking after the device is locked (will be disabled by default)</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-100">version 100</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-101">version 101</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/123.0.6312.80.0">version 123.0.6312.80.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/123.0.6312.80.1">version 123.0.6312.80.1</a></li>
                    </ul>
                </article>

                <article id="2024032100">
                    <h3><a href="#2024032100">2024032100</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024032100-redfin">2024032100-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024032100">2024032100</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024031400 release:</p>

                    <ul>
                        <li>Bluetooth: revert broken upstream change and changes depending on it to fix Galaxy Watch 6 Classic and likely other devices impacted by the same issue (this was a failure of upstream testing and release engineering for AOSP and doesn't impact the stock Pixel OS because it uses a different APEX module revision branched from an older revision of AOSP but it will impact every other Android-based OS on Android 14 QPR2 since there isn't a Bluetooth mainline module published in the Play Store and AOSP yet)</li>
                        <li>revert disabling hardened_malloc for Broadcom Bluetooth HAL (we've fixed the upstream issue and this wasn't needed)</li>
                        <li>revert allowing users to disable hardened_malloc for Bluetooth system app (we've fixed the upstream issue and this wasn't needed)</li>
                        <li>Android Runtime: disable stripping symbols for libart to restore compatibility with some popular obfuscated Chinese apps using a specific obfuscation SDK depending on private APIs which was broken by Android 14 QPR2 when not using the mainline ART module based on older code like the stock Pixel OS (does not result in any lost storage space, just slightly larger factory images / updates as if we'd bundled another small app)</li>
                        <li>Android Runtime: remove Android's hard-wired <code>speed-profile</code> compilation for launcher apps which was limiting ahead-of-time compilation for user installed launcher apps to the parts of the code included in baseline and/or cloud profiles rather than compiling the whole app via our default <code>speed</code> compilation which we use to replace JIT compilation and JIT profiles guiding background AOT compilation</li>
                        <li>backport 12 upstream fixes from the mainline MediaProvider, Wifi, NetworkStack and HealthFitness APEX modules</li>
                        <li>allow using device controls quick tile when unlocked since it already has a toggle for controlling availability so our new default requirement of the device being unlocked needs to be overridden for it</li>
                        <li>more complete setup design configuration to improve appearance of Setup Wizard, etc.</li>
                        <li>Settings: fix upstream footer formatting issue for App pinning screen</li>
                        <li>update timezone module to Android mainline 341510010 (based on tzdata 2024a)</li>
                        <li>kernel (5.15, 6.1): improve support for hosting servers by enabling SYN cookies as we do for the older kernels</li>
                        <li>kernel (6.1): drop obsolete usage of YAMA which we replaced with our dynamic SELinux flag extension</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-99">version 99</a></li>
                    </ul>
                </article>

                <article id="2024031400">
                    <h3><a href="#2024031400">2024031400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024031400">2024031400</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024031100 release:</p>

                    <ul>
                        <li>allow users to disable GrapheneOS hardened_malloc for the Bluetooth system app via the Settings app to help with debugging upstream bugs (still enabled by default)</li>
                        <li>temporarily disable hardened_malloc for Broadcom Bluetooth HAL as a potential workaround for upstream bugs in Android 14 QPR2 (will be reverted if it doesn't help and reverted after fixes are implemented if it does help)</li>
                        <li>fix upstream bug in Android 14 QPR2 breaking Wi-Fi tethering on fresh installs before Wi-Fi is enabled for the first time, which didn't occur on the stock OS in practice due to it enabling Wi-Fi by default</li>
                        <li>fix upstream system_server crash in Android 14 QPR2 when installing updates to packages with an original-package application id such as Vanadium (was reported by users helping with Vanadium Alpha channel testing and we released Apps version 22 with a workaround avoiding the crash prior to this fix)</li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/22">version 22</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/122.0.6261.119.0">version 122.0.6261.119.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/123.0.6312.40.0">version 123.0.6312.40.0</a></li>
                        <li>drop legacy script/envsetup.sh (see current build instructions)</li>
                    </ul>
                </article>

                <article id="2024031100">
                    <h3><a href="#2024031100">2024031100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024031100">2024031100</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024030900 release:</p>

                    <ul>
                        <li>toggle USB port after device unlock to automatically detect a device plugged in while it was in charging-only mode while locked, etc.</li>
                        <li>Tensor Pixels: change default mode for our USB-C port control feature able to truly disable USB at a hardware level to "Charging-only when locked, except before first unlock" (doesn't apply to connections that were made before locking or first unlock) which can be changed by users in Settings > Security > USB-C port</li>
                        <li>fix Wi-Fi auto-turn-off issues leading to it not triggering in certain cases caused by backwards incompatible changes in Android 14 QPR2</li>
                        <li>Pixel 8, Pixel 8 Pro: fix enabling DisplayPort alternate mode support</li>
                        <li>Pixel 8, Pixel 8 Pro: fully enable PAC and BTI for userspace too, especially since ShadowCallStack is not currently used in userspace and Clang type-based CFI is only used for a large subset of the important userspace code</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-98">version 98</a></li>
                        <li>improve internal infrastructure used by GrapheneOS features</li>
                    </ul>
                </article>

                <article id="2024030900">
                    <h3><a href="#2024030900">2024030900</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024030900">2024030900</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024030800 release:</p>

                    <ul>
                        <li>fix upstream Android 14 QPR2 use-after-free bug impacting Bluetooth LE audio with certain devices (reliably caught by our hardware memory tagging integration on the Pixel 8 and Pixel 8 Pro, but also impacts previous devices which still have the standard hardened_malloc mitigations for use-after-free)</li>
                        <li>Settings: hide placeholder dates for Battery information screen in Settings > About device due to 6th/7th generation Pixel batteries having a placeholder value for the first use date</li>
                    </ul>
                </article>

                <article id="2024030800">
                    <h3><a href="#2024030800">2024030800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024030800">2024030800</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024030700 release:</p>

                    <ul>
                        <li>add back unlocking requirement for the new Internet quick tile in QPR2</li>
                        <li>ThemePicker: restore themed icon and grid settings for QPR2 port</li>
                        <li>DocumentsUI (Files): work around crashes caused by QPR2 R8 changes resulting in code used via reflection being removed</li>
                    </ul>
                </article>

                <article id="2024030700">
                    <h3><a href="#2024030700">2024030700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024030700">2024030700</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024030600 release:</p>

                    <ul>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a: fix USB-C mode control issue introduced by QPR2 port which prevented pushing out the last release</li>
                        <li>Gallery: work around crashes caused by QPR2 R8 changes resulting in code used via reflection being removed</li>
                        <li>Settings: enable Battery information screen in Settings > About device for QPR2 including Manufacture date, Date of first use and Cycle count</li>
                        <li>Settings: make the style for settings consistent between Compose and non-Compose settings</li>
                        <li>fixes for certain GrapheneOS notifications in QPR2</li>
                    </ul>
                </article>

                <article id="2024030600">
                    <h3><a href="#2024030600">2024030600</a></h3>

                    <p>This is the first release of GrapheneOS based on Android 14 QPR2. Android 14
                    QPR2 is the first Android release following the new development model where
                    quarterly releases follow the development branch. This release is a massive
                    overhaul of the OS almost as large as the migration from Android 13 QPR3 to
                    Android 14 despite fewer user facing changes. This release includes a large part
                    of the migration to Android 15. The new development model will be very
                    beneficial for GrapheneOS by spreading out the porting process throughout the
                    year between major releases as part of the 3 quarterly releases between the
                    yearly major releases.</p>

                    <p>Since this is a major release, the Pixel 4a (5G) and Pixel 5 have not been
                    ported to Android 14 QPR2 as part our initial release. We need to determine
                    whether it makes sense to move these end-of-life devices to Android 14 QPR2 or
                    keep them on a legacy extended support release branch based on the last Android
                    14 QPR1 release.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024030600">2024030600</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024030300 release:</p>

                    <ul>
                        <li>full 2024-03-05 security patch level</li>
                        <li>rebased onto AP1A.240305.019.A1 Android Open Source Project release, which is the 2nd quarterly maintenance/feature release for Android 14 (QPR2)</li>
                        <li>continue to allow disabling cell broadcast extreme alerts with all carriers contrary to QPR2 change</li>
                        <li>Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a: add back launcher app pinning to potentially work around launcher bugs</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/122.0.6261.105.0">version 122.0.6261.105.0</a></li>
                        <li>Pixel 6 Pro: remove unnecessary product name, model and brand overrides for attestation since we use the official ones</li>
                        <li>System Updater: fix typo in error message</li>
                        <li>System Updater: update summary for check for updates button now that it always checks immediately</li>
                    </ul>
                </article>

                <article id="2024030300">
                    <h3><a href="#2024030300">2024030300</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024030300-redfin">2024030300-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024030300">2024030300</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024022800 release:</p>

                    <ul>
                        <li>System Updater: ignore configured constraints for user-initiated update checks</li>
                        <li>System Updater: avoid automatic retry for user-initiated update checks</li>
                        <li>Settings: migrate to new Compose-based Settings infrastructure in preparation for Android 14 QPR2</li>
                        <li>improve GrapheneOS infrastructure for per-app notifications</li>
                        <li>Setup Wizard: improve wording for secondary user setup word</li>
                        <li>adevtool: fix overlay parsing issues</li>
                        <li>adevtool: include missing "Learn more" fingerprint setup text</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-97">version 97</a></li>
                    </ul>
                </article>

                <article id="2024022800">
                    <h3><a href="#2024022800">2024022800</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024022800-redfin">2024022800-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024022800">2024022800</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024022600 release:</p>

                    <ul>
                        <li>Tensor Pixels: fix issue with the USB-C changes breaking recovery sideloading and the fastbootd flashing mode used by the web installer which blocked us being able to release the previous release to all users</li>
                        <li>Settings: change "Charging only" to "Charging-only" for the USB-C port mode options to make the meaning clearer</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/122.0.6261.90.0">version 122.0.6261.90.0</a></li>
                    </ul>
                </article>

                <article id="2024022600">
                    <h3><a href="#2024022600">2024022600</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024022600-redfin">2024022600-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024022600">2024022600</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024022300 release:</p>

                    <ul>
                        <li>Tensor Pixels: add new USB-C port mode setting to Settings > Security providing a high level of control over USB functionality with hardware-specific integration for disabling USB controller functionality including fully disabling the data lines. There are 5 modes: On (current default during testing), Charging-only when locked except before first unlock (likely near future default), Charging-only when locked, Charging-only and Off (which even disables charging while booted into the normal OS mode). The modes tied to lock state permit already connected devices to continue working after locking and disable the data lines at a USB controller level after disconnecting. This is much different from the existing USB features including the Android 12 USB HAL toggle which only disable high-level kernel functionality and leave all the low-level kernel driver, USB protocol and USB controller attack surface enabled.</li>
                        <li>kernel (5.10, 5.15): add support for ignoring USB alt modes</li>
                        <li>kernel (Tensor Pixels): extend max77759 USB-C controller driver used by Tensor Pixels with support for a sysfs node providing fine-grained control over the USB-C data path at the USB controller level</li>
                        <li>Setup Wizard: fix crash for SIM locales not recognized by com.android.internal.app.LocalePicker</li>
                    </ul>
                </article>

                <article id="2024022300">
                    <h3><a href="#2024022300">2024022300</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024022300-redfin">2024022300-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024022300">2024022300</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024020500 release:</p>

                    <ul>
                        <li>completely new GrapheneOS Setup Wizard implementation for the initial setup of the device and secondary user profiles</li>
                        <li>Theme Picker: update color schemes including adding the monochromatic colorscheme option</li>
                        <li>Sandboxed Google Play compatibility layer: always apply PhenotypeFlag overrides to avoid regressions for some users</li>
                        <li>Sandboxed Google Play compatibility layer: catch SecurityException from setApplicationEnabledSetting() instead of relying on PhenotypeFlag override</li>
                        <li>Sandboxed Google Play compatibility layer: add support for Android Auto 11.3 by extending the wireless Android Auto and phone call handling toggles to also allow BluetoothAdapter#getActiveDevices</li>
                        <li>Sandboxed Google Play compatibility layer: add developer functionality for updating Android Auto via the Play Store for testing</li>
                        <li>Storage Scopes: avoid legacy apps using legacy storage crashing when trying to access the wallpaper</li>
                        <li>remove legacy AOSP Search app now that Vanadium provides the global search intent in addition to the more common web search intent also implemented by other browsers including Brave</li>
                        <li>fix upstream bug breaking package manager support for uninstalling apps only installed in other profiles from the Owner user</li>
                        <li>Settings: improve strings for network connection toggles</li>
                        <li>kernel (5.10, 5.15, 6.1): temporarily ignore sysrq_always_enabled to avoid sysrq being enabled on devices passing it on the kernel line unconditionally</li>
                        <li>kernel (5.10): update to latest GKI LTS branch revision</li>
                        <li>kernel (5.15): update to latest GKI LTS branch revision</li>
                        <li>kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.75</li>
                        <li>Pixel 4a (5G), Pixel 5: update to UP1A.231105.001.B2 vendor files</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/121.0.6167.164.0">version 121.0.6167.164.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/121.0.6167.178.0">version 121.0.6167.178.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/122.0.6261.43.0">version 122.0.6261.43.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/122.0.6261.43.1">version 122.0.6261.43.1</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/122.0.6261.64.0">version 122.0.6261.64.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-94">version 94</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-95">version 95</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-96">version 96</a></li>
                        <li>only use build number for build display id to simplify the value shown at Settings > About device > Build number</li>
                    </ul>
                </article>

                <article id="2024020500">
                    <h3><a href="#2024020500">2024020500</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024020500-redfin">2024020500-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024020500">2024020500</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024012600 release:</p>

                    <ul>
                        <li>full 2024-02-01 security patch level</li>
                        <li>full 2024-02-05 security patch level</li>
                        <li>rebased onto UQ1A.240205.004 Android Open Source Project release</li>
                        <li>run full compacting garbage collection purging all regular Java heaps of dead objects in SystemUI and system_server after locking (this is already done after unlocking to purge data tied to the lock method and derived data, but it makes sense to do it after locking too)</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5, Pixel 5a): update to latest Android 14 QPR2 Beta release including additional security fixes</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.209</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.148</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Generic 5.15, Generic 6.1): enable both software Shadow Call Stack (SCS) and Pointer Authentication Code (PAC) protection for kernel return addresses instead of only using SCS when PAC is unavailable</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Generic 5.15, Generic 6.1): enable Branch Target Identification (BTI) protection for the kernel in addition to Clang type-based CFI to provide coarse-grained CFI coverage for indirect calls excluded from type-based CFI</li>
                        <li>kernel (Generic 6.1): apply sysrq hardening changes</li>
                        <li>kernel (Generic 6.1): update to latest GKI LTS branch revision including update to 6.1.74</li>
                        <li>Settings: enable SIM deletion confirmation by default</li>
                        <li>System Updater: clarify name of the notification channel for already being up to date</li>
                        <li>Messaging: update MMS configuration database based on Google Messages 20240123_01_RC02</li>
                        <li>Dialer: update visual voicemail (VVM) configuration database based on Google Phone 121.0.603393336</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/121.0.6167.101.2">version 121.0.6167.101.2</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/121.0.6167.101.3">version 121.0.6167.101.3</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/121.0.6167.143.0">version 121.0.6167.143.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/121.0.6167.143.1">version 121.0.6167.143.1</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/65">version 65</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/66">version 66</a></li>
                    </ul>
                </article>

                <article id="2024012600">
                    <h3><a href="#2024012600">2024012600</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024012600-redfin">2024012600-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024012600">2024012600</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024011600 release:</p>

                    <ul>
                        <li>isolate eSIM activation app from non-system apps to avoid it sharing data with sandboxed Google Play</li>
                        <li>make eSIM activation toggle available without sandboxed Google Play installed (eSIM management no longer requires sandboxed Google Play)</li>
                        <li>make the eSIM activation app toggle persistent instead of it being disabled at boot</li>
                        <li>remove misleading message about device info being sent to Google message before eSIM download</li>
                        <li>hardened_malloc: use tag 0 for freed slots instead of reserving a tag to allow using 15 of 16 possible tag values for random tags (there are 3 dynamic exclusions of the random values for the previous tag along with the 2 current or previous adjacent tags)</li>
                        <li>Settings: prevent disabling Camera2/CameraX extension provider app (Pixel Camera Services for Pixels) since it breaks apps using CameraX</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro): use a normal reboot on overheating instead of an emergency reboot to harden against physical attacks</li>
                        <li>kernel: enable reset attack mitigation for UEFI systems supporting it (Tensor Pixels use minimalistic littlekernel-based boot firmware rather than UEFI and the previous Snapdragon Pixels using UEFI didn't implement this but we may need this for future devices)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.208</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.147</li>
                        <li>kernel (Generic 6.1): update to latest GKI LTS branch revision including update to 6.1.73</li>
                        <li>Launcher: disable gradient at the top of the home screen again (change lost with Android 14 QPR1 due to it being reimplemented upstream)</li>
                        <li>rewrite HTTPS network time implementation to make it much more maintainable and robust along with providing better debug output via ADB</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/120.0.6099.230.0">version 120.0.6099.230.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/121.0.6167.71.0">version 121.0.6167.71.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/121.0.6167.101.0">version 121.0.6167.101.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/121.0.6167.101.1">version 121.0.6167.101.1</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-93">version 93</a></li>
                        <li>Seedvault: update to latest revision (will be replaced with a better backup implementation in the future)</li>
                    </ul>
                </article>

                <article id="2024011600">
                    <h3><a href="#2024011600">2024011600</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024011600-redfin">2024011600-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024011600">2024011600</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024011300 release:</p>

                    <ul>
                        <li>work around upstream Android bug causing system_server crash due to failed security-related assertion by denying the action without crashing system_server, which avoids turning a buggy security check into a denial of service issue</li>
                        <li>add workaround for upstream Android crash reporting bug recording clean f2fs filesystem check results as errors which is resulting in many users receiving filesystem check error reports on GrapheneOS due to our user-facing notifications for serious errors/crashes</li>
                        <li>add workaround for upstream Android crash reporting bug causing old crashes to be reported again</li>
                        <li>add workaround for upstream Android crash reporting bug wrongly attributing certain app crashes to system_server</li>
                        <li>only show kernel crashes when the user opts into showing all system crashes as notifications since there are many false positives caused by hardware issues such as some users having devices which sometimes fail to resume from sleep while idle</li>
                        <li>only show report button in log viewer for system_server Java/native crashes, MTE crashes and filesystem check errors (which now have non-error results properly filtered out) due to receiving too many reports about upstream bugs and hardware issues</li>
                        <li>hide specific system apps and also sandboxed Google Play from Aurora Store so users don't try to update them through it and receive errors</li>
                        <li>Log Viewer: explicitly set status bar color to fix light mode icon colors</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5, Pixel 5a): add missing kernel changes from the past 2 releases</li>
                    </ul>
                </article>

                <article id="2024011300">
                    <h3><a href="#2024011300">2024011300</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024011300-redfin">2024011300-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024011300">2024011300</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2024010400 release:</p>

                    <ul>
                        <li>replace auto-reboot implementation with a new more hardened implementation based on a timer in the init process (since init crashing reboots the device, unlike system_server) which also avoids rebooting when the device hasn't been unlocked since boot</li>
                        <li>reduce default auto-reboot timer from 72 hours to 18 hours</li>
                        <li>add log viewer available at <b>Settings&#160;<span aria-label="and then">></span> System&#160;<span aria-label="and then">></span> View logs</b> to avoid needing developer options for making useful bug reports and inspecting the device for issues</li>
                        <li>reimplement our user-facing crash reporting infrastructure with our new log viewer app</li>
                        <li>Settings: add links to log viewer in app info and system settings</li>
                        <li>show report button in sandboxed Google Play crash report UI</li>
                        <li>adevtool: integrate support for Pixel Camera Services (currently provides Night mode for GrapheneOS Camera and other apps on Pixel 6 and later)</li>
                        <li>adevtool: improve and clean up infrastructure for device support</li>
                        <li>adevtool: drop devices not supported with Android 14</li>
                        <li>adevtool: remove unused default permissions configuration</li>
                        <li>Contact Scopes: add handling of malformed contact data subtype names to avoid crash</li>
                        <li>show notification after hardened_malloc detects memory corruption via a direct check (does not cover memory corruption detected via memory protected address space)</li>
                        <li>kernel: disable sysrq by default rather than waiting for init to disable it</li>
                        <li>kernel: disable unused sysrq serial support</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.206</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.145</li>
                        <li>kernel (Generic 6.1): update to latest GKI LTS branch revision including update to 6.1.69</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-91">version 91</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-92">version 92</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/120.0.6099.210.0">version 120.0.6099.210.0</a></li>
                        <li>System Updater: use sentence case for notification channel names</li>
                    </ul>
                </article>

                <article id="2024010400">
                    <h3><a href="#2024010400">2024010400</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024010400-redfin">2024010400-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2024010400">2024010400</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023123100 release:</p>

                    <ul>
                        <li>full 2024-01-01 security patch level</li>
                        <li>full 2024-01-05 security patch level</li>
                        <li>rebased onto UQ1A.240105.004 Android Open Source Project release</li>
                        <li>kernel (Generic 6.1): update to latest GKI LTS branch revision including update to 6.1.67</li>
                        <li>Sandboxed Google Play compatibility layer: stop hiding Android Auto from the Play Store since it breaks Play Store dependent functionality</li>
                        <li>Sandboxed Google Play compatibility layer: mark Android Auto as owned by our app repository client to stop the Play Store from updating it</li>
                        <li>Sandboxed Google Play compatibility layer: add Network permission to baseline permissions needed for wireless Android Auto</li>
                        <li>Sandboxed Google Play compatibility layer: add list of requirements for Android Auto voice commands</li>
                        <li>Sandboxed Google Play compatibility layer: add back dedicated name for Sandboxed Google Play crash notification channel</li>
                        <li>Sandboxed Google Play compatibility layer: skip Android Auto crash reports when it lacks baseline permissions and show a dedicated notification about the problem instead</li>
                        <li>Keyboard: add workaround for multi-locale spell checking and remove our attempt at implementing it properly in the keyboard itself for now</li>
                        <li>AppCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_AppCompatConfig/releases/tag/3">version 3</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/120.0.6099.193.0">version 120.0.6099.193.0</a></li>
                        <li>adevtool: remove unused permission configuration</li>
                    </ul>
                </article>

                <article id="2023123100">
                    <h3><a href="#2023123100">2023123100</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023123100-redfin">2023123100-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023123100">2023123100</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023123000 release:</p>

                    <ul>
                        <li>Keyboard: avoid spell checker crash after keyboard's spell checking service is stopped by the OS (regression in the last Alpha channel only release fixing multi-locale spell checking)</li>
                        <li>backport upstream fix for Wi-Fi background scan system_server crash</li>
                        <li>hardened_malloc / bionic: restore default SIGABRT handler in fatal_error to work around crashlytics bug caused by it using fork instead of clone which triggers a deadlock when malloc locks are held already</li>
                        <li>skip missing sensors permission notification with wrong app id</li>
                        <li>Sandboxed Google Play compatibility layer: avoid crashes in Android Auto and potentially elsewhere from missing Google Search app to make it a proper optional dependency</li>
                        <li>Sandboxed Google Play compatibility layer: fix handling of while-in-use permissions</li>
                        <li>Sandboxed Google Play compatibility layer: drop ACCESS_BACKGROUND_LOCATION permission for Android Auto now that while-in-use permission works</li>
                        <li>Sandboxed Google Play compatibility layer: add workaround for rare foreground service crash (may be upstream bug)</li>
                    </ul>
                </article>

                <article id="2023123000">
                    <h3><a href="#2023123000">2023123000</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023123000-redfin">2023123000-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023123000">2023123000</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023121200 release:</p>

                    <ul>
                        <li>Keyboard: add new implementation of multi-locale spell checking support to fix crashes and other issues</li>
                        <li>Sandboxed Google Play compatibility layer: add Android Auto support with the compatibility layer eliminating the need for most of the permissions and a permission menu with 4 toggles for granting the minimal special access required for wired Android Auto, wireless Android Auto, audio routing and phone calls</li>
                        <li>Settings: remove confusing mention of Android Auto from Connected devices screen</li>
                        <li>exempt non-app system processes from Sensors permission enforcement (fixes some issues including gpsd crashes)</li>
                        <li>fix Bluetooth auto-turn-off race condition to avoid crashes</li>
                        <li>work around upstream race condition bug in biometric service</li>
                        <li>disable support for pre-approving PackageInstaller sessions due to incompatibility with Network permission toggle</li>
                        <li>fix several upstream bugs in handling crash reports mainly to improve our user-facing crash reporting system</li>
                        <li>use GrapheneOS Widevine provisioning proxy by default</li>
                        <li>add settings for changing Widevine provisioning server</li>
                        <li>add configuration for setupdesign and setupcompat libraries to improve system UI theme</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.204</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.142</li>
                        <li>kernel (Generic 6.1): initial port of GrapheneOS changes for use with emulator builds</li>
                        <li>force disable network ADB (Android Debug Bridge) developer option in early boot to improve verified boot security (no user-facing change since it's currently disabled by default later in the boot process, but not robustly)</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/120.0.6099.115.0">version 120.0.6099.115.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/120.0.6099.144.0">version 120.0.6099.144.0</a></li>
                        <li>AppCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_AppCompatConfig/releases/tag/2">version 2</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-88">version 88</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-89">version 89</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-90">version 90</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/78">version 78</a></li>
                    </ul>
                </article>

                <article id="2023121200">
                    <h3><a href="#2023121200">2023121200</a></h3>

                    <p>Pixel 4a (5G) and Pixel 5 are end-of-life and shouldn't be used anymore due
                    to lack of security patches for firmware and drivers. We provide extended
                    support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023121200-redfin">2023121200-redfin</a> (Pixel 4a (5G), Pixel 5)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023121200">2023121200</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023120800 release:</p>

                    <ul>
                        <li>stop reporting forced reboot (long press power) as a kernel crash</li>
                        <li>filter out SoC ID from kernel crash logs (logged by Little Kernel firmware boot stage before the OS)</li>
                        <li>temporarily disable memory tagging and hardened_malloc for surfaceflinger process to work around upstream use-after-free bug(s)</li>
                        <li>raise max open files for system_server to 256k from the baseline 32k limit used for all processes on Android due to situations where the 32k limit is exhausted, which has become much more common for a small number of users with Android 14 QPR1</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold): backport fix for glibc 2.38 build error to device-specific driver source tree too to end the need for mounting a modified features.h for building host executables</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.201</li>
                        <li>kernel (Pixel 8, Pixel 8 Pro, Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.138</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-87">version 87</a></li>
                        <li>suppress repetitive sendHistogramChannelIoctl logging (upstream issue)</li>
                    </ul>
                </article>

                <article id="2023120800">
                    <h3><a href="#2023120800">2023120800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023120800">2023120800</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023120701 release:</p>

                    <ul>
                        <li>Package Installer: fix crash introduced upstream in Android 14 QPR1 for handling pending user action</li>
                        <li>Package Installer: fix crash introduced upstream in Android 14 QPR1 by limiting maximum app snippet icon size</li>
                        <li>avoid false positives for our kernel crash reporting when running in the Android emulator</li>
                    </ul>
                </article>

                <article id="2023120701">
                    <h3><a href="#2023120701">2023120701</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023120701">2023120701</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023120700 release:</p>

                    <ul>
                        <li>adevtool (Pixel 8, Pixel 8 Pro): update system property removal</li>
                    </ul>
                </article>

                <article id="2023120700">
                    <h3><a href="#2023120700">2023120700</a></h3>

                    <p>This is the first quarterly release of Android 14 and includes a bunch of
                    nice improvements including using the phone as a webcam.</p>

                    <p>Starting with this release, the Pixel 4a (5G) and Pixel 5 are end-of-life
                    and shouldn't be used anymore due to lack of security patches for firmware and
                    drivers. Certain driver patches will remain available until the Pixel 5a is
                    end-of-life due to shared code. We'll continue providing all of the Android
                    Open Source Project and GrapheneOS changes for them until the release of
                    Android 15. After Android 15 is released, they'll remain on a legacy Android
                    14 branch with only the AOSP security patch backports to Android 14 and some
                    additional changes backported by us on a best effort basis. This is the same
                    kind of extended support we provided for the Pixel 4 and Pixel 4 XL.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023120700">2023120700</a> (Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023120400 release:</p>

                    <ul>
                        <li>full 2023-12-01 security patch level for 6th/7th generation Pixels too</li>
                        <li>full 2023-12-05 security patch level</li>
                        <li>rebased onto UQ1A.231205.015 Android Open Source Project release, which is the first quarterly maintenance/feature release for Android 14</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision</li>
                        <li>Sandboxed Google Play compatibility layer: disable privileged AlarmManager.FLAG_PRIORITIZE to prevent crashes (this API is a no-op when Unrestricted battery mode is granted anyway)</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-86">version 86</a></li>
                    </ul>
                </article>

                <article id="2023120400">
                    <h3><a href="#2023120400">2023120400</a></h3>

                    <p>The December release of the Android Open Source Project and stock Pixel OS
                    will be the first quarterly release of Android 14. It will likely be available
                    this week, but hasn't been published yet. Since there hasn't been a release
                    yet this month, we're publishing an early December security update based on
                    the AOSP backports to Android 14.</p>

                    <p>It's unclear if 6th/7th generation Pixels received a specific Mali GPU
                    kernel driver patch so we aren't raising the patch level for these until the
                    official December release is available. We often backport these patches early
                    but we don't know which patch corresponds to which CVE ID so we can't raise
                    the claimed patch level. ARM covers up the details publicly and only releases
                    tarballs for each major revision without the Git commit history or individual
                    security patch backports they make available to partners, despite partners
                    being allowed to apply those in public Git repositories. We can often figure
                    out the patch corresponding to a CVE ID or vice versa through ARM partners
                    publishing it, but we haven't been able to in this case.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023120400">2023120400</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023120400-shusky">2023120400-shusky</a> (Pixel 8, Pixel 8 Pro)</li>
                    </ul>

                    <p>Changes since the 2023112900 release:</p>

                    <ul>
                        <li>full 2023-12-01 security patch level (6th/7th generation Pixels may be missing a 2023-11-05 Mali GPU patch so we've frozen the patch level string until the official December update)</li>
                        <li>Pixel 8, Pixel 8 Pro: use more modern target CPU configuration</li>
                        <li>System Updater: enable non-low (currently 20% or higher) battery requirement for the update job by default (will not change for users who have previously opened the update settings due to how they're implemented)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/120.0.6099.43.0">version 120.0.6099.43.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-85">version 85</a></li>
                    </ul>
                </article>

                <article id="2023112900">
                    <h3><a href="#2023112900">2023112900</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023112900">2023112900</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023112900-shusky">2023112900-shusky</a> (Pixel 8, Pixel 8 Pro)</li>
                    </ul>

                    <p>Changes since the 2023112600 release:</p>

                    <ul>
                        <li>improve compatibility of the opt-in forced hardware memory tagging mode for user installed apps</li>
                        <li>add AppCompatConfig for out-of-band updates to app compatibility configuration such as enabling memory tagging by default for apps compatible with it in the default mode and disabling it for apps not compatible with it when users globally enable it</li>
                        <li>suppress native debugging notification for sandboxed Google Play services since it works without it</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.200</li>
                        <li>Settings: hide global memory tagging setting from secondary users</li>
                        <li>Settings: add toggle for system process crash notifications and disable it by default since it uncovers a lot of upstream bugs</li>
                        <li>Settings: clarify description for third party app memory tagging toggle in the Security settings menu</li>
                        <li>Settings: fix typo in the extended virtual address space explanation</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/119.0.6045.193.0">version 119.0.6045.193.0</a></li>
                    </ul>
                </article>

                <article id="2023112600">
                    <h3><a href="#2023112600">2023112600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023112600">2023112600</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023112600-shusky">2023112600-shusky</a> (Pixel 8, Pixel 8 Pro)</li>
                    </ul>

                    <p>Changes since the 2023111500 release:</p>

                    <ul>
                        <li>improve existing infrastructure and settings for per-app hardening control</li>
                        <li>add new infrastructure for dynamic SELinux flags for apps</li>
                        <li>replace static SELinux policy disabling dynamic native code generation for base system apps with dynamic SELinux flag</li>
                        <li>replace YAMA LSM with dynamic SELinux flag for ptrace access</li>
                        <li>add per-app toggle for native debugging</li>
                        <li>add global toggle to disable native debugging for user installed apps by default</li>
                        <li>add per-app memory tagging toggle for user installed apps</li>
                        <li>add global toggle to enable memory tagging for user installed apps by default</li>
                        <li>add logging infrastructure for dynamic GrapheneOS SELinux flags</li>
                        <li>raise post-boot audit message rate limit from 5 to 50 per second</li>
                        <li>add more infrastructure and tests for per-app hardening control</li>
                        <li>fix Android bug with rate limiting for non-app tombstones (crash info for reporting bugs)</li>
                        <li>notify the user about notable system journal entries including kernel crash, file system check error, system_server crash, system app native crash and non-app process native crash</li>
                        <li>notify the user after memory tagging detects memory corruption in an app</li>
                        <li>notify the user after an app is blocked from accessing ptrace by the native debugging toggle</li>
                        <li>Pixel 8, Pixel 8 Pro: migrate to using our standard 5.15.137 GKI LTS kernel as the base with reverts for changes that are not compatible with the driver tree yet</li>
                        <li>include more info about Java and native crashes, ANRs, low memory conditions. kernel crash logs and filesystem check errors in bug report zips manually captured by users which on the stock OS is uploaded by Play services</li>
                        <li>Sandboxed Google Play compatibility layer: allow compatibility layer to show the error report UI</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-84">version 84</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/119.0.6045.163.2">version 119.0.6045.163.2</a></li>
                    </ul>
                </article>

                <article id="2023111500">
                    <h3><a href="#2023111500">2023111500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023111500">2023111500</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023111500-shusky">2023111500-shusky</a> (Pixel 8, Pixel 8 Pro)</li>
                    </ul>

                    <p>Changes since the 2023110700 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: replace cross-user intent broadcasts with user-local ones to avoid occasional background service crashes</li>
                        <li>fix upstream bug causing crash for previewing live wallpapers</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision</li>
                        <li>Seedvault: update to latest revision (will be replaced with a better backup implementation in the future)</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/119.0.6045.134.0">version 119.0.6045.134.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/119.0.6045.163.0">version 119.0.6045.163.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/119.0.6045.163.1">version 119.0.6045.163.1</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-83">version 83</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/64">version 64</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/77">version 77</a></li>
                    </ul>
                </article>

                <article id="2023110700">
                    <h3><a href="#2023110700">2023110700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023110700">2023110700</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023110700-shusky">2023110700-shusky</a> (Pixel 8, Pixel 8 Pro)</li>
                    </ul>

                    <p>Changes since the 2023103100 release:</p>

                    <ul>
                        <li>full 2023-11-01 security patch level</li>
                        <li>full 2023-11-05 security patch level for generic targets and 5th/8th generation Pixels (6th/7th generation Pixels are marked as 2023-11-01 upstream which may be due to a missing Mali GPU kernel patch we can work on obtaining to apply early)</li>
                        <li>rebased onto UP1A.231105.003 (generic) and UD1A.231105.004 (shusky) Android Open Source Project releases</li>
                        <li>Pixel 8, Pixel 8 Pro: always enable hardware memory tagging (there is no longer an opt-in toggle) which is currently used everywhere other than Vanadium (coming soon), vendor executables and user installed apps with their own native code not marked as compatible with memory tagging</li>
                        <li>disable GWP-ASan since it's a bug finding feature rather than a hardening feature and doesn't preserve all the hardened_malloc security properties for the random allocations in random system processes where it gets activated especially now that memory tagging is supported</li>
                        <li>Launcher: add missing catch for null pointer exception (upstream bug) triggered by Signal</li>
                        <li>revert change to show crash dialog for first crash of an app since boot since this results in a high support burden from the many third party app crashes it uncovers especially since it's not enabled on the stock OS</li>
                        <li>always compile VPN service packages with speed filter to avoid background recompilation since many of these apps only automatically connect at boot and the user has to manually reconnect if the OS restarts them such as when users manually trigger app restart via the background recompilation notification</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.199</li>
                        <li>backport health permission UI fixes from AOSP</li>
                        <li>backport DocumentsUI (Files) fix from AOSP preventing bypassing restrictions via initial open directory</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-81">version 81</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-82">version 82</a></li>
                        <li>use sdk_phone_x86_64 (emulator) target as the default one for convenience</li>
                        <li>flash-all: raise minimum fastboot version to 34.0.4</li>
                    </ul>
                </article>

                <article id="2023103100">
                    <h3><a href="#2023103100">2023103100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023103100">2023103100</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023103100-shusky">2023103100-shusky</a> (Pixel 8, Pixel 8 Pro)</li>
                    </ul>

                    <p>Changes since the 2023103000 release:</p>

                    <ul>
                        <li>Keyboard: include words from all active locales in spell checking to support multiple locales again after the port to Android 14</li>
                        <li>Gallery: revert one of the 3 improvements to preview resolution due to it causing out-of-memory errors</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/119.0.6045.66.0">version 119.0.6045.66.0</a></li>
                    </ul>
                </article>

                <article id="2023103000">
                    <h3><a href="#2023103000">2023103000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023103000">2023103000</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023103000-shusky">2023103000-shusky</a> (Pixel 8, Pixel 8 Pro)</li>
                    </ul>

                    <p>Changes since the 2023102300 release:</p>

                    <ul>
                        <li>add infrastructure for hardware memory tagging support</li>
                        <li>hardened_malloc: add support for hardware memory tagging launched with the ARMv9 cores on the Pixel 8 and Pixel 8 Pro</li>
                        <li>Settings: enable memory tagging toggle at <b>Settings&#160;<span aria-label="and then">></span> Security&#160;<span aria-label="and then">></span> More security settings&#160;<span aria-label="and then">></span> Advanced memory protection</b> beta on supported devices (Pixel 8 and Pixel 8 Pro)</li>
                        <li>Pixel 8, Pixel 8 Pro: enable memory tagging support for everything built by GrapheneOS (other than Vanadium, since Chromium currently disables it) and also user installed apps without native libraries (will be expanded to Vanadium later along with the option to use it for all user installed apps)</li>
                        <li>Pixel 8, Pixel 8 Pro: use asymmetric memory tagging mode on all cores to provide much higher security than asynchronous mode without much more overhead unlike the very expensive synchronous mode without any clear security benefits over asymmetric</li>
                        <li>enable parallel compilation of non-precompiled bytecode to native code for first-boot and first-boot-after-update with 2 processes for now (can be increased later)</li>
                        <li>improve user interface for reporting background package compilation progress</li>
                        <li>show crash dialog for first crash of an app since boot instead of waiting until the second crash like upstream Android</li>
                        <li>Gallery: fix low resolution image preview in editor</li>
                        <li>restore Android 13 behavior for installing APKs from the file manager by requesting permission for the app which created the APK (current Google Files behavior is a bit different and requests permission for Google Files, but the AOSP Files approach seems more useful)</li>
                        <li>SELinux policy: use per-app-instance MLS level for the update client domain as used for regular apps to provide better isolation from other system components</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.198</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.137</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/118.0.5993.111.0">version 118.0.5993.111.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/119.0.6045.53.0">version 119.0.6045.53.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/119.0.6045.53.1">version 119.0.6045.53.1</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-80">version 80</a></li>
                    </ul>
                </article>

                <article id="2023102300">
                    <h3><a href="#2023102300">2023102300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023102300">2023102300</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023102300-shusky">2023102300-shusky</a> (Pixel 8, Pixel 8 Pro)</li>
                    </ul>

                    <p>Changes since the 2023101300 release:</p>

                    <ul>
                        <li>initial non-experimental release for Pixel 8 and Pixel 8 Pro support</li>
                        <li>speed up skipping compilation of system packages with dexpreopt (precompilation to native code) to improve post-update boot time</li>
                        <li>backport assorted dexpreopt fixes to make it work for more system packages again to improve verified boot security, free up wasted disk space and reduce post-update boot time</li>
                        <li>use speed-profile compilation for user installed packages for first boot of an update to significantly improve boot time, then recompile with full speed optimization in the background with a progress notification and a notification when it's finished for respawning apps</li>
                        <li>temporarily disable otapreopt (precompilation of apps in the background in update Finalizing step) due to it being broken in Android 14</li>
                        <li>Gallery: remove optional dependency to fix dexpreopt (precompilation to native code)</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold: fix support for Widevine L1 on Android 14</li>
                        <li>fix PIN scrambling for SIM PIN (regression from port to Android 14)</li>
                        <li>handle new Android 14 network time code path for our feature making the automatic time toggle control whether network time connections are made</li>
                        <li>remove standard special case enabling Android 14 auto-confirm PIN by default for 6 digit PINs</li>
                        <li>allow system apps to make sticky notifications again (important for System Updater to avoid users missing the notice to reboot after update installation)</li>
                        <li>System Updater: add option to require that the device is charging</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.134</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/76">version 76</a></li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/21">version 21</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/118.0.5993.80.0">version 118.0.5993.80.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-79">version 79</a></li>
                        <li>improve GrapheneOS system_server infrastructure</li>
                    </ul>
                </article>

                <article id="2023101300">
                    <h3><a href="#2023101300">2023101300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023101300">2023101300</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023101100 release:</p>

                    <ul>
                        <li>exempt non-app system packages from new package visibility restrictions to fix many APIs in secondary users</li>
                        <li>Sandboxed Google Play compatibility layer: expand background activity launch shim to all the core Google Play apps to fix sandboxed Play Store compatibility issues with Android 14</li>
                        <li>Sandboxed Google Play compatibility layer: fix "Don't show again" notification action which broke after Android 14 port</li>
                        <li>Pixel 5: add back support for battery share (reverse wireless charging) via the new infrastructure in Android 14 which we already adopted for 6th/7th/8th generation Pixels</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-78">version 78</a></li>
                        <li>Settings: reorder auto-reboot options from least disruptive to most secure</li>
                        <li>Settings: add 18 hours as an auto-reboot option</li>
                    </ul>
                </article>

                <article id="2023101100">
                    <h3><a href="#2023101100">2023101100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023101100">2023101100</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023100900 release:</p>

                    <ul>
                        <li>enable customizing lock screen shortcuts</li>
                        <li>Launcher: set target API level to 33 since it doesn't properly support 34 and it prevents adding widgets among other potential issues (Pixel Launcher fork in the stock Pixel OS still uses 33 too, so this is an AOSP-specific upstream bug)</li>
                        <li>Launcher: delete broken legacy shortcuts instead of crashing (upstream bug)</li>
                        <li>Sandboxed Google Play compatibility layer: enable DynamiteLoader v2</li>
                        <li>fix per-app hardening configuration for apps missing from the Owner user</li>
                        <li>fix Bluetooth auto-turn-off</li>
                        <li>Settings: avoid crashes when changing user restrictions for guest users (upstream bug)</li>
                        <li>do not delete compiled code of hibernated apps</li>
                        <li>curl: update to 8.4.0 to fix CVE-2023-38545 and assorted minor issues (Android may not use this functionality, but it should be fixed in case it does)</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/118.0.5993.65.0">version 118.0.5993.65.0</a></li>
                        <li>remove unnecessary wrapper for registering receivers</li>
                    </ul>
                </article>

                <article id="2023100900">
                    <h3><a href="#2023100900">2023100900</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023100900">2023100900</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023100800 release:</p>

                    <ul>
                        <li>temporarily unsuspend work profiles when resuming them to avoid our stricter pause approach causing issues</li>
                        <li>Settings: split title/summary for automatic exploit protection compatibility mode</li>
                        <li>Settings: fix upstream bug causing crash when accessing tethering settings from secondary users where they're unavailable</li>
                        <li>System Updater: set foreground service type to special</li>
                        <li>System Updater: update minimum and target API level to 34 (Android 14)</li>
                        <li>fix port of our change enabling usage timeline for all permission groups</li>
                        <li>add back compiling code not built with signed integer overflow checking using -fwrapv to make it well defined</li>
                        <li>add back very minor hardening involving making more data read only</li>
                        <li>Seedvault: update to latest revision (will be replaced with a better backup implementation in the future)</li>
                        <li>Health Fitness: disable functionality for showing available apps, updating apps and sending feedback when Google Play is unavailable (these options may be removed completely in the future)</li>
                        <li>Health Fitness: check for Google Play via signature instead of whether it's a system app to support sandboxed Google Play</li>
                    </ul>
                </article>

                <article id="2023100800">
                    <h3><a href="#2023100800">2023100800</a></h3>

                    <p>This is the initial non-experimental release of GrapheneOS based on Android
                    14. Our initial public experimental release (2023100600) was published on
                    October 6th so there have already been a couple days of public testing. All of
                    our documented features are now ported to Android 14. We'll be continuing to
                    work on fixing regressions including new Android bugs and new compatibility
                    issues caused by our features. However, it's already stable and usable.</p>

                    <p>This release provides the full 2023-10-06 patch level for all supported
                    devices along with the recommended security patches only included in Android
                    14.</p>

                    <p>Android 13 is no longer actively developed upstream and now only receives
                    backports of the Android Security Bulletin patches, not the recommended
                    patches included in the latest stable release of Android. Pixels are also now
                    only supported via Android 14 and require Android 14 to achieve a patch level
                    above 2023-10-01. Android 14 has had publicly available experimental releases
                    since February 2023 and is already a mature OS. It also contains significant
                    privacy and security enhancements which more than offset the attack surface
                    from added features. These reasons are why we have so heavily prioritized
                    porting to Android 14 and began to defer more and more of our other work until
                    after Android 14 since around July 2023.</p>

                    <p>Pixel 4, Pixel 4 XL and Pixel 4a are end-of-life and shouldn't be used
                    anymore due to lack of security patches for firmware and drivers. We provide
                    extended support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023100800">2023100800</a> (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023100300 release:</p>

                    <ul>
                        <li>full 2023-10-06 security patch level</li>
                        <li>rebased onto UP1A.231005.007 Android Open Source Project release as the initial port of all GrapheneOS features to Android 14</li>
                        <li>add default-enabled toggle for automatic per-app exploit protection compatibility mode configuration</li>
                        <li>temporarily add Google Camera to automatic exception list for hardened_malloc</li>
                        <li>add back support for displaying app compilation progress at boot</li>
                        <li>restore Android 13 work profile pause behavior by stopping the profile from running instead of only suspending apps</li>
                        <li>fix cosmetic issue for adevtool envsetup.sh integration</li>
                        <li>adevtool: download: add option to unpack factory images</li>
                        <li>adevtool: collect-state: fix the output file name format</li>
                        <li>adevtool: collect-state: add an option to automatically make prep OS build</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/117.0.5938.153.0">version 117.0.5938.153.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/118.0.5993.48.0">version 118.0.5993.48.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-77">version 77</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/75">version 75</a></li>
                    </ul>
                </article>

                <article id="2023100300">
                    <h3><a href="#2023100300">2023100300</a></h3>

                    <p>Android 14 is replacing Android 13 this month. There will no longer be any
                    monthly or quarterly releases of Android 13, only the monthly backports of
                    Android Security Bulletin patches. This is an early October release based on
                    the Android Security Bulletin backports. We'll need to port to Android 14 to
                    provide the full 2023-10-06 patch level. We've spent months porting to Android
                    14 in advance in order to make this migration as smooth and quick as possible.
                    We weren't accepted as an Android partner so we don't have full early access
                    to new major releases, but we've had partial early access to the sources and
                    were able to do a lot of the porting in advance.</p>

                    <p>There wasn't a proper Android Open Source Project or stock Pixel OS release
                    for September since Android 14 was meant to be released. They only shipped a
                    release marked as having the 2023-09-01 patch level, but most patches which
                    were going to be included in 2023-09-05 were deferred to October and most of
                    the devices ended up providing the published 2023-09-05 patch level. Devices
                    with a Qualcomm SoC (Pixel 4a (5G), Pixel 5, Pixel 5a) or standalone Qualcomm
                    Wi-Fi (Pixel 7a) still need firmware/driver patches for 2023-09-05. Other
                    supported devices (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel
                    Tablet, Pixel Fold) were already on the 2023-09-05 patch level and will now be
                    on the 2023-10-01 patch level. All of these devices will be quickly upgraded
                    to the full Android 14 2023-10-05 patch level once it's released.</p>

                    <p>Pixel 4, Pixel 4 XL and Pixel 4a are end-of-life and shouldn't be used
                    anymore due to lack of security patches for firmware and drivers. We provide
                    extended support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023100300-coral">2023100300-coral</a> (Pixel 4, Pixel 4 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023100300">2023100300</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023100300-tangorpro">2023100300-tangorpro</a> (Pixel Tablet)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023100300-felix">2023100300-felix</a> (Pixel Fold)</li>
                    </ul>

                    <p>Changes since the 2023100100 release:</p>

                    <ul>
                        <li>full 2023-10-01 security patch level (early release based on AOSP 13 security backports since the AOSP/stock monthly release is not available yet)</li>
                    </ul>
                </article>

                <article id="2023100100">
                    <h3><a href="#2023100100">2023100100</a></h3>

                    <p>Pixel 4, Pixel 4 XL and Pixel 4a are end-of-life and shouldn't be used
                    anymore due to lack of security patches for firmware and drivers. We provide
                    extended support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023100100-coral">2023100100-coral</a> (Pixel 4, Pixel 4 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023100100">2023100100</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023100100-tangorpro">2023100100-tangorpro</a> (Pixel Tablet)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023100100-felix">2023100100-felix</a> (Pixel Fold)</li>
                    </ul>

                    <p>Changes since the 2023091800 release:</p>

                    <ul>
                        <li>fix upstream bug auto-dismissing crash dialogs</li>
                        <li>improve readability of native crash reports</li>
                        <li>Settings: remove Private DNS setting for secondary users since it's not currently per-profile like VPN configuration but rather is global like Wi-Fi configuration</li>
                        <li>Settings: remove connectivity check setting for secondary users</li>
                        <li>Dialer: disable false gesture detection for answering calls until the faulty implementation in the AOSP Dialer app is replaced</li>
                        <li>hardened_malloc: improve fatal error reporting to include the abort message in Android crash reports</li>
                        <li>Messaging: work around upstream null pointer exception bug</li>
                        <li>libvpx: apply patch for CVE-2023-5217 to the standalone AOSP libvpx library, which was already fixed in the 117.0.5938.140.0 release of Vanadium</li>
                        <li>Pixel 4, Pixel 4 XL: add upstream sensor-related app compatibility fix from the September release already included for other devices</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold): add upstream build reproducibility fix</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-75">version 75</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-76">version 76</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/117.0.5938.140.0">version 117.0.5938.140.0</a></li>
                        <li>replace GrapheneOS themes stub app with AOSP themes stub app with our configuration ported over to it (AOSP didn't used to include a themes stub app)</li>
                    </ul>
                </article>

                <article id="2023091800">
                    <h3><a href="#2023091800">2023091800</a></h3>

                    <p>The September releases of AOSP and the stock OS came out on 2023-09-18 and
                    are incorporated into this release. Unusually, they still set the patch level
                    to 2023-09-01 despite having all listed patches for 2023-09-05 for some of the
                    devices such as the Pixel 6 and Pixel 7. We left the listed patch level alone
                    to avoid delaying the release for aesthetic reasons while we figured out where
                    it could be raised due to delayed Qualcomm firmware patches. We shipped
                    2023-09-01 in our much earlier 2023090600 release but this is the official
                    September release from AOSP and the stock OS rather than just applying the
                    Android Security Bulletin backports to Android 13.</p>

                    <p>The strange timing and inclusion of only a single patch (Mali GPU kernel
                    driver fix) in the September Pixel Update Bulletin is due to Android 14 being
                    scheduled for this month but delayed to October. The Pixel Update Bulletin for
                    Android 14 will include a large number of recommended AOSP security patches
                    and many hardware related patches, neither of which will be backported to
                    Android 13, so we've already put a significant effort into porting to Android
                    14 via our limited early access to the source code. We aim to have our Android
                    14 port available as soon as possible after the stable release is published
                    due to the importance for security. It's unfortunate we don't have full access
                    to the sources in advance like Android partners, but we've had access to more
                    than we usually do this year and for longer due to the delay.</p>

                    <p>We've also included additional Mali GPU kernel driver patches and a libwebp
                    patch in this release, similar to the kernel.org LTS patches we ship on a
                    regular basis many months before Android. We'll do more of this in the future
                    as our resources and partnerships grow, but we don't have much ability to ship
                    firmware patches earlier until there's hardware built to run GrapheneOS.</p>

                    <p>Pixel 4, Pixel 4 XL and Pixel 4a are end-of-life and shouldn't be used
                    anymore due to lack of security patches for firmware and drivers. We provide
                    extended support for harm reduction.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023091800-coral">2023091800-coral</a> (Pixel 4, Pixel 4 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023091800">2023091800</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023091800-tangorpro">2023091800-tangorpro</a> (Pixel Tablet)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023091800-felix">2023091800-felix</a> (Pixel Fold)</li>
                    </ul>

                    <p>Changes since the 2023090600 release:</p>

                    <ul>
                        <li>integrate official September update as a replacement for the backports in the last release</li>
                        <li>rebased onto TQ3A.230901.001 (generic, coral), TQ3A.230901.001.B1 (tangorpro) and TQ3C.230901.001.A1 (felix) Android Open Source Project releases</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold): backport additional Mali GPU driver security fixes from Android 14 Beta 5.3</li>
                        <li>webp: backport fix for CVE-2023-4863 not included in the Android September security patch level</li>
                        <li>Settings: remove Storage manager toggle since it lacks an implementation without Play services integrated into the OS</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.131</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/117.0.5938.44.0">version 117.0.5938.44.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/117.0.5938.44.1">version 117.0.5938.44.1</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/117.0.5938.60.0">version 117.0.5938.60.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-73">version 73</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-74">version 74</a></li>
                        <li>adevtool: add command for fetching info about stock OS kernels from AOSP repositories</li>
                    </ul>
                </article>

                <article id="2023090600">
                    <h3><a href="#2023090600">2023090600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023090600-coral">2023090600-coral</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023090600">2023090600</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023090600-tangorpro">2023090600-tangorpro</a> (Pixel Tablet)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023090600-felix">2023090600-felix</a> (Pixel Fold)</li>
                    </ul>

                    <p>Changes since the 2023090200 release:</p>

                    <ul>
                        <li>full 2023-09-01 security patch level (early release based on AOSP 13 security backports since the AOSP/stock monthly release is not available yet)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.194</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.130</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/116.0.5845.172.0">version 116.0.5845.172.0</a></li>
                    </ul>
                </article>

                <article id="2023090200">
                    <h3><a href="#2023090200">2023090200</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023090200-coral">2023090200-coral</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023090200">2023090200</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023090200-tangorpro">2023090200-tangorpro</a> (Pixel Tablet)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023090200-felix">2023090200-felix</a> (Pixel Fold)</li>
                    </ul>

                    <p>Changes since the 2023080800 release:</p>

                    <ul>
                        <li>add support for viewing 7 days of history in the privacy dashboard via the official toggle instead of our previous approach</li>
                        <li>Sandboxed Google Play compatibility layer: hide eSIM activation app from Play Store since it can't update it</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.192</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.128</li>
                        <li>adevtool: fix 6th generation Pixel builds with PRODUCT_ENFORCE_RRO_TARGETS to make vendor generation easier</li>
                        <li>adevtool: major overhaul fixing resource parsing bugs via protobuf aapt2 output, removing depencency on BUILD_BROKEN_ELF_PREBUILT_PRODUCT_COPY_FILES, verifying hashes of vendor files, unpacking via debugfs/fsck.erofs to avoid needing mount privileges on the workstation and other UX / error checking improvements</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/116.0.5845.78.0">version 116.0.5845.78.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/116.0.5845.92.0">version 116.0.5845.92.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/116.0.5845.114.0">version 116.0.5845.114.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/116.0.5845.114.1">version 116.0.5845.114.1</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/116.0.5845.163.0">version 116.0.5845.163.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/116.0.5845.163.1">version 116.0.5845.163.1</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-67">version 67</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-68">version 68</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-69">version 69</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-70">version 70</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-71">version 71</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-72">version 72</a></li>
                    </ul>
                </article>

                <article id="2023080800">
                    <h3><a href="#2023080800">2023080800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023080800-coral">2023080800-coral</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023080800">2023080800</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023080800-tangorpro">2023080800-tangorpro</a> (Pixel Tablet)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023080800-felix">2023080800-felix</a> (Pixel Fold)</li>
                    </ul>

                    <p>Changes since the 2023080700 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: fix handling of app install confirmation for the sandboxed Play Store in background processes since they're moving towards it with a partially deployed feature flag</li>
                    </ul>
                </article>

                <article id="2023080700">
                    <h3><a href="#2023080700">2023080700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023080700-coral">2023080700-coral</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023080700">2023080700</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023080700-tangorpro">2023080700-tangorpro</a> (Pixel Tablet)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023080700-felix">2023080700-felix</a> (Pixel Fold)</li>
                    </ul>

                    <p>Changes since the 2023072600 release:</p>

                    <ul>
                        <li>full 2023-08-01 security patch level</li>
                        <li>full 2023-08-05 security patch level</li>
                        <li>rebased onto TQ3A.230805.001 (generic, coral), TQ3A.230805.001.B1 (tangorpro) and TQ3C.230805.001.A3 (felix) Android Open Source Project releases</li>
                        <li>add workarounds for upstream Android issue with user profiles causing screenshots to break the recent app list and launcher</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.187</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.120</li>
                        <li>Updater: add low-level ACCESS_NETWORK_STATE permission to prepare for it being required to run scheduled jobs depending on network state in Android 14</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/115.0.5790.166.0">version 115.0.5790.166.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-65">version 65</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-66">version 66</a></li>
                    </ul>
                </article>

                <article id="2023072600">
                    <h3><a href="#2023072600">2023072600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023072600-coral">2023072600-coral</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023072600">2023072600</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023072600-tangorpro">2023072600-tangorpro</a> (Pixel Tablet)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023072600-felix">2023072600-felix</a> (Pixel Fold)</li>
                    </ul>

                    <p>Changes since the 2023072400 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: fix crash caused by regression in the previous release which was caught in Alpha/Beta testing and blocked us from releasing it to the Stable channel</li>
                        <li>Settings: improve GrapheneOS user management setting infrastructure</li>
                        <li>Settings: move run in background settings right below switch user settings</li>
                        <li>Settings: unify app install settings into three options for non-guest users and two for guest users and move them right above the install available apps settings</li>
                        <li>Settings: remove incorrect caching of default guest user manager restrictions</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/115.0.5790.138.0">version 115.0.5790.138.0</a></li>
                    </ul>
                </article>

                <article id="2023072400">
                    <h3><a href="#2023072400">2023072400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023072400-coral">2023072400-coral</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023072400">2023072400</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023072400-tangorpro">2023072400-tangorpro</a> (Pixel Tablet)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023072400-felix">2023072400-felix</a> (Pixel Fold)</li>
                    </ul>

                    <p>Changes since the 2023071100 release:</p>

                    <ul>
                        <li>replace our changes to AOSP APN and CarrierConfig configurations with a GrapheneOS CarrierConfig2 app for easier maintenance, improved MVNO support and support for recently added configuration options</li>
                        <li>add infrastructure for comparing CarrierConfig2 against Google's CarrierSettings app</li>
                        <li>show installer package name in error reports to help with identifying issues caused by broken installers</li>
                        <li>update timezone module to Android mainline 331910000</li>
                        <li>Sandboxed Google Play compatibility layer: support overriding ComponentEnabledSettings via GmsCompatConfig</li>
                        <li>Sandboxed Google Play compatibility layer: add missing string for "Missing Play Games app" notification channel name</li>
                        <li>Sandboxed Google Play compatibility layer: avoid uncaught exceptions with location rerouting when client only has coarse location permission</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/115.0.5790.85.0">version 115.0.5790.85.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/115.0.5790.136.0">version 115.0.5790.136.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-63">version 63</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-64">version 64</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/74">version 74</a></li>
                    </ul>
                </article>

                <article id="2023071100">
                    <h3><a href="#2023071100">2023071100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023071100-coral">2023071100-coral</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023071100">2023071100</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023071100-tangorpro">2023071100-tangorpro</a> (Pixel Tablet)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023071100-felix">2023071100-felix</a> (Pixel Fold)</li>
                    </ul>

                    <p>Changes since the 2023070500 release:</p>

                    <ul>
                        <li>Pixel Fold: rebased onto TQ3C.230705.001.C1 Android Open Source Project release</li>
                        <li>fix incomplete eSIM activation app initialization</li>
                        <li>do not allow enabling eSIM activation app on first boot due to issues from not including the Google Setup Wizard (UI explains that a reboot is required)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.186</li>
                        <li>SELinux policy (Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Fold): allow OemRilHookService to access IOemSlsiRadioExternal hwservice in order to avoid occasional battery drain from retries</li>
                        <li>Sandboxed Google Play compatibility layer: handle location rerouting inside the app using the Google Play location service to have the location permission usage and battery consumption properly attributed among other improvements</li>
                        <li>Sandboxed Google Play compatibility layer: notify user when "Nearby devices" perm is needed to connect to Wear OS</li>
                        <li>Sandboxed Google Play compatibility layer: show name of calling app in "Missing Play Games app" notification</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-62">version 62</a></li>
                    </ul>
                </article>

                <article id="2023070500">
                    <h3><a href="#2023070500">2023070500</a></h3>

                    <p>July release of the Android Open Source Project and stock OS for the Pixel
                    Fold is delayed, likely only for a few days. The device was just released on
                    June 27th with official support shipped in a GrapheneOS release on June
                    28th so it doesn't make sense to do an incomplete early release. We'll include
                    it as part of this release when the official July release is available.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023070500-coral">2023070500-coral</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023070500">2023070500</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023070500-tangorpro">2023070500-tangorpro</a> (Pixel Tablet)</li>
                    </ul>

                    <p>Changes since the 2023062800 release:</p>

                    <ul>
                        <li>full 2023-07-01 security patch level</li>
                        <li>full 2023-07-05 security patch level</li>
                        <li>rebased onto TQ3A.230705.001 (generic, coral) and TQ3A.230705.001.B4 (tangorpro) Android Open Source Project releases</li>
                        <li>do not report pseudo-"network" location provider to be always disabled (resolves regression with network location compatibility from <a href="#2023062300">2023062300</a>)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.185</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): revert 2 f2fs garbage collection optimizations backported in the Android GKI tree since at least one of them appears to be broken which we ran into in our previous <a href="#2023061400">2023061400 release</a> and now multiple OEMs including Xiaomi have encountered the issue in their own testing too</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.119</li>
                        <li>disable unused instant app features at boot</li>
                        <li>disable problematic "Add users from lock screen" setting at boot</li>
                        <li>Settings: remove problematic "Add users from lock screen" setting</li>
                        <li>Dialer: re-enable false gesture detection for answering calls, which can be replaced with a newer implementation in the near future instead of it being removed</li>
                        <li>Settings: require device restart to disable eSIM activation app via our toggle</li>
                        <li>Seedvault: update to latest revision (will be replaced with a better backup implementation in the future)</li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/17">version 17</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-61">version 61</a></li>
                    </ul>
                </article>

                <article id="2023062800">
                    <h3><a href="#2023062800">2023062800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023062800-coral">2023062800-coral</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023062800">2023062800</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023062800-tangorpro">2023062800-tangorpro</a> (Pixel Tablet)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023062800-felix">2023062800-felix</a> (Pixel Fold)</li>
                    </ul>

                    <p>Changes since the 2023062300 release:</p>

                    <ul>
                        <li>add initial Pixel Fold support</li>
                        <li>replace unused BUILD_ID field with device name in release channel metadata</li>
                        <li>System Updater: add enforcement of device name in release channel metadata as a misuse resistance improvement</li>
                        <li>Settings: mark DSUs (Dynamic System Updates) as unsupported</li>
                        <li>Launcher: add back Storage Scopes and Contact Scopes links to launcher icon shortcuts since this is now separate from the recent apps screen</li>
                        <li>Pixel Tablet: set default screen rotation to landscape mode (270 degrees) since we disable auto-rotation by default (due to the manual rotate button appearing after rotation) and the current default means that the device starts locked in portrait mode in the initial setup which gives a bad impression</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Generic 5.10): add missing non-security patch</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/114.0.5735.196.0">version 114.0.5735.196.0</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/73">version 73</a></li>
                    </ul>
                </article>

                <article id="2023062300">
                    <h3><a href="#2023062300">2023062300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023062300-coral">2023062300-coral</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023062300">2023062300</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/2023062301-tangorpro">2023062301-tangorpro</a> (Pixel Tablet)</li>
                    </ul>

                    <p>Changes since the 2023061402 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: fix compatibility with Nearby Share with current Play services versions</li>
                        <li>add production ready Pixel Tablet support (we published our initial release for it on June 21st, but this is the first production release with tags)</li>
                        <li>ignore non-system packages for location indicator exemptions, getLocationBypassPackages(), Qualified Network Services, telephony data services, device provisioning and wlan/wwan wireless network services to resolve an upstream vulnerability in the approach to exemptions impacting the Pixel Tablet</li>
                        <li>Settings: hide eSIM activation app toggle when the app isn't included in the OS such as the Pixel Tablet</li>
                        <li>prevent adding guest user on lockscreen via adding new users on lockscreen is disabled (UI only appears on large screens such as the Pixel Tablet)</li>
                        <li>improve compatibility with apps trying to use a network location provider when none is available</li>
                        <li>fix work profile screenshot crash caused by missing configuration in AOSP</li>
                        <li>use unified tags based on our build number rather than the standard <var>BUILD_ID</var>.<var>BUILD_NUMBER</var></li>
                        <li>Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a: set <var>BUILD_ID</var> to match stock OS again</li>
                        <li>Settings: improve our infrastructure for user management toggles</li>
                        <li>Settings: add toggle for preventing a user from running in the background</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.110</li>
                        <li>adevtool: add support for devices without a cellular baseband</li>
                        <li>adevtool: make adding vendor_kernel_boot partition-exists generic</li>
                        <li>adevtool: disable broken support for file reference overlays</li>
                        <li>simplify Pixel prototype check by comparing brand instead of device model</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-58">version 58</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-59">version 59</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-60">version 60</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/72">version 72</a></li>
                    </ul>
                </article>

                <article id="2023061402">
                    <h3><a href="#2023061402">2023061402</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023061402">TP1A.221005.002.B2.2023061402</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ3A.230605.012.2023061402">TQ3A.230605.012.2023061402</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023061400 release:</p>

                    <ul>
                        <li>enable "Enhanced PIN privacy" feature by default to disable lockscreen PIN animations (configurable via PIN screen lock settings using the gear icon)</li>
                        <li>fix upstream bug in Android 13 QPR3 causing crash when selecting a wallpaper</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Generic 5.10): revert update to latest GKI LTS branch revision due to it potentially causing very rare update failures that are successfully rolled back (note: this is not part of the June Android 13 QPR3 release but rather we are normally months ahead on core kernel updates due to using a bleeding edge GKI release and we'll be a little bit less ahead now)</li>
                    </ul>
                </article>

                <article id="2023061400">
                    <h3><a href="#2023061400">2023061400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023061400">TP1A.221005.002.B2.2023061400</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ3A.230605.012.2023061400">TQ3A.230605.012.2023061400</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023060700 release:</p>

                    <ul>
                        <li>full 2023-06-05 security patch level (official AOSP and stock OS June security update was earlier today)</li>
                        <li>rebased onto TQ3A.230605.012 release, which is the third quarterly maintenance/feature release for Android 13 (released earlier today)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Generic 5.10): update to latest GKI LTS branch revision</li>
                        <li>Gallery: remove broken widgets (AOSP Gallery will eventually be replaced with a much better app)</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/114.0.5735.131.0">version 114.0.5735.131.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-57">version 57</a></li>
                    </ul>
                </article>

                <article id="2023060700">
                    <h3><a href="#2023060700">2023060700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023060700">TP1A.221005.002.B2.2023060700</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230505.002.2023060700">TQ2A.230505.002.2023060700</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2B.230505.005.A1.2023060700">TQ2B.230505.005.A1.2023060700</a> (Pixel 7a)</li>
                    </ul>

                    <p>Changes since the 2023052900 release:</p>

                    <ul>
                        <li>full 2023-06-01 security patch level (early release based on AOSP 13 security backports since the AOSP/stock QPR3 release is not available yet)</li>
                        <li>partial 2023-06-05 security patch level (full firmware and userspace patches will not be available until the AOSP/stock QPR3 release and some of the kernel changes depend on those too)</li>
                        <li>fix Contact Scopes UI handling of absent number/email type</li>
                        <li>remove E-Tugra Certificate Authority</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/114.0.5735.58.0">version 114.0.5735.58.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/114.0.5735.61.0">version 114.0.5735.61.0</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/71">version 71</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/63">version 63</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-56">version 56</a></li>
                    </ul>
                </article>

                <article id="2023052900">
                    <h3><a href="#2023052900">2023052900</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023052900">TP1A.221005.002.B2.2023052900</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230505.002.2023052900">TQ2A.230505.002.2023052900</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2B.230505.005.A1.2023052900">TQ2B.230505.005.A1.2023052900</a> (Pixel 7a)</li>
                    </ul>

                    <p>Changes since the 2023052800 release:</p>

                    <ul>
                        <li>avoid disabling DNS-over-TLS resolver test queries as part of disabling connectivity checks since it breaks automatic mode</li>
                        <li>fix Contact Scopes regression blocking granting Contacts permission via the permission screen</li>
                        <li>fix native debug toggle regression</li>
                        <li>Pixel 7a: keep standalone project repositories in sync for the device branch</li>
                    </ul>
                </article>

                <article id="2023052800">
                    <h3><a href="#2023052800">2023052800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023052800">TP1A.221005.002.B2.2023052800</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230505.002.2023052800">TQ2A.230505.002.2023052800</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2B.230505.005.A1.2023052800">TQ2B.230505.005.A1.2023052800</a> (Pixel 7a)</li>
                    </ul>

                    <p>Changes since the 2023051600 release:</p>

                    <ul>
                        <li>use GrapheneOS name by default for remaining DNS resolver name resolution tests</li>
                        <li>extend GrapheneOS toggle to remaining DNS resolver name resolution tests</li>
                        <li>port remaining GrapheneOS settings to modern GrapheneOS settings infrastructure</li>
                        <li>improve compatibility of revoking the Network permission by treating the network as down for more APIs</li>
                        <li>improve infrastructure for the Network permission</li>
                        <li>improve Contact Scopes user interface, fix various minor bugs and improve app compatibility</li>
                        <li>Dialer: support up to 12 buttons instead of 6 to work around call recording going beyond the limit</li>
                        <li>Messaging: update MMS configuration database based on Google Messages 20230502_01_RC04</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/113.0.5672.132.0">version 113.0.5672.132.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/113.0.5672.163.0">version 113.0.5672.163.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/114.0.5735.53.0">version 114.0.5735.53.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-53">version 53</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-54">version 54</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-55">version 55</a></li>
                    </ul>
                </article>

                <article id="2023051600">
                    <h3><a href="#2023051600">2023051600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023051600">TP1A.221005.002.B2.2023051600</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230505.002.2023051600">TQ2A.230505.002.2023051600</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2B.230505.005.A1.2023051600">TQ2A.230505.002.2023051600</a> (Pixel 7a)</li>
                    </ul>

                    <p>Changes since the 2023050500 release:</p>

                    <ul>
                        <li>add initial Contact Scopes feature as an alternative to granting the Contacts permission</li>
                        <li>improve Storage Scopes performance and robustness</li>
                        <li>improve GrapheneOS package state infrastructure</li>
                        <li>add production ready Pixel 7a support</li>
                        <li>Settings: fix obtaining maximum peak refresh rate for smooth display field for devices without smooth display enabled by default (Pixel 7a)</li>
                        <li>factory images flash-all script: raise minimum fastboot version for Windows to 33.0.3 too</li>
                        <li>factory images flash-all script: add device model check to Windows too</li>
                        <li>carriersettings-extractor: drop unused android-prepare-vendor support (all supported devices use adevtool)</li>
                        <li>enable non-flattened APEX modules for all targets (previously only enabled for 6th/7th generation Pixels which have hard dependencies on it)</li>
                        <li>extend making userspace function pointer tables read-only</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.178</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/70">version 70</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-52">version 52</a></li>
                    </ul>
                </article>

                <article id="2023050500">
                    <h3><a href="#2023050500">2023050500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023050500">TP1A.221005.002.B2.2023050500</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230505.002.2023050500">TQ2A.230505.002.2023050500</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023050100 release:</p>

                    <ul>
                        <li>add support for disabling PSDS in addition to the GrapheneOS server and standard server options</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: add support for controlling PSDS on Qualcomm SoC devices to extend PSDS configuration to them along with using the GrapheneOS PSDS cache by default</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: disable User-Agent for Qualcomm PSDS (XTRA) via xtra-daemon hooking to avoid providing device information to the server (we already removed the hardware identifier via SELinux policy in a previous release)</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: use time.grapheneos.org for XTRA NTP and qualcomm.psds.grapheneos.org for XTRA PSDS downloads by default</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: always use most complete / generic Qualcomm PSDS (XTRA) variant via xtra-daemon hooking to avoid leaking info on radio variant or region</li>
                        <li>Settings: improve infrastructure for GrapheneOS settings</li>
                        <li>Settings: port remote key provisioning setting to new infrastructure</li>
                        <li>Settings: move PSDS configuration to Location settings with our SUPL configuration</li>
                        <li>Settings: port SUPL setting to new infrastructure</li>
                        <li>Settings: remove icon for Internet connectivity check and remote key provisioning settings for now</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): Mali GPU driver update</li>
                        <li>System Updater: add TLS key pinning with expiration 2 months in the future to make TLS more useful as an additional layer of security before the 3 layers of offline update signing with downgrade protection (update package signature, update_engine payload signature and verified boot signatures) while also avoiding blocking updates on out-of-date installs falling behind changes to our TLS certificate approach</li>
                        <li>update timezone module to Android mainline 331314030 (based on tzdata 2023a)</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.106</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/113.0.5672.77.0">version 113.0.5672.77.0</a></li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/19">version 19</a></li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/20">version 20</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-51">version 51</a></li>
                    </ul>
                </article>

                <article id="2023050100">
                    <h3><a href="#2023050100">2023050100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023050100">TP1A.221005.002.B2.2023050100</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230505.002.2023050100">TQ2A.230505.002.2023050100</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023042900 release:</p>

                    <ul>
                        <li>full 2023-05-01 security patch level</li>
                        <li>full 2023-05-05 security patch level</li>
                        <li>rebased onto TQ2A.230505.002 release</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-50">version 50</a></li>
                    </ul>
                </article>

                <article id="2023042900">
                    <h3><a href="#2023042900">2023042900</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023042900">TP1A.221005.002.B2.2023042900</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230405.003.2023042900">TQ2A.230405.003.2023042900</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230405.003.E1.2023042900">TQ2A.230405.003.E1.2023042900</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023041100 release:</p>

                    <ul>
                        <li>add Storage Scopes link to "All files access" screen</li>
                        <li>Launcher: revert additional padding (will need a different workaround for the upstream issue)</li>
                        <li>disable UWB (Ultra Wide Band) by default</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: enforce XTRA version 3 for PSDS downloads (GNSS satellite almanacs)</li>
                        <li>Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: fix generic certificate authority configuration for future use with our Qualcomm PSDS proxy</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: remove access to SoC information from GPS user to prevent xtra-daemon from reading SoC serial number and including it in User-Agent</li>
                        <li>hwui: backport null pointer check from AOSP master</li>
                        <li>keystore: backport generating fallback operation challenge with SecureRandom from AOSP master</li>
                        <li>Launcher: backport null pointer check from AOSP master</li>
                        <li>backport fix for Bluetooth related system_server crash</li>
                        <li>backport 8 media framework memory corruption fixes from AOSP master</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.177</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.104</li>
                        <li>kernel (5.15): enable RANDOMIZE_KSTACK_OFFSET_DEFAULT</li>
                        <li>kernel (5.10, 5.15): panic on memory corruption detected by kfence</li>
                        <li>kernel (5.10, 5.15): use hardened configuration for x86_64 GKI used by the emulator</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-47">version 47</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-48">version 48</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-49">version 49</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/112.0.5615.101.0">version 112.0.5615.101.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/112.0.5615.136.0">version 112.0.5615.136.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/113.0.5672.62.0">version 113.0.5672.62.0</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/113.0.5672.62.1">version 113.0.5672.62.1</a></li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/18">version 18</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/69">version 69</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/62">version 62</a></li>
                    </ul>
                </article>

                <article id="2023041100">
                    <h3><a href="#2023041100">2023041100</a></h3>

                    <p>As with the March release, the monthly Android Open Source Project and
                    stock Pixel OS release were rescheduled to the 2nd Monday of the month instead
                    of the 1st Monday.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023041100">TP1A.221005.002.B2.2023041100</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230405.003.2023041100">TQ2A.230405.003.2023041100</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230405.003.E1.2023041100">TQ2A.230405.003.E1.2023041100</a> (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023040400 release:</p>

                    <ul>
                        <li>full 2023-04-01 security patch level</li>
                        <li>full 2023-04-05 security patch level</li>
                        <li>rebased onto TQ2A.230405.003.E1 release</li>
                        <li>Settings: add toggle for controlling direct access to Tensor hardware accelerators (TPU, GXP) by certain Google apps for users to choose whether Google apps can use more than the portable Android hardware acceleration features such as the Neural Networks API (direct access does not give them any additional data)</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro: add dynamic control over direct TPU access</li>
                        <li>Pixel 7, Pixel 7 Pro: add dynamic control over GXP access by Google Camera</li>
                        <li>add support for providing Camera vendor extensions on Pixels via Pixel Camera Services app (at the moment, only the Camera2 Night extension is available for certain devices and CameraX extensions aren't available yet)</li>
                        <li>add support for runtime resource overlays (RROs) to exec spawning</li>
                        <li>remove support for disabling app visibility filtering since our Pixel eSIM firmware app integration depends on it</li>
                        <li>change standard Android package installer behavior to preserving packages being disabled after updating them</li>
                        <li>Launcher: add padding to background behind app drawer search bar to work around upstream layout issue</li>
                        <li>Contacts: use proper theme for AndroidX dialogs to fix crash</li>
                        <li>System Updater: directly enforce respecting network type parameter instead of it solely depending on the JobScheduler constraint</li>
                        <li>System Updater: improve code quality and robustness</li>
                        <li>System Updater: ask the OS to allocate required storage space before starting update download</li>
                        <li>SELinux policy: add back app_data_file execute for adb shell run-as domain</li>
                        <li>Sandboxed Google Play compatibility layer: coerce Play Store into updating disabled apps by hiding disabled state from it</li>
                        <li>Sandboxed Google Play compatibility layer: add infrastructure for bypassing permission requirements of services provided by Play services</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-45">version 45</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-46">version 46</a></li>
                        <li>TalkBack (screen reader): update base code to 13.0 and overhaul our changes for it including removing proprietary library dependency</li>
                        <li>TalkBack (screen reader): update dependencies</li>
                        <li>kernel (5.10, 5.15): fix build for non-arm64 architectures</li>
                    </ul>
                </article>

                <article id="2023040400">
                    <h3><a href="#2023040400">2023040400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023040400">TP1A.221005.002.B2.2023040400</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.E1.2023040400">TQ2A.230305.008.E1.2023040400</a> (Pixel 6, Pixel 6 Pro, Pixel 6a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.2023040400">TQ2A.230305.008.2023040400</a> (Pixel 7)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.C1.2023040400">TQ2A.230305.008.C1.2023040400</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023032600 release:</p>

                    <ul>
                        <li>Keyboard: apply fix for upstream spell checking bug causing words followed by periods to be flagged as invalid for some configurations</li>
                        <li>enable auto-reboot feature by default with a very conservative 72 hour timer (i.e. the device will automatically reboot after 3 days without a successful unlock of any profile by default with users encouraged to set a shorter value to get their data automatically back at rest faster)</li>
                        <li>Dialer: add modernized call recording implementation using modern Android storage (no files permission) and with unnecessary cruft removed including not locking availability or playing a recording tone based on region (users are responsible for respecting regional laws including informing the other party or obtaining explicit consent if required)</li>
                        <li>Dialer: replace disabling bytecode optimization with a specific rule to keep fragment constructors</li>
                        <li>add generic compatibility shim catching the exception from the Gservices provider being missing to enable apps like Google Camera and the Pixel eSIM firmware app (Google eSIM activation app is separate) to work without GSF installed since they don't have any actual hard dependency on either GSF or Play services</li>
                        <li>remove unnecessary INTERNET (Network) permission from Pixel eSIM firmware app</li>
                        <li>enable Pixel eSIM firmware app by default instead of it being part of the eSIM activation toggle which is now only used for the eSIM activation app (Google eUICC LPA)</li>
                        <li>restrict Pixel eSIM firmware app from communication with non-system components to prevent it trying to get flags from GSF or a fake GSF</li>
                        <li>Settings: add Pixel eSIM firmware app to the list of apps which can't be disabled via GUI since it updates firmware</li>
                        <li>Launcher: hide "all apps" view when search starts to avoid upstream race condition where the wrong app can be opened when pressing too quickly</li>
                        <li>Launcher, Keyboard: drop GrapheneOS prefix from naming to match other GrapheneOS apps</li>
                        <li>update timezone module to Android mainline 331314020 (based on tzdata 2022g)</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10, Generic 5.15): add back our slab allocator canary feature</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10, Generic 5.15): align with linux-hardened BPF JIT configuration (always on with JIT hardening enabled in all cases)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.176</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.98</li>
                        <li>Settings: reimplement remote attestation key provisioning toggle via modern GrapheneOS settings infrastructure</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/112.0.5615.48.0">version 112.0.5615.48.0</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-44">version 44</a></li>
                        <li>Sandboxed Google Play compatibility layer: improve support for compatibility layer development</li>
                    </ul>
                </article>

                <article id="2023032600">
                    <h3><a href="#2023032600">2023032600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023032600">TP1A.221005.002.B2.2023032600</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.E1.2023032600">TQ2A.230305.008.E1.2023032600</a> (Pixel 6, Pixel 6 Pro, Pixel 6a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.2023032600">TQ2A.230305.008.2023032600</a> (Pixel 7)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.C1.2023032600">TQ2A.230305.008.C1.2023032600</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023032000 release:</p>

                    <ul>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.169</li>
                        <li>allow toggling VoWiFi while roaming by default</li>
                        <li>ignore carrier configuration disabling VoWiFi, VoLTE and VoNR toggles to make them available for all newly provisioned setups</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a: add missing SELinux policy context for resku_rescue_kicker (only currently used on Pixel 6a)</li>
                        <li>improve infrastructure for GosPackageState and permission self-check spoofing</li>
                        <li>fix work profile Storage Scopes link</li>
                        <li>only strip out carrier configuration refering to carrier apps that are not included in GrapheneOS to improve compatibility</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a: ship pvmfw as part of over-the-air updates for future use</li>
                        <li>Pixel 4, Pixel 4 XL: revert incompatible display mode change</li>
                        <li>Dialer: update visual voicemail (VVM) configuration database based on Google Phone 100.0.512999549</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-41">version 41</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-42">version 42</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-43">version 43</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/111.0.5563.116.0">version 111.0.5563.116.0</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/61">version 61</a></li>
                    </ul>
                </article>

                <article id="2023032000">
                    <h3><a href="#2023032000">2023032000</a></h3>

                    <p>Extended support for the end-of-life Pixel 4 and Pixel 4 XL will continue
                    but time is needed to resolve compatibility issues with Android 13 QPR2.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.E1.2023032000">TQ2A.230305.008.E1.2023032000</a> (Pixel 6, Pixel 6 Pro, Pixel 6a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.2023032000">TQ2A.230305.008.2023032000</a> (Pixel 7)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.C1.2023032000">TQ2A.230305.008.C1.2023032000</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023031500 release:</p>

                    <ul>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a: switch to QPR2 stable release vendor files instead of using the QPR2 3.2 Beta release</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a: stop freezing the patch level at a lower value which we were doing in case QPR2 3.2 Beta was missing firmware and other updates from the 2023-03-05 Pixel patch level</li>
                        <li>disable screenshot sound when touch sounds are disabled</li>
                        <li>adevtool: add support for converting privileged apps to unprivileged apps</li>
                        <li>adevtool: include PixelNfc app on all supported Pixels to enable support for FeliCa on Japanese Pixel models</li>
                        <li>adevtool: convert PixelNfc app into an unprivileged app since it doesn't need any privileged APIs</li>
                        <li>adevtool: implementation quality improvements</li>
                        <li>Settings: remove missing display resolution animation</li>
                        <li>CellBroadcastReceiver: drop out-of-sync translations for presidential alerts string</li>
                        <li>disable unnecessary auto-grant of Camera permission to eSIM activation app</li>
                        <li>Settings: revoke Camera permission from eSIM activation app before enabling it since it was auto-granted in the past</li>
                        <li>Sandboxed Google Play compatibility layer: don't spoof self permission checks that come from the compatibility layer itself</li>
                        <li>Sandboxed Google Play compatibility layer: add missing CHANGE_WIFI_STATE (Wi-Fi control) special access permission to the list of potential issues shown to users</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-39">version 39</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-40">version 40</a></li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/17">version 17</a></li>
                    </ul>
                </article>

                <article id="2023031500">
                    <h3><a href="#2023031500">2023031500</a></h3>

                    <p>Extended support for the end-of-life Pixel 4 and Pixel 4 XL will continue
                    but time is needed to resolve compatibility issues with Android 13 QPR2.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/T2B3.230109.009.2023031500">T2B3.230109.009.2023031500</a> (Pixel 6, Pixel 6 Pro, Pixel 6a) — 2023-03-05 Android patch level but only 2023-03-01 Pixel patch until a March stock OS release is published with updated firmware, etc. (marked as 2023-03-01 overall patch level in the OS)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.2023031500">TQ2A.230305.008.2023031500</a> (Pixel 7)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.C1.2023031500">TQ2A.230305.008.C1.2023031500</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023031300 release:</p>

                    <ul>
                        <li>keep PIN scrambling state up-to-date in all cases to make toggling it on or off kick in immediately instead of next time it opens</li>
                        <li>adevtool: remove overlay setting config_systemBluetoothStack to the wrong value (caused Bluetooth to break for users with exec-based spawning disabled, which is why the previous release only made it to Beta and not Stable)</li>
                        <li>adevtool: remove other unnecessary overlays</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro: disable GSI keys</li>
                    </ul>
                </article>

                <article id="2023031300">
                    <h3><a href="#2023031300">2023031300</a></h3>

                    <p>This release includes the 2nd quarterly release of Android 13 (QPR2) and is
                    why the March release of the Android Open Source Project and stock Pixel OS
                    ended up rescheduled to the 2nd Monday of the month rather than the 1st Monday
                    of the month. QPR2 includes dozens of additional recommended privacy/security
                    patches beyond the baseline March Android Security Bulletin. Shipping the full
                    monthly, quarterly and yearly releases rather than only the subset of patches
                    backported to older releases and listed in the Android Security Bulletins is
                    quite important.</p>

                    <p>We expect the official March release of the stock OS and Android Open
                    Source Project for the Pixel 6, Pixel 6 Pro and Pixel 6a to be on March 20th
                    (3rd Monday of the month). This release provides the full March Android
                    Security Bulletin patches for them but the Pixel bulletin patches require an
                    official release since the full set of changes isn't published yet.</p>

                    <p>Extended support for the end-of-life Pixel 4 and Pixel 4 XL will continue
                    but time is needed to resolve compatibility issues with Android 13 QPR2.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/T2B3.230109.009.2023031300">T2B3.230109.009.2023031300</a> (Pixel 6, Pixel 6 Pro, Pixel 6a) — 2023-03-05 Android patch level but only 2023-03-01 Pixel patch until a March stock OS release is published with updated firmware, etc. (marked as 2023-03-01 overall patch level in the OS)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.2023031300">TQ2A.230305.008.2023031300</a> (Pixel 7)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ2A.230305.008.C1.2023031300">TQ2A.230305.008.C1.2023031300</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023030400 release:</p>

                    <ul>
                        <li>full 2023-03-01 security patch level</li>
                        <li>full 2023-03-05 security patch level</li>
                        <li>rebased onto TQ2A.230305.008.C1 release, which is the second quarterly maintenance/feature release for Android 13</li>
                        <li>Pixel 6a: enable and enforce TLSv1.2 for Broadcom gpsd SUPL connections rather than using SSLv2, SSLv3, TLSv1 and TLSv1.1 without TLSv1.2 enabled like the stock OS</li>
                        <li>disable compressed APEX support since it only wastes space when not heavily using out-of-band APEX updates and adds more verified boot attack surface</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: switch Qualcomm xtra-daemon service to standard time.xtracloud.net server from Pixel-specific time.google.com (we plan to provide the option to use GrapheneOS servers for XTRA time and PSDS data on Qualcomm devices in the future as we do for newer generation Tensor Pixels already, and we have the server-side part implemented already)</li>
                        <li>add infrastructure for allowing apps with INSTALL_PACKAGES to avoid trying to install the same package at the same time</li>
                        <li>new PIN scrambling implementing extending PIN scrambling to SIM PIN/PUK and redoing PIN scrambling each time the PIN UI is opened</li>
                        <li>Settings: reimplement PIN scrambling toggle via modern GrapheneOS settings infrastructure</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/111.0.5563.58.0">version 111.0.5563.58.0</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/60">version 60</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-37">version 37</a></li>
                    </ul>
                </article>

                <article id="2023030400">
                    <h3><a href="#2023030400">2023030400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023030400">TP1A.221005.002.B2.2023030400</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230205.002.2023030400">TQ1A.230205.002.2023030400</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023022300 release:</p>

                    <ul>
                        <li>override carrier selected SUPL server (usually the fallback supl.google.com) to supl.grapheneos.org by default</li>
                        <li>Settings: replace toggle for disabling SUPL with a new toggle for choosing between GrapheneOS proxy (default), Standard (carrier choice, usually supl.google.com) and Disabled (users with our previous disable toggle enabled will have their setting preserved as Disabled and users who had disabled it then enabled it will have Standard as the default while anyone who hasn't touched it will have the new GrapheneOS proxy as the initial setting since it's the default)</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 7, Pixel 7 Pro: enable and enforce TLSv1.2 for Broadcom gpsd SUPL connections rather than using SSLv2, SSLv3, TLSv1 and TLSv1.1 without TLSv1.2 enabled like the stock OS (Pixel 6a will be changed in the next release)</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-35">version 35</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-36">version 36</a></li>
                        <li>Sandboxed Google Play compatibility layer: add debugging option to skip GNSS location updates</li>
                        <li>Sandboxed Google Play compatibility layer: support forcing PhenotypeFlags to their default values</li>
                        <li>Sandboxed Google Play compatibility layer: support spoofing self permission checks</li>
                        <li>Sandboxed Google Play compatibility layer: add support for GmsCompatConfig force_default_flags section</li>
                        <li>Sandboxed Google Play compatibility layer: add support for GmsCompatConfig spoof_self_permission_checks section</li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/110.0.5481.154.1">version 110.0.5481.154.1</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/111.0.5563.49.0">version 111.0.5563.49.0</a></li>
                        <li>System Updater: simplify the title for the silent/collapsed already up-to-date notification</li>
                        <li>disallow apps reading Global/Secure settings added by GrapheneOS via the new infrastructure since we currently have no settings apps need to read</li>
                        <li>skip INTERNET pre-grant checkbox when installing a system app in a profile where it isn't considered installed since it doesn't work correctly</li>
                        <li>add infrastructure for properly handling initial installation of system apps in Apps (our app repository client)</li>
                        <li>improve OS debug build developer option for skipping install time fs-verity requirement</li>
                        <li>reuse shared infrastructure for our implementation of enforcing a greater rather than greater or equal version for package updates</li>
                        <li>replace disabling install time greater versionCode check in OS debug builds with a similar debug build developer option as we use for skipping fs-verity checks at install time</li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/16">version 16</a></li>
                    </ul>
                </article>

                <article id="2023022300">
                    <h3><a href="#2023022300">2023022300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023022300">TP1A.221005.002.B2.2023022300</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230205.002.2023022300">TQ1A.230205.002.2023022300</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023021000 release:</p>

                    <ul>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.168</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.94</li>
                        <li>HTTPS-based network time: switch to custom X-Time header with UTC time in milliseconds to improve precision</li>
                        <li>HTTPS-based network time: establish HTTPS connection with another request in advance and then reuse it to improve accuracy</li>
                        <li>HTTPS-based network time: set clock offset field used by tests</li>
                        <li>HTTPS-based network time: improve logging</li>
                        <li>HTTPS-based network time: simplify implementation</li>
                        <li>reduce time update threshold to 50ms from Android's default 2000ms instead of allowing the clock to get up to 2s out-of-date</li>
                        <li>reduce system clock drift warning to 250ms from Android's default 2000ms</li>
                        <li>simplify our implementation of disabling cellular-based automatic time by using the standard permitted origin configuration</li>
                        <li>simplify our implementation of disabling network time refresh when automatic time is disabled (unlike GrapheneOS, Android always performs network time checks and the user only controls whether the results from any of the automatic time methods are used)</li>
                        <li>Messaging: avoid crash caused by upstream bug when forwarding a message</li>
                        <li>Seedvault: add back restore action in settings without marking it experimental</li>
                        <li>Settings: fix accessibility settings links for SetupWizard</li>
                        <li>add shared infrastructure for GrapheneOS settings and port the settings to it (improves UI of Settings)</li>
                        <li>Settings: only allow Owner to control our added toggle for camera availability on lockscreen since it's global</li>
                        <li>hardened_malloc: preserve errno for free calls (future POSIX requirement)</li>
                        <li>simplify infrastructure for special runtime permissions (Network, Sensors)</li>
                        <li>Sandboxed Google Play compatibility layer: remove obsolete shim now handled by GmsCompatConfig</li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-33">version 33</a></li>
                        <li>GmsCompatConfig: update to <a href="https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-34">version 34</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/110.0.5481.65">version 110.0.5481.65</a></li>
                        <li>Vanadium: update to <a href="https://github.com/GrapheneOS/Vanadium/releases/tag/110.0.5481.154">version 110.0.5481.154</a></li>
                        <li>use C.UTF-8 locale for build environment to avoid dependency of the en_US.UTF-8 locale being available</li>
                    </ul>
                </article>

                <article id="2023021000">
                    <h3><a href="#2023021000">2023021000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023021000">TP1A.221005.002.B2.2023021000</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230205.002.2023021000">TQ1A.230205.002.2023021000</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023020600 release:</p>

                    <ul>
                        <li>add toggle to <b>Settings&#160;<span aria-label="and then">></span> Location</b> for force disabling SUPL as a carrier-independent replacement for editing APN configuration since editing APN configuration is unintuitive, not fully respected on Tensor SoC devices and users with no carrier should be able to disable it without using airplane mode</li>
                        <li>Vanadium: update Chromium base to 110.0.5481.64</li>
                        <li>GmsCompatConfig: update max supported version of Play Store</li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/15">version 15</a></li>
                    </ul>
                </article>

                <article id="2023020600">
                    <h3><a href="#2023020600">2023020600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.B2.2023020600">TP1A.221005.002.B2.2023020600</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230205.002.2023020600">TQ1A.230205.002.2023020600</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023020200 release:</p>

                    <ul>
                        <li>full 2023-02-01 security patch level</li>
                        <li>full 2023-02-05 security patch level</li>
                        <li>rebased onto TQ1A.230205.002 release</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.162</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.91</li>
                        <li>Seedvault: update to latest revision (will be replaced with a better backup implementation in the future)</li>
                        <li>Seedvault: require lock method to enable backups to prevent accessing internal app data for a device that has been unlocked without the lock method for the user profile, similar to how enabling developer options requires the lock method</li>
                        <li>SetupWizard: update GrapheneOS string branding</li>
                        <li>fix renaming of original-package Vanadium provider authorities regressed in the previous release due to the fix for an upstream Android 13 bug</li>
                        <li>Dialer: add dark mode to call UI dial pad</li>
                        <li>Pixel 4, Pixel 4 XL: switch to TP1A.221005.002.B2 (February 2022) vendor files</li>
                        <li>GmsCompatConfig: update max supported version of Play services and Play Store</li>
                    </ul>
                </article>

                <article id="2023020200">
                    <h3><a href="#2023020200">2023020200</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2023020200">TP1A.221005.002.2023020200</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.001.2023020200">TQ1A.230105.001.2023020200</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.001.A2.2023020200">TQ1A.230105.001.A2.2023020200</a> (Pixel 6a, Pixel 7)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.002.2023020200">TQ1A.230105.002.2023020200</a> (Pixel 6, Pixel 6 Pro, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>This release fixes major weaknesses in Android's verified boot. Android has
                    working protection of the firmware images, OS images and out-of-band updates
                    to APEX components through verified boot and provides verification for every
                    read of the data rather than actually only verifying at boot. Firmware and
                    core OS images are fully read and verified before use. High level OS images
                    and out-of-band APEX updates are verified dynamically when data is read via
                    dm-verity. Unfortunately, Android doesn't have anywhere near complete/correct
                    verification of non-APEX APK-based components including many privileged OS
                    components implemented as apps and the apps bundled with the OS. GrapheneOS
                    now provides an implementation of this verification to extend verified boot
                    and hardware-based attestation to these components correctly. We previously
                    enhanced the downgrade protection check for system updates to require a
                    greater version rather than equal or greater due to most Android OS components
                    not having their versionCode consistently increased when they're changed, and
                    this is now integrated into our new verification. Fully verifying signatures
                    of system app updates at boot isn't enough to fully extend the verified boot
                    guarantees to them, so we're shipping signed fs-verity metadata for all our
                    system app updates through our app repository and we're enforcing having valid
                    fs-verity metadata for system app updates at install time and boot time. This
                    provides continuous verification of the data provided by out-of-band package
                    updates.</p>

                    <p>Since fs-verity is now fully enforced for installing system app updates,
                    they can only be installed from our app repository providing the fs-verity
                    metadata. This happens automatically via our app repository client, but you
                    could manually download packages and fs-verity metadata to manually install
                    them. OS releases bundle the latest releases of the bundled components so the
                    out-of-band updates are simply a way to get updates quicker.</p>

                    <p>This release also supports out-of-band updates for Vanadium going forward
                    due to replacing incompatible SELinux hardening with these far superior
                    verified boot improvements along with fixing a major upstream Android 13
                    regression in the original-package feature causing out-of-band updates to
                    system apps using this feature to be rolled back on reboot. Vanadium used
                    original-package to rename the browser app from org.chromium.chrome to
                    app.vanadium.browser so it still uses the org.chromium.chrome app id for
                    compatibility on older installs (factory reset counts as a fresh install).
                    Both app ids will be able to receive out-of-band updates due to our bug
                    fix.</p>

                    <p>Changes since the 2023012500 release:</p>

                    <ul>
                        <li>Settings: fix issue preventing users from re-enabling system apps they previously disabled which can no longer be disabled</li>
                        <li>fix upstream Android bug causing out-of-band updates to system components using original-package to be rolled back after reboot if they're still using the old package name, which will allow us to ship Vanadium updates out-of-band without the browser package updates being rolled back for users with an older install where it's still <code>org.chromium.chrome</code> instead of <code>app.vanadium.browser</code></li>
                        <li>SELinux policy: drop base OS apk_data_file restrictions to avoid blocking out-of-band updates to APK-based system components (this was a minor security feature that's being replaced with our recent and ongoing improvements to package manager and verified boot security to close major weaknesses in the standard Android verified boot security model)</li>
                        <li>disable package parser cache since it provides a verified boot bypass for system component updates for regular boots while saving less than a second of boot time</li>
                        <li>perform additional boot-time checks on system package updates in order to extend verified boot to out-of-band system package updates including enforcing having valid signed fs-verity metadata for continuous verification (Android does not even provide working boot-time verification for out-of-band APK updates for non-APEX components)</li>
                        <li>reimplement requiring fs-verity when installing system package updates in a better way</li>
                        <li>remove unnecessary warning for failed virtual A/B sideloaded updates since it's atomic just like A/B updates</li>
                        <li>drop our extension to the install available apps feature (which is still available, without this extension) making it work for apps not installed in Owner since this is risky in a situation where there are actually separate people using secondary users and while we want to provide this feature, we'd need to come up with a way to address this to add it back</li>
                        <li>SetupWizard: stop enabling Wi-Fi automatically</li>
                        <li>SetupWizard: stop sending unused sticky broadcast</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.89</li>
                        <li>kernel (Pixel 7, Pixel 7 Pro): update Mali GPU driver to QPR2 Beta 3 release</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a): update base kernel to Android 13 QPR2 Beta 3 providing 2023-02-05 security patch level for the kernel</li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/14">version 14</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/68">version 68</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/59">version 59</a></li>
                        <li>Vanadium: update Chromium base to 110.0.5481.61</li>
                        <li>GmsCompatConfig: update max supported version of Play services and Play Store</li>
                    </ul>
                </article>

                <article id="2023012500">
                    <h3><a href="#2023012500">2023012500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2023012500">TP1A.221005.002.2023012500</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.001.2023012500">TQ1A.230105.001.2023012500</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.001.2023012600">TQ1A.230105.001.2023012600</a> (Pixel 4a (5G)) — rebuild to fix radio firmware loading issue caused by an upstream Android build system bug</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.001.A2.2023012500">TQ1A.230105.001.A2.2023012500</a> (Pixel 6a, Pixel 7)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.002.2023012500">TQ1A.230105.002.2023012500</a> (Pixel 6, Pixel 6 Pro, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023011000 release:</p>

                    <ul>
                        <li>don't send IMSI / Phone number to SUPL server when SUPL is enabled (note: using SUPL is always an optional choice on GrapheneOS, unlike AOSP and the stock OS)</li>
                        <li>SELinux policy: drop auditing for apk_data_file execute/execute_no_trans (research is done)</li>
                        <li>SELinux policy: add back apk_data_file execute/execute_no_trans for adb shell for debugging use cases (removing it isn't really useful for hardening and we plan on hardening ADB for the verified boot model another way)</li>
                        <li>Settings: revert to standard Android 13 minimum threshold of 10% for automatic battery saver since lowering it below 10% doesn't work as intended without more invasive changes outside the scope of GrapheneOS</li>
                        <li>fully disallow installing instant apps instead of permitting ADB shell and system apps to do it (this will simplify future work)</li>
                        <li>extend self app-op spoofing used for Network permission compatibility to unsafeCheckOpRaw()</li>
                        <li>fix upstream bug causing crash from isServiceTokenValidLocked() being called without holding the lock</li>
                        <li>Sandboxed Google Play compatibility layer: support enabling compatibility layer for any package on debuggable builds to help with development</li>
                        <li>Sandboxed Google Play compatibility layer: coerce Play Store into not attempting to auto install AR services</li>
                        <li>Sandboxed Google Play compatibility layer: fix issues with Play Store updates of Play services</li>
                        <li>Sandboxed Google Play compatibility layer: avoid our implementation of the Play services location API returning null for getCurrentLocation() to avoid crashes in apps not handling it</li>
                        <li>Sandboxed Google Play compatibility layer: increment compatibility layer version to 1001</li>
                        <li>Sandboxed Google Play compatibility layer: use the most recent available version map in GmsCompatConfig to simplify defining configuration</li>
                        <li>Sandboxed Google Play compatibility layer: improve stack trace parser used for dynamic exception shims</li>
                        <li>Sandboxed Google Play compatibility layer: add shim for making Bluetooth adapter discoverable</li>
                        <li>Sandboxed Google Play compatibility layer: improve UX for "Action required in Play Store" notification</li>
                        <li>Sandboxed Google Play compatibility layer: add new shims to support requesting temporary screen capture from the user via the standard unprivileged approach for Chromecast screen casting (currently lacks shims to support audio capture)</li>
                        <li>GmsCompatConfig: add stub for LocationManager.registerGnssStatusCallback()</li>
                        <li>GmsCompatConfig: update max supported version of Play services and Play Store</li>
                        <li>stop re-enabling deprecated 2-button navigation option since Android no longer has official support for it and is gradually breaking support for it including making changes knowingly introducing bugs with it since it's not meant to be used (traditional 3-button navigation is still fully supported)</li>
                        <li>Settings: add GrapheneOS Camera to list of mandatory components since only system camera apps can provide the media capture intents required by other apps on Android 11 and above (can still be disabled via ADB but we want to avoid easy ways to break the OS in the UI)</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.80</li>
                        <li>extend the install available apps feature (allows Owner user to install apps in other users) to apps only installed in secondary profiles</li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/13">version 13</a></li>
                        <li>add GrapheneOS fs-verity public key as a supported key</li>
                        <li>require fs-verity for installing system app updates (will be enforced at boot for verified boot enhancement in a future release due to the need to phase in the feature properly because of future out-of-band app updates on earlier OS releases)</li>
                        <li>Vanadium: update Chromium base to 109.0.5414.118</li>
                        <li>SettingsIntelligence: drop no longer required QUERY_ALL_PACKAGES permission now that more precise queries are defined upstream providing the necessary package visibility for Settings app search</li>
                    </ul>
                </article>

                <article id="2023011000">
                    <h3><a href="#2023011000">2023011000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2023011000">TP1A.221005.002.2023011000</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.001.2023011000">TQ1A.230105.001.2023011000</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.001.A2.2023011000">TQ1A.230105.001.A2.2023011000</a> (Pixel 6a, Pixel 7)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.002.2023011000">TQ1A.230105.002.2023011000</a> (Pixel 6, Pixel 6 Pro, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2023010300 release:</p>

                    <ul>
                        <li>fix upstream bug leading to AppOps being reset after reboot (may occur for users one last time due to corrupt state from before this update)</li>
                        <li>add more logging to resolve another upstream AppOps bug</li>
                        <li>enable adaptive brightness by default</li>
                        <li>Sandboxed Google Play compatibility layer: improve logging of GmsCompatConfig parser errors</li>
                        <li>Sandboxed Google Play compatibility layer: update BluetoothAdapter.enable() shim for Android 13</li>
                        <li>Sandboxed Google Play compatibility layer: fix deadlock when reading state of "Google Location Accuracy" toggle</li>
                        <li>Sandboxed Google Play compatibility layer: delay notification about Google Play crash until after potential config update</li>
                        <li>Sandboxed Google Play compatibility layer: allow bound Google Play apps to request update of GmsCompatConfig</li>
                        <li>Sandboxed Google Play compatibility layer: don't block Play Store from installing APK splits for Play services and itself</li>
                        <li>Sandboxed Google Play compatibility layer: try to update GmsCompatConfig before update of Play services or Play Store</li>
                        <li>GmsCompatConfig: update max supported versions of Play services and Play Store</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.161</li>
                        <li>Settings: hide missing illustration for quickly open camera not covered by our earlier fix</li>
                        <li>kernel (Pixel 7, Pixel 7 Pro): update Mali GPU driver to QPR2 Beta 2 release</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a): update base kernel to Android 13 QPR2 Beta 2</li>
                        <li>Vanadium: update Chromium base to 109.0.5414.86</li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/12">version 12</a></li>
                        <li>switch to signing OS source releases (Git tags) with OpenSSH instead of GPG to fully phase out usage of our GPG key (public key list: <a href="/allowed_signers">allowed_signers</a>, key rotation proof via signify: <a href="/allowed_signers.sig">allowed_signers.sig</a>, key rotation proof via GPG: <a href="/allowed_signers.asc">allowed_signers.asc</a>)</li>
                    </ul>
                </article>

                <article id="2023010300">
                    <h3><a href="#2023010300">2023010300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2023010300">TP1A.221005.002.2023010300</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.001.2023010300">TQ1A.230105.001.2023010300</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.001.A2.2023010300">TQ1A.230105.001.A2.2023010300</a> (Pixel 6a, Pixel 7)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.230105.002.2023010300">TQ1A.230105.002.2023010300</a> (Pixel 6, Pixel 6 Pro, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022122700 release:</p>

                    <ul>
                        <li>full 2023-01-01 security patch level</li>
                        <li>full 2023-01-05 security patch level</li>
                        <li>rebased onto TQ1A.230105.002 release</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a): add Valve Steam Controller driver security fix from the January release not already included in the QPR2 Beta 1 kernel we use as the base (was already included for other devices)</li>
                        <li>add sandboxed Play Store to the dependencies of Google's eUICC packages (eSIM)</li>
                        <li>eUICC compat toggle (eSIM): listen and react to changes to relevant packages</li>
                        <li>add extra logging to debug upstream issue causing AppOps to be reset after reboot</li>
                        <li>fix upstream bug in lite package parser causing targetSdkVersion to not be read in all cases which among other things was causing Android 12+ unattended update support to fail for updating PayPal without user intervention</li>
                        <li>TalkBack (screen reader): revert base code update due to multiple upstream regressions such as Braille keyboard crashes until these issues are resolved</li>
                        <li>System Updater: replace icons with new Material symbols</li>
                        <li>System Updater: use dedicated icons for success and failure notifications</li>
                        <li>Vanadium: enable new third party storage partitioning</li>
                        <li>Storage Scopes: don't show the link for system components with force enabled storage permissions</li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/8">version 8</a></li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/9">version 9</a></li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/10">version 10</a></li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/11">version 11</a></li>
                        <li>GmsCompatConfig: update max supported versions of Play services and Play Store</li>
                    </ul>
                </article>

                <article id="2022122700">
                    <h3><a href="#2022122700">2022122700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022122700">TP1A.221005.002.2022122700</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.221205.011.2022122700">TQ1A.221205.011.2022122700</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022122000 release:</p>

                    <ul>
                        <li>fix upstream Android 13 QPR1 recent apps list bug mainly triggered after user profile switches (Android 13 QPR1 "App not available" bug)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision which provides a proper fix for a backport mistake we discovered and reported</li>
                        <li>block updating system packages to versions with the same versionCode since system packages without releases outside the OS rarely have their versionCode increased when changes are made and therefore it makes it possible to downgrade them which is a security weakness in Android's approach</li>
                        <li>prefer package from OS image  over equal version packages installed as an update to improve security by dropping potentially downgraded packages particularly for the verified boot security model, with the bonus of saving disk space by dropping out-of-band updates installed from our app repository once they're redundant</li>
                        <li>add an API for system apps with the privileged INSTALL_PACKAGES permission to search for packages across all profiles in order to avoid redownloading packages that are already installed in another user and to prevent attempting to downgrade a package with a newer version already installed in another user (used by the GrapheneOS app repository client within GrapheneOS to provide a better experience than it can when not integrated into the OS)</li>
                        <li>restore previous lockscreen clock font from before Android Open Source Project 13 QPR1 since the stock Pixel OS overrides it and most people seem to prefer the previous font</li>
                        <li>TalkBack (screen reader): update base code to 13</li>
                        <li>TalkBack (screen reader): update dependencies</li>
                    </ul>
                </article>

                <article id="2022122000">
                    <h3><a href="#2022122000">2022122000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022122000">TP1A.221005.002.2022122000</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.221205.011.2022122000">TQ1A.221205.011.2022122000</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022121400 release:</p>

                    <ul>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.78</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.157</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): revert 5.10.157 IRQ changes breaking boot on Pixel 7 and Pixel 7 Pro</li>
                        <li>adevtool: stop including unused install constraint configuration</li>
                        <li>adevtool: stop including stock OS root CA database</li>
                        <li>include Apps (app repository client) in managed profiles by default in order to support installing / updating sandboxed Google Play</li>
                        <li>change DNS-over-TLS connectivity check to querying for <code><var>randomstring</var>-dnsotls-ds.dnscheck.grapheneos.org</code> rather than <code><var>randomstring</var>-dnsotls-ds.metric.gstatic.com</code> when the connectivity check mode is set to the default GrapheneOS mode (note: no connection is made to the resolved IP based on the DNS query, this is only used to check if the DNS resolver works and we're mainly changing this for aesthetic reasons)</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro: switch to more generic broadcom.psds.grapheneos.org name for our Predicted Satellite Data Service (PSDS) cache instead of google.psds.grapheneos.org since we're obtaining it directly from Broadcom rather than Google's cache and it isn't Pixel specific but rather could be used with any Broadcom GNSS (GPS, GLONASS, etc.) chip</li>
                        <li>Dialer: disable showing homescreen wallpaper</li>
                        <li>fix Storage Scopes interaction with pre-granted storage permissions for system apps</li>
                        <li>fix upstream issue causing factory images flashing script to break with paths containing spaces on systems where /bin/sh isn't bash such as Debian-based distributions where dash is used instead</li>
                    </ul>
                </article>

                <article id="2022121400">
                    <h3><a href="#2022121400">2022121400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022121400">TP1A.221005.002.2022121400</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.221205.011.2022121400">TQ1A.221205.011.2022121400</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022121100 release:</p>

                    <ul>
                        <li>kernel (Pixel 7, Pixel 7 Pro): update Mali GPU driver to r38p1 along with other changes included in the QPR2 Beta 1 including a bunch of security fixes previously neglected upstream (GrapheneOS will continue applying further updates downstream)</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a): update base kernel to Android 13 QPR2 Beta 1 to ship many security patches early</li>
                        <li>fix app label for draw over other apps in secondary profiles</li>
                        <li>fix toast color not changing with theme changes</li>
                        <li>Settings: hide missing illustrations</li>
                        <li>SELinux policy (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): remove unused domains and keys to reduce attack surface</li>
                        <li>Messaging: add dark theme</li>
                        <li>Vanadium: update Chromium base to 108.0.5359.128</li>
                        <li>adevtool: avoid needing manual changes for vendor state generation builds</li>
                        <li>use clone-depth="1" for prebuilts repositories in the pantah kernel manifest for a much more lightweight repo sync</li>
                    </ul>
                </article>

                <article id="2022121100">
                    <h3><a href="#2022121100">2022121100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022121100">TP1A.221005.002.2022121100</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.221205.011.2022121100">TQ1A.221205.011.2022121100</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022120700 release:</p>

                    <ul>
                        <li>resolve <a href="https://issuetracker.google.com/issues/254665045">upstream bug in Android 13 QPR1</a> causing screen brightness dimming on user profile changes</li>
                        <li>Settings: replace hard-wired refresh rate in the text for the smooth display toggle with the actual max refresh rate used for the device model (Android has the string hard-wired to say 90Hz and expects the device to provide an overlay with the correct string which isn't present in AOSP for Pixels)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.156</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.77</li>
                        <li>Sandboxed Google Play compatibility layer: new infrastructure for controlling Play Store updates of Play Store and Play services with a max version of Play services and the Play Store set via GmsCompatCompat and an override toggle for allowing it to update to any version</li>
                        <li>Sandboxed Google Play compatibility layer: hide GrapheneOS Auditor variant (app.attestation.auditor) from the Play Store so it doesn't try to update it (note: we plan to fully switch to app.grapheneos.auditor.play for the Play Store and we can remove this workaround once we unpublish the GrapheneOS variant of the app there and stop updating it)</li>
                        <li>Pixel 7, Pixel 7 Pro: remove unused Google Camera SELinux policy</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/67">version 67</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/58">version 58</a></li>
                    </ul>
                </article>

                <article id="2022120700">
                    <h3><a href="#2022120700">2022120700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022120700">TP1A.221005.002.2022120700</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.221205.011.2022120700">TQ1A.221205.011.2022120700</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022120600 release:</p>

                    <ul>
                        <li>Launcher: fix Recent Apps activity crashing when using the TalkBack screen reader due to an incorrect port of the Storage Scopes shortcut to Android 13 QPR1</li>
                    </ul>
                </article>

                <article id="2022120600">
                    <h3><a href="#2022120600">2022120600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022120600">TP1A.221005.002.2022120600</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TQ1A.221205.011.2022120600">TQ1A.221205.011.2022120600</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022120300 release:</p>

                    <ul>
                        <li>full 2022-12-01 security patch level</li>
                        <li>full 2022-12-05 security patch level</li>
                        <li>rebased onto TQ1A.221205.011 release, which is the first quarterly maintenance/feature release for Android 13</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro: rewrite under display fingerprint scanner integration</li>
                        <li>Sandboxed Google Play compatibility layer: set GmsCompat versionCode to 1000 (v1) to prepare for defining dependencies on the compatibility layer version for the Google Play apps mirrored in our app repository</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a: use Scudo instead of hardened_malloc for camera service for consistency with the Pixel 7 and Pixel 7 Pro until memory corruption issues with it are resolved</li>
                        <li>add back support for OS device controls and wallet quick tiles</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision including update to 5.10.152</li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/16">version 16</a></li>
                    </ul>
                </article>

                <article id="2022120300">
                    <h3><a href="#2022120300">2022120300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022120300">TP1A.221005.002.2022120300</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221105.002.2022120300">TP1A.221105.002.2022120300</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.221105.001.2022120300">TD1A.221105.001.2022120300</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022113000 release:</p>

                    <ul>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a): add back our change enabling ARM64_SSBD now that upstream issues with it are resolved for this branch</li>
                        <li>Sandboxed Google Play compatibility layer: avoid chain crash of GmsCompat app following process death from OOM killer, etc.</li>
                        <li>Vanadium: update Chromium base to 108.0.5359.79</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to 5.15.76</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10): update to latest GKI LTS branch revision</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): update Mali GPU driver to r37p0 (current release is r41p0 but there are substantial changes to the driver for the Tensor SoC on Pixels and it will take substantial work to upgrade all the way)</li>
                        <li>remove broken, obsolete upstream code causing install permissions defined by user install apps not being automatically granted for user installed apps installed before the app defining the permissions unless the app is reinstalled</li>
                        <li>Messaging: update MMS configuration database based on Google Messages 20221115_01_RC01</li>
                        <li>Dialer: update visual voicemail (VVM) configuration database based on Google Phone 90.0.477356402</li>
                        <li>Dialer: adjust VVM configuration database entries for compatibility with AOSP</li>
                    </ul>
                </article>

                <article id="2022113000">
                    <h3><a href="#2022113000">2022113000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022113000">TP1A.221005.002.2022113000</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221105.002.2022113000">TP1A.221105.002.2022113000</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.221105.001.2022113000">TD1A.221105.001.2022113000</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022112500 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 108.0.5359.61</li>
                        <li>Pixel 7, Pixel 7 Pro: set QNS package name to fix compatibility issues with Wi-Fi calling</li>
                        <li>kernel (Generic 5.15): update to latest GKI LTS branch revision including update to Linux 5.15.75</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Generic 5.10, Generic 5.15): apply patches for remotely exploitable Bluetooth vulnerabilities (CVE-2022-42895, CVE-2022-42896)</li>
                    </ul>
                </article>

                <article id="2022112500">
                    <h3><a href="#2022112500">2022112500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022112500">TP1A.221005.002.2022112500</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221105.002.2022112500">TP1A.221105.002.2022112500</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.221105.001.2022112500">TD1A.221105.001.2022112500</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022111800 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: fix missing handling of APEX ListSlices in dynamic stubs (improves compatibility when granting Nearby devices permission to Play services with a WearOS device connected)</li>
                        <li>Sandboxed Google Play compatibility layer: mark PackageInstallerStatusForwarder as not exported</li>
                        <li>Settings: avoid OBB toggle unnecessarily force stopping app</li>
                        <li>extend original-package renaming to static launcher shortcuts to fix Vanadium new tab shortcut for users with an install predating the package rename</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/57">version 57</a></li>
                        <li>Vanadium: update Chromium base to 107.0.5304.141</li>
                        <li>Contacts: add support for dark mode</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): restore fix for CVE-2022-3176 which was reverted upstream (GKI LTS branch) due to not being marked as a security fix and changing the GKI ABI</li>
                        <li>Pixel 4, Pixel 4 XL: set frozen patch level string to 2022-11-01 (has been provided since the <a href="#2022110800">2022110800</a> release but we initially left the patch level string at the previous value)</li>
                        <li>port GrapheneOS changes to Linux 5.15 GKI LTS branch in order to prepare for 6th/7th generation Pixels potentially moving to the Linux 5.15 LTS and late 2023 devices which will be based on it</li>
                    </ul>
                </article>

                <article id="2022111800">
                    <h3><a href="#2022111800">2022111800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022111800">TP1A.221005.002.2022111800</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221105.002.2022111800">TP1A.221105.002.2022111800</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.221105.001.2022111800">TD1A.221105.001.2022111800</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022111000 release:</p>

                    <ul>
                        <li>don't skip ahead-of-time (AOT) compilation of apps that weren't recently used since we depend on full AOT compilation being done for performance rather than JIT compilation with background JIT profile guided AOT compilation like Android</li>
                        <li>battery usage UI: use fallback name for unknown components</li>
                        <li>change minimal value of battery saver schedule to 5% again as it was before Android 13</li>
                        <li>enable the post-upgrade "Optimizing apps" progress indication UI</li>
                        <li>app crash UI: show process uptime and optional extra text</li>
                        <li>Sandboxed Google Play compatibility layer: show version of GmsCompatConfig in the crash UI</li>
                        <li>Sandboxed Google Play compatibility layer: stop splitting multi-package PackageInstaller sessions</li>
                        <li>Sandboxed Google Play compatibility layer: improve handling of activity starts</li>
                        <li>Sandboxed Google Play compatibility layer: bugfix: Parcel position wasn't reset by dynamic stubs</li>
                        <li>Sandboxed Google Play compatibility layer: bugfix: missing handling of ListSlices in dynamic stub</li>
                        <li>GmsCompatConfig: make sure Play Store PhenotypeFlags are overridable by Gservices flags (further deterring Play Store trying to update Play services / Play Store beyond supported versions)</li>
                        <li>Pixel 7, Pixel 7 Pro (adevtool): drop unused face unlock components since we have no plans to enable support for an insecure face unlock implementation incapable providing reasonable security due to lack of dedicated face unlock hardware (Pixel 4 and Pixel 4 XL had dual infrared cameras, IR dot projector and IR flood illuminator providing a more secure biometric unlock system than fingerprint unlock as opposed to simply using the front camera in a way that could be done on any device)</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 7, Pixel 7 Pro: include gril library to avoid qns crash on Pixel 7 and Pixel 7 Pro</li>
                        <li>Pixel 7, Pixel 7 Pro: include vendor_kernel_boot partition requirement in factory images metadata to force an error with an incompatible fastboot such as the currently buggy Arch Linux package</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): update GKI to Linux 5.10.150</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/66">version 66</a></li>
                    </ul>
                </article>

                <article id="2022111000">
                    <h3><a href="#2022111000">2022111000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022111000">TP1A.221005.002.2022111000</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221105.002.2022111000">TP1A.221105.002.2022111000</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.221105.001.2022111000">TD1A.221105.001.2022111000</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022110800 release:</p>

                    <ul>
                        <li>remove TrustCor Certificate Authority due to <a href="https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/oxX69KFvsm4">malicious domain squatting and ties to entites involved in surveillance</a> which should have very little impact on web compatibility due to this CA barely being used by anyone other than a specific dynamic DNS provider</li>
                        <li>ignore wireless alert channels being marked as always-on to prevent channel configuration overriding presidential alert toggle</li>
                        <li>GmsCompatConfig: change app label from "GmsCompat config" to "GmsCompatConfig"</li>
                        <li>GmsCompatConfig: disable TelecomTaskService to resolve sandboxed Google Play services crash caused by feature flag</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a): update base kernel to Android 13 QPR1 Beta 3 to ship the December security update and many other search patches early</li>
                        <li>Vanadium: update Chromium base to 107.0.5304.105</li>
                    </ul>
                </article>

                <article id="2022110800">
                    <h3><a href="#2022110800">2022110800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022110800">TP1A.221005.002.2022110800</a> (Pixel 4, Pixel 4 XL) — extended support release for legacy devices with frozen 2022-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221105.002.2022110800">TP1A.221105.002.2022110800</a> (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.221105.001.2022110800">TD1A.221105.001.2022110800</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022110600 release:</p>

                    <ul>
                        <li>full 2022-11-01 security patch level</li>
                        <li>full 2022-11-05 security patch level</li>
                        <li>rebased onto TP1A.221105.002 and TD1A.221105.001 releases</li>
                        <li>DocumentsUI: fix crash in "Get info" screen for images with location metadata caused by upstream bug</li>
                    </ul>
                </article>

                <article id="2022110600">
                    <h3><a href="#2022110600">2022110600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022110600">TP1A.221005.002.2022110600</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.003.2022110600">TP1A.221005.003.2022110600</a> (Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.220804.031.2022110600">TD1A.220804.031.2022110600</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022110400 release:</p>

                    <ul>
                        <li>extend original-package renaming to provider authorities for Vanadium</li>
                        <li>remove upstream workaround added in 2016 for legacy launchers since it creates a device-wide package list leak for apps installed in the owner user when a work profile is active</li>
                        <li>block updates of GSF, Play services and the Play Store by any app other than the GrapheneOS app repository or the Play Store itself to prevent users updating to unsupported versions from Aurora Store or elsewhere before the sandboxed Google Play compatibility layer has well tested official support for them</li>
                        <li>show presidential alerts toggle for all carriers without the alert channels disabled</li>
                    </ul>
                </article>

                <article id="2022110400">
                    <h3><a href="#2022110400">2022110400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022110400">TP1A.221005.002.2022110400</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.003.2022110400">TP1A.221005.003.2022110400</a> (Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.220804.031.2022110400">TD1A.220804.031.2022110400</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022102800 release:</p>

                    <ul>
                        <li>GmsCompatConfig: stub out privileged UserManager.getUserName() needed by a newer version of Play services than we currently mirror in our app repository</li>
                        <li>set up Android 13 QR scan quick tile for GrapheneOS Camera</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): disable BINFMT_MISC</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a): add back our change enabling UNMAP_KERNEL_AT_EL0 now that upstream issues with it are resolved for this branch</li>
                        <li>allow toggling presidential alerts (toggle will not yet be shown for most carriers until the next release)</li>
                        <li>Vanadium: change app id to app.vanadium.browser while using original-package to keep using org.chromium.chrome for existing installs (until factory reset) to preserve compatibility and user data</li>
                        <li>Pixel 7, Pixel 7 Pro: replace UWB and EUICC certificates</li>
                        <li>Messaging: update MMS configuration database based on Google Messages 20221018_01_RC01</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/53">version 53</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/54">version 54</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/55">version 55</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/56">version 56</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/65">version 65</a></li>
                    </ul>
                </article>

                <article id="2022102800">
                    <h3><a href="#2022102800">2022102800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022102800">TP1A.221005.002.2022102800</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.003.2022102800">TP1A.221005.003.2022102800</a> (Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.220804.031.2022102800">TD1A.220804.031.2022102800</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022102600 release:</p>

                    <ul>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): enable DEBUG_SG</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): enable DEBUG_CREDENTIALS</li>
                        <li>Vanadium: update Chromium base to 107.0.5304.91</li>
                        <li>backport many upstream fixes for clat including a more complete set of fixes for the compatibility issue impacting all Android 13 operating systems between VPN lockdown and certain IPv6-only mobile data configurations along with fixing other issues with these setups</li>
                    </ul>
                </article>

                <article id="2022102600">
                    <h3><a href="#2022102600">2022102600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022102600">TP1A.221005.002.2022102600</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.003.2022102600">TP1A.221005.003.2022102600</a> (Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.220804.031.2022102600">TD1A.220804.031.2022102600</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022102300 release:</p>

                    <ul>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): fix upstream compatibility issue preventing using better hashing algorithms than sha1 for kernel module signing with BoringSSL</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): switch from standard GKI kernel module signing (used to enforce protected symbol rules for vendor modules) to forced kernel module signing as an additional lower level layer of security beyond the verification already provided by verified boot and SELinux</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): enable lockdown LSM in forced confidentiality mode as an additional lower level layer of security beyond the verification already provided by verified boot and SELinux</li>
                        <li>Pixel 7, Pixel 7 Pro: handle readlink system call failing in a friendlier way for detection of the camera service executable</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro: add back Pixel charger mode animation override removed in the <a href="#2022101600">2022101600</a> release (fallback images aren't included on the Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7 and Pixel 7 Pro so this was completely missing on those devices)</li>
                        <li>disable unnecessary ldisc_autoload feature (no relevant modules available for it to load anyway)</li>
                        <li>backport fix for crosvm locking up after suspend/resume</li>
                        <li>Vanadium: update Chromium base to 107.0.5304.54</li>
                        <li>Sandboxed Google Play compatibility layer: stop special casing GmsCompat as force queryable by marking that way directly</li>
                        <li>Sandboxed Google Play compatibility layer: improve shim for background activity starts</li>
                        <li>Sandboxed Google Play compatibility layer: add PackageManager.getPackagesForUid() shim</li>
                        <li>Sandboxed Google Play compatibility layer: update link to "Google Location Accuracy" activity to match the style of the Settings app</li>
                        <li>Sandboxed Google Play compatibility layer: add early rejection of getCurrentLocation() requests to avoid unnecessary battery usage and location indicator when we're going to reject the request anyway</li>
                        <li>Sandboxed Google Play compatibility layer: check request granularity when issuing app-op checks to fix a case where apps can be blamed for doing a fine location check when they only did a coarse location check (no user-facing impact since the location history / indicator makes no distinction and it was correctly enforced for permission enforcement already)</li>
                    </ul>
                </article>

                <article id="2022102300">
                    <h3><a href="#2022102300">2022102300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022102300">TP1A.221005.002.2022102300</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.003.2022102300">TP1A.221005.003.2022102300</a> (Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.220804.031.2022102300">TD1A.220804.031.2022102300</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022101800 release:</p>

                    <ul>
                        <li>GmsCompatConfig: stub out privileged BluetoothDevice#setSilenceMode</li>
                        <li>GmsCompatConfig: disable CAST_CONNECTION_NOTIFY popup dialogs</li>
                        <li>GmsCompatConfig: fix crash in FastPair service</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): update GKI to Linux 5.10.149</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro): replace upstream default of sha1 with sha256 for module signing (GKI devices rely on verified boot for vendor modules and only use module signing for GKI modules of which there are currently 0, but it should be using a secure hash in case there are ever GKI modules and for when we extend it to vendor modules as a lower level 2nd layer of security not depending on userspace)</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a): enable forced kernel module signing with a per-build signing key (RSA 4096 / sha256) as an additional lower level layer of security beyond the verification already provided by dm-verity and SELinux</li>
                        <li>kernel (Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a): disable IP_SCTP</li>
                        <li>kernel (Pixel 4a): enable REFCOUNT_FULL</li>
                        <li>Pixel 7, Pixel 7 Pro: fix bug in detection of the camera service executable for the memory corruption workaround added in the previous release (inconsequential in practice for this specific case of the bug)</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro: load AoC firmware via daemon (aocd) to match stock OS</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/64">version 64</a></li>
                    </ul>
                </article>

                <article id="2022101800">
                    <h3><a href="#2022101800">2022101800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022101800">TP1A.221005.002.2022101800</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.003.2022101800">TP1A.221005.003.2022101800</a> (Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.220804.031.2022101800">TD1A.220804.031.2022101800</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022101600 release:</p>

                    <ul>
                        <li>Pixel 7, Pixel 7 Pro: work around memory corruption bug(s) in the camera service by using Scudo instead of hardened_malloc for the camera service process</li>
                        <li>Sandboxed Google Play compatibility layer: fix location rerouting API compatibility issue with the new Play services update that's currently in our app repository Alpha and Beta channels</li>
                        <li>Settings: add PSDS server configuration for Pixel 7 and Pixel 7 Pro</li>
                        <li>Auditor (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a): update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/63">version 63</a></li>
                    </ul>
                </article>

                <article id="2022101600">
                    <h3><a href="#2022101600">2022101600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022101600">TP1A.221005.002.2022101600</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.003.2022101600">TP1A.221005.003.2022101600</a> (Pixel 6a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TD1A.220804.031.2022101600">TD1A.220804.031.2022101600</a> (Pixel 7, Pixel 7 Pro)</li>
                    </ul>

                    <p>Changes since the 2022101500 release:</p>

                    <ul>
                        <li>Vanadium: add back 32-bit WebView support primarily due to a certain F-Droid repository distributing 32-bit-only APKs to save storage space since they lack of split APK support and are incorrectly assuming 64-bit devices support 32-bit apps (Pixel 7 and Pixel 7 Pro have finally dropped 32-bit app support so we'll be able to build and ship 64-bit-only Vanadium on those devices, but we don't want to break existing setups on previous generation devices)</li>
                        <li>don't auto-revoke Sensors/Network permissions when 'freezing' apps with device managers</li>
                        <li>GmsCompatConfig: disable WearableDataListenerService</li>
                        <li>raise minimum supported fastboot version for the factory images flashing scripts to 33.0.3</li>
                        <li>adevtool: exclude additional prebuilt files</li>
                        <li>Auditor (Pixel 7, Pixel 7 Pro): update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/63">version 63</a> (update was not released in time to be bundled with older devices)</li>
                    </ul>
                </article>

                <article id="2022101500">
                    <h3><a href="#2022101500">2022101500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022101500">TP1A.221005.002.2022101500</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.003.2022101500">TP1A.221005.003.2022101500</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022101400 release:</p>

                    <ul>
                        <li>improve wording for sensor access notification</li>
                        <li>use parent profile settings for Sensors permission auto-grant toggle in work profile</li>
                        <li>Sandboxed Google Play compatibility layer: ability to override SharedPreferences-backed PhenotypeFlags</li>
                        <li>Sandboxed Google Play compatibility layer: overhaul reimplementation of the Play services geolocation API used by the default enabled location request rerouting mode to support new APIs added by recent Play services releases along with fixing compatibility issues in the existing implementation</li>
                        <li>raise minimum supported fastboot version for the factory images flashing scripts to 33.0.1 since it will be required for the Pixel 7 and Pixel 7 Pro</li>
                        <li>Settings: backport and configure intent configuration related to styles and wallpaper configuration activities to make the device branch for the Pixel 7 and Pixel 7 Pro easier to maintain</li>
                        <li>prepare for future Pixel 7 and Pixel 7 Pro support by adding them to the device lists for device prototype checks and PSDS configuration</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/61">version 61</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/62">version 62</a></li>
                    </ul>
                </article>

                <article id="2022101400">
                    <h3><a href="#2022101400">2022101400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022101400">TP1A.221005.002.2022101400</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.003.2022101400">TP1A.221005.003.2022101400</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022101200 release:</p>

                    <ul>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a): apply patches for remotely exploitable upstream Linux kernel Wi-Fi vulnerabilities disclosed on October 13th (CVE-2022-41674, CVE-2022-42719, CVE-2022-42720, CVE-2022-42721, CVE-2022-42722) along with additional related fixes</li>
                        <li>revert exploit protection compatibility mode suggestion notification since there are too many false positives and it encourages unnecessarily disabling many of our added exploit protections for an app along with creating the concern that we'll be suggesting disabling protections after they successfully block exploitation</li>
                        <li>Vanadium: update Chromium base to 106.0.5249.126</li>
                        <li>Vanadium: switch to 64-bit only releases without 32-bit WebView support. 32-bit-only apps haven't been obtainable through the Play Store on 64-bit devices since 2021-09-01, haven't been possible to publish since 2019-08-01 and the Pixel 7, Pixel 7 Pro and upcoming Pixel Tablet have fully dropped 32-bit app support. Most of the legacy 32-bit-only apps people want to run are old games which will still work fine since almost none of them require the WebView.</li>
                    </ul>
                </article>

                <article id="2022101200">
                    <h3><a href="#2022101200">2022101200</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022101200">TP1A.221005.002.2022101200</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.003.2022101200">TP1A.221005.003.2022101200</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022100300 release:</p>

                    <ul>
                        <li>notify the user when sensors access is denied by disabled Sensors permission</li>
                        <li>Settings: add a toggle for auto grants of Sensors permission</li>
                        <li>avoid restarting process when Sensors permission is granted since it fully supports runtime toggling</li>
                        <li>add a toggle for turning off auto grant of Network permission to package installation UI</li>
                        <li>don't auto-grant denied special runtime permissions (Sensors, Network) after app data reset</li>
                        <li>Storage Scopes: fix denial of app ops that are allowed by default</li>
                        <li>Storage Scopes: fix showing storage permission prompt in certain cases</li>
                        <li>add notification with suggestion to try exploit protection compatibility mode when apps die in certain ways (will require some thought on wording, etc. to reduce the chance of users enabling this after an actual exploit is successfully mitigated)</li>
                        <li>Sandboxed Google Play compatibility layer: support intercepting SynchronousResultReceiver exceptions</li>
                        <li>Sandboxed Google Play compatibility layer: improve handling of pending intents</li>
                        <li>Sandboxed Google Play compatibility layer: silence notification channels by default</li>
                        <li>Sandboxed Google Play compatibility layer: improve infrastructure for GmsCompatConfig shims</li>
                        <li>Sandboxed Google Play compatibility layer: notify the user that Contacts sync can be enabled</li>
                        <li>Sandboxed Google Play compatibility layer: notify when an app requires the Speech Services app</li>
                        <li>Sandboxed Google Play compatibility layer: fix Google account removal caused by attempt to use privileged APIs leading to an error blocking it</li>
                        <li>GmsCompatConfig: fully disable com.google.android.westworld</li>
                        <li>GmsCompatConfig: disable OS update service to prevent it crashing from lack of access</li>
                        <li>GmsCompatConfig: add BluetoothDevice shims</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a): update GKI base to ASB-2022-10-05_13-5.10</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a): switch back to full LTO from thin LTO now that the compilation compatibility issue is resolved</li>
                        <li>Pixel 4a: raise maximum number of users to 32 to match other devices (was being overridden by device overlay)</li>
                        <li>Dialer: update visual voicemail (VVM) configuration database based on Google Phone 90.0.477356402</li>
                        <li>Messaging: update MMS configuration database based on Google Messages 20220926_01_RC01</li>
                        <li>Vanadium: update Chromium base to 106.0.5249.118</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/52">version 52</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/60">version 60</a></li>
                    </ul>
                </article>

                <article id="2022100300">
                    <h3><a href="#2022100300">2022100300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.002.2022100300">TP1A.221005.002.2022100300</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.221005.003.2022100300">TP1A.221005.003.2022100300</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022092800 release:</p>

                    <ul>
                        <li>full 2022-10-01 security patch level</li>
                        <li>full 2022-10-05 security patch level</li>
                        <li>rebased onto TP1A.221005.003 release</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a): update GKI base to android13-5.10-2022-09_r1 (October maintenance release of September GKI)</li>
                        <li>Vanadium: update Chromium base to 106.0.5249.79</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/59">version 59</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/49">version 49</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/50">version 50</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/51">version 51</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/15">version 15</a></li>
                    </ul>
                </article>

                <article id="2022092800">
                    <h3><a href="#2022092800">2022092800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.2022092800">TP1A.220905.004.2022092800</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A1.2022092800">TP1A.220905.004.A1.2022092800</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A2.2022092800">TP1A.220905.004.A2.2022092800</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022092300 release:</p>

                    <ul>
                        <li>GmsCompatConfig: disable com.google.android.westworld to avoid Play services crashes</li>
                        <li>backport fix for clat on restricted networks (note: does not fix Android 13 compatibility issue between VPN lockdown and certain IPv6 only carrier configurations, which can be worked around by switching to an IPv4/IPv6 APN from a pure IPv6 APN)</li>
                        <li>Sandboxed Google Play compatibility layer: hide Stats Manager service</li>
                        <li>Sandboxed Google Play compatibility layer: don't report CannotDeliverBroadcastException to the user</li>
                        <li>Gallery: hide obsolete menu items</li>
                        <li>Vanadium: update Chromium base to 106.0.5249.65</li>
                        <li>Vanadium: add handling for ACTION_WEB_SEARCH intent</li>
                        <li>QuickSearchBox: drop handling for ACTION_WEB_SEARCH since Vanadium now handles it directly along with certain other browsers like Brave which makes more sense than having a search app pass it to the browser with a separate default search engine</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5, Pixel 5a): rebuild production kernel with updated metadata (no changes to code)</li>
                    </ul>
                </article>

                <article id="2022092300">
                    <h3><a href="#2022092300">2022092300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.2022092300">TP1A.220905.004.2022092300</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A1.2022092300">TP1A.220905.004.A1.2022092300</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A2.2022092300">TP1A.220905.004.A2.2022092300</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022092200 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: add back Bluetooth shim unable to be covered by GmsCompatConfig hooks</li>
                        <li>Sandboxed Google Play compatibility layer: redirect privileged settings APIs to partial implementation by GmsCompat app</li>
                        <li>Sandboxed Google Play compatibility layer: stub out PermissionController activity starts</li>
                        <li>Sandboxed Google Play compatibility layer: prevent triggering throttling of silent package updates</li>
                    </ul>
                </article>

                <article id="2022092200">
                    <h3><a href="#2022092200">2022092200</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.2022092200">TP1A.220905.004.2022092200</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A1.2022092200">TP1A.220905.004.A1.2022092200</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A2.2022092200">TP1A.220905.004.A2.2022092200</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022092000 release:</p>

                    <ul>
                        <li>GmsCompatConfig: set version name based on version code and change app name to a string resource for compatibility with aapt2 retrieval of application-label</li>
                        <li>GmsCompatConfig: fix regressions caused by the port to text file configuration of hooks</li>
                        <li>Sandboxed Google Play compatibility layer: fix regression caused by recent change</li>
                        <li>Sandboxed Google Play compatibility layer: notify about missing battery optimization exception for Play services resulting in delayed push notifications, etc.</li>
                        <li>Settings: show version code, target SDK version, min SDK version, install time and last update time in app info in addition to version name</li>
                    </ul>
                </article>

                <article id="2022092000">
                    <h3><a href="#2022092000">2022092000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.2022092000">TP1A.220905.004.2022092000</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A1.2022092000">TP1A.220905.004.A1.2022092000</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A2.2022092000">TP1A.220905.004.A2.2022092000</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022091400 release:</p>

                    <ul>
                        <li>Storage Scopes: deny storage permissions when Storage Scopes is enabled and then permit enabling storage permissions in combination with it for hybrid setups such as permitting access to all images while using storage scopes for other storage permissions</li>
                        <li>Storage Scopes: improve compatibility with apps checking storage permission app ops for themselves by spoofing the results</li>
                        <li>Sandboxed Google Play compatibility layer: skip app restart after permission grant in some cases</li>
                        <li>Sandboxed Google Play compatibility layer: move many compatibility shims to a text file with the possibility of dynamic updates of GmsCompatConfig along with triggering update checks via Apps after a Play services crash</li>
                        <li>Sandboxed Google Play compatibility layer: move away from deprecated PackageManager APIs</li>
                        <li>Sandboxed Google Play compatibility layer: add report to developers button to Google Play crash notifications</li>
                        <li>Sandboxed Google Play compatibility layer: improve compatibility shims to fix some remaining app compatibility issues</li>
                        <li>add GrapheneOS logo to boot animation</li>
                        <li>Contacts: add themed icon support</li>
                        <li>TalkBack (screen reader): update dependencies</li>
                        <li>Vanadium: update Chromium base to 105.0.5195.136</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/58">version 58</a></li>
                    </ul>
                </article>

                <article id="2022091400">
                    <h3><a href="#2022091400">2022091400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.2022091400">TP1A.220905.004.2022091400</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A1.2022091400">TP1A.220905.004.A1.2022091400</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A2.2022091400">TP1A.220905.004.A2.2022091400</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022091300 release:</p>

                    <ul>
                        <li>hardened_malloc: disable self-init to fix exploit protection compatibility mode which regressed in the previous release</li>
                        <li>Vanadium: update Chromium base to 105.0.5195.124</li>
                        <li>Vanadium: backport fix for favicon links leak</li>
                        <li>Calculator, Clock, Dialer, Files, Gallery, Messaging, Settings: add themed icon support</li>
                        <li>Launcher: disable white gradient at the top of the home screen</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/48">version 48</a></li>
                    </ul>
                </article>

                <article id="2022091300">
                    <h3><a href="#2022091300">2022091300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.2022091300">TP1A.220905.004.2022091300</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A1.2022091300">TP1A.220905.004.A1.2022091300</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.A2.2022091300">TP1A.220905.004.A2.2022091300</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022090600 release:</p>

                    <ul>
                        <li>rebased onto TP1A.220905.004.A2 release</li>
                        <li>hardened_malloc: increase arm64 class region size to 32GB from 2GB to provide higher entropy random bases and higher memory allocation limits since all supported devices have a 48 bit address space now</li>
                        <li>add missing permission to allow Settings search (SettingsIntelligence) to query all apps</li>
                        <li>update GrapheneOS mask used for boot animation</li>
                        <li>change default build target from aosp_arm to aosp_arm64</li>
                        <li>increase maximum users to 32 across all devices since it has been confirmed the Pixel 4 and later support 64 Weaver slots</li>
                        <li>Launcher: set up themed icon support (caveat: we still need to provide themeable icons for the AOSP apps and several of our own apps)</li>
                        <li>implement Android 13 color picker support</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro): switch to raviole kernel/build tag as the base instead of the previously newer bluejay tag</li>
                        <li>Pixel 6, Pixel 6 Pro: update to mid-September TP1A.220905.004.A2 vendor files for Verizon carrier configuration updates</li>
                        <li>Pixel 6a: update to mid-September TP1A.220905.004.A2 vendor files for multiple improvements including the patch for CVE-2022-20231 in the TEE firmware raising patch level from 2022-09-01 to 2022-09-05 like the other devices</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/56">version 56</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/57">version 57</a></li>
                    </ul>
                </article>

                <article id="2022090600">
                    <h3><a href="#2022090600">2022090600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.A1.2022090600">TP1A.220624.021.A1.2022090600</a> (Pixel 6a) — 2022-09-01 patch level until the September AOSP and stock OS release is available for bluejay to provide updated Trusty TEE firmware fixing CVE-2022-20231</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220905.004.2022090600">TP1A.220905.004.2022090600</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022090400 release:</p>

                    <ul>
                        <li>full 2022-09-01 security patch level</li>
                        <li>full 2022-09-05 security patch level</li>
                        <li>rebased onto TP1A.220905.004 release</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a): update GKI base to ASB-2022-09-05_13-5.10</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a): split raviole (Pixel 6, Pixel 6 Pro) and bluejay (Pixel 6a) kernels for now due to AOSP / stock OS differences</li>
                        <li>fix for Bluetooth timeout feature with BLE devices</li>
                        <li>remove conflicting permission from GSF when parsing the package since it appears to be set incorrectly by a build system bug and conflicts with Shannon IMS on 6th generation Pixels and is blocking us upgrading to GSF v33 via our app repository</li>
                        <li>Vanadium: update Chromium base to 105.0.5195.79</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro: use stock OS copyright notices for product/system_ext/vendor instead of AOSP-generated ones since AOSP doesn't have modules with the notices for all of them (September 2022 release is the first release including these notices, which is why the Pixel 6a is not included yet)</li>
                    </ul>
                </article>

                <article id="2022090400">
                    <h3><a href="#2022090400">2022090400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.014.2022090400">TP1A.220624.014.2022090400</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.2022090400">TP1A.220624.021.2022090400</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.A1.2022090400">TP1A.220624.021.A1.2022090400</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022083000 release:</p>

                    <ul>
                        <li>Settings: enable install available apps feature for installing apps in a secondary user profile from the Owner profile</li>
                        <li>System Updater: update target API level to 33</li>
                        <li>System Updater: replace Material library with SettingsLib to match Settings app theme</li>
                        <li>System Updater: add app icon</li>
                        <li>Vanadium: update Chromium base to 105.0.5195.77</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/55">version 55</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/46">version 46</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/47">version 47</a></li>
                    </ul>
                </article>

                <article id="2022083000">
                    <h3><a href="#2022083000">2022083000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.014.2022083000">TP1A.220624.014.2022083000</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.2022083000">TP1A.220624.021.2022083000</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.A1.2022083000">TP1A.220624.021.A1.2022083000</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022082400 release:</p>

                    <ul>
                        <li>add per-app toggle to relax memory corruption exploit protections for an app to allow users to work around buggy apps with latent bugs including many games like Diablo Immortal (uses 39-bit address space and Scudo instead of 48-bit address space and hardened_malloc along with forcing exec spawning for the app since the Zygote is always fully hardened)</li>
                        <li>Sandboxed Google Play compatibility layer: expand existing shims to further improve compatibility</li>
                        <li>improve infrastructure for GrapheneOS package state</li>
                        <li>improve safety of factory images flashing scripts by flashing the SoC firmware to the inactive slot, switching it to active, rebooting to it and then repeating the same thing again to get the current firmware flashed and safely boot tested for both slots (this provides a high level of safety for devices like 6th generation Pixels doing boot chain anti-rollback despite the fact that they neglected to provide firmware handling flashing safely)</li>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a: erase DPM partitions in factory images flashing scripts</li>
                        <li>drop unused flash-base.sh from factory images to reduce maintenance burden for our safer flashing procedure</li>
                        <li>System Updater: catch ServiceSpecificException thrown by UpdateEngine.applyPayload(...) in some cases to properly report the error via a notification</li>
                        <li>System Updater: reduce connect/read timeouts from 60s to 30s</li>
                        <li>carriersettings-extractor: fix handling currently mostly unused field (not going to make any difference to users in practice, but may become more relevant in the future)</li>
                        <li>Seedvault: fix apk backups on Android 13</li>
                        <li>Storage Scopes: add support for Android 13 image picker</li>
                        <li>Storage Scopes: add link to storage scopes configuration from launcher recent apps activity for apps with it enabled for convenient configuration of file/directory scopes</li>
                        <li>improve app compatibility with Network toggle for DownloadManager and NsdManager</li>
                        <li>use 1.1.1.1 instead of 8.8.8.8 as the arbitrary IP for MTU detection in CLAT initialization (could be made configurable in the future)</li>
                        <li>Vanadium: update Chromium base to 105.0.5195.68</li>
                    </ul>
                </article>

                <article id="2022082400">
                    <h3><a href="#2022082400">2022082400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.014.2022082400">TP1A.220624.014.2022082400</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.2022082400">TP1A.220624.021.2022082400</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.A1.2022082400">TP1A.220624.021.A1.2022082400</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022082301 release:</p>

                    <ul>
                        <li>Pixel 6, Pixel 6 Pro, Pixel 6a: rewrite under display fingerprint scanner integration</li>
                        <li>Sandboxed Google Play compatibility layer: don't report spurious DeadSystemRuntimeException exceptions</li>
                        <li>Contacts: stop hiding local storage when a Google account is present in the profile and no contacts are saved locally</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5, Pixel 5a): add several changes missed in Android 13 port (which is why we didn't push out the last release for them)</li>
                    </ul>
                </article>

                <article id="2022082301">
                    <h3><a href="#2022082301">2022082301</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li>TP1A.220624.014.2022082301 (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li>TP1A.220624.021.2022082301 (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.A1.2022082301">TP1A.220624.021.A1.2022082301</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022082300 release:</p>

                    <ul>
                        <li>Seedvault: add missing notification permission</li>
                        <li>pre-grant notification permission to Contacts, Apps, Camera, Auditor and Seedvault</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a): patch CVE-2022-2588 which is not exposed to anything other than the privileged (CAP_NET_ADMIN) netd process, network HALs (Bluetooth, Wi-Fi, cellular, etc.) and network helper services within the OS such as ppp</li>
                        <li>Pixel 6, Pixel 6a, Pixel 6 Pro: fix Wi-Fi HAL configuration to fix Wi-Fi hotspot</li>
                        <li>Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, Pixel 6a: fix inclusion of our kernel builds in published manifest</li>
                    </ul>
                </article>

                <article id="2022082300">
                    <h3><a href="#2022082300">2022082300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.014.2022082300">TP1A.220624.014.2022082300</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.2022082300">TP1A.220624.021.2022082300</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.A1.2022082300">TP1A.220624.021.A1.2022082300</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022082200 release:</p>

                    <ul>
                        <li>add back LTE only mode support for world mode (dual CDMA + GSM networks)</li>
                        <li>ThemePicker: add missing null check for Monet toggle</li>
                        <li>grant notifications permission to System Updater by default for fresh installs</li>
                    </ul>
                </article>

                <article id="2022082200">
                    <h3><a href="#2022082200">2022082200</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.014.2022082200">TP1A.220624.014.2022082200</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.2022082200">TP1A.220624.021.2022082200</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.A1.2022082200">TP1A.220624.021.A1.2022082200</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022082100 release:</p>

                    <ul>
                        <li>pre-grant notifications permission to the Clock app</li>
                        <li>fix automatic notification grants</li>
                        <li>Clock: use correct intent for opening notification settings</li>
                        <li>Clock: protect broadcast receivers including not allowing other apps to snooze or dismiss alarms (upstream problem)</li>
                        <li>Contacts: fix VCF import due by removing obsolete READ_EXTERNAL_STORAGE permission usage</li>
                        <li>Theme Picker: fix our added wallpaper color scheme toggle not showing updated status</li>
                        <li>Sandboxed Google Play compatibility layer: disable Play services promotion of exposure notification feature unless the user grants Location access since this crashes with the default/normal state of Location not being granted to Play services (normal privileged Play services cannot have Location revoked so it doesn't handle this properly across multiple areas and we have multiple compatibility shims for it)</li>
                    </ul>
                </article>

                <article id="2022082100">
                    <h3><a href="#2022082100">2022082100</a></h3>

                    <p>This is the initial release of GrapheneOS based on Android 13. All of our
                    features have been ported to Android 13. We've made many improvements as part
                    of porting to Android 13 including improved compatibility for the Google Play
                    compatibility layer.</p>

                    <p>For a great overview of the new improvements in Android 13, check out the
                    great <a href="https://blog.esper.io/android-13-deep-dive/">Android 13
                    changelog article from esper</a>. We don't document the Android Open Source
                    Project (AOSP) changes in our release notes beyond noting the version upgrades
                    and our changes made in response to AOSP changes.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.014.2022082100">TP1A.220624.014.2022082100</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.2022082100">TP1A.220624.021.2022082100</a> (Pixel 6, Pixel 6 Pro)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/TP1A.220624.021.A1.2022082100">TP1A.220624.021.A1.2022082100</a> (Pixel 6a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022081800 release:</p>

                    <ul>
                        <li>rebased onto TP1A.220624.021.A1 release</li>
                        <li>full port of <a href="/features">all existing GrapheneOS features</a> to Android 13</li>
                        <li>full 2022-08-05 security patch level</li>
                        <li>enable Android 13 location indicator feature by default as a replacement for the earlier location indicators we had enabled (on the stock OS this is an opt-in developer option only shown if a feature flag is enabled)</li>
                        <li>change new location indicators to show all location accesses instead of only showing high power (GNSS) accesses (preserves existing GrapheneOS behavior)</li>
                        <li>change new location indicators to show for all apps instead of only user installed apps (preserves existing GrapheneOS behavior)</li>
                        <li>show system app location access history by default rather than requiring opt-in (preserves existing GrapheneOS behavior)</li>
                        <li>Sandboxed Google Play compatibility layer: add more shims to further improve compatibility</li>
                        <li>fix issue with prototype device check causing the warning to be shown on non-Pixel phones without the <code>ro.boot.secure_boot</code> property</li>
                        <li>add back AvoidAppsInCutoutOverlay since this cutout mode is no longer broken on Android 13</li>
                        <li>fix upstream Android 13 user logout bug causing end session to be broken</li>
                        <li>drop workaround for slow lockscreen animation which is fixed in Android 13</li>
                        <li>drop workaround for SystemUI ANR (App Not Responding) false positives caused by screenshot service in Android 12</li>
                        <li>Vanadium: revert removal of mremap system call from the sandbox allowlist for now since libc is using it internally</li>
                        <li>Dialer: temporarily disable R8 optimization to work around missing annotations / exceptions upstream</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a): switch to kernel manifests instead of including the kernel source trees in the OS source tree with submodules for the module repositories</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a): switch to AOSP kernel build system</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a): use dynamic kernel modules matching AOSP / stock OS instead of using monolithic kernel builds to avoid further issues from driver bugs with monolithic kernel builds (this was a useful feature but maintenance has become too difficult and the advantages of Generic Kernel Images for 6th generation Pixels and beyond outweigh the benefits so this was already phased out for 6th generation devices)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro, Pixel 6a): temporarily use ThinLTO instead of LTO due to an upstream kernel or toolchain bug we have yet to resolve or work around in a better way</li>
                    </ul>
                </article>

                <article id="2022081800">
                    <h3><a href="#2022081800">2022081800</a></h3>

                    <p>This is the final release of GrapheneOS based on Android 12.1. Android 13
                    was released on August 15th and GrapheneOS is now fully focused on our port to
                    Android 13. We aim to release GrapheneOS based on Android 13 before the end of
                    August. We've fulfilled our commitment to providing extended support releases
                    for the end-of-life 3rd generation Pixels until the next major OS release and
                    all users on those devices should have moved to devices receiving full privacy
                    and security updates such as the highly recommended 6th generation Pixels with
                    at least 5 years of full security support from launch. After we finish porting
                    GrapheneOS to Android 13, we may continue extended support releases for legacy
                    3rd generation Pixels based on Android 12.1 in a more limited capacity, but we
                    haven't determined how we'll handle it going forward.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022081800">SP1A.210812.016.C2.2022081800</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022081800">SP2A.220505.006.2022081800</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SD2A.220601.004.B2.2022081800">SD2A.220601.004.B2.2022081800</a> (Pixel 6a) — early release for Pixel 6a with 2022-06-01 patch level which is the latest available until there's a normal AOSP / stock OS release for it on the latest patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022081800">SQ3A.220705.003.A1.2022081800</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.004.2022081800">SQ3A.220705.004.2022081800</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022081600 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: conditionally stub out LocationManager#requestLocationUpdates() to avoid crashes from not having the Location permission granted (cannot be revoked on stock OS due to stock OS using Play services as a backend) which started happening with the deployment of a Play services change via a feature flag to a subset of users and will likely ramp up soon</li>
                    </ul>
                </article>

                <article id="2022081600">
                    <h3><a href="#2022081600">2022081600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022081600">SP1A.210812.016.C2.2022081600</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022081600">SP2A.220505.006.2022081600</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SD2A.220601.004.B2.2022081600">SD2A.220601.004.B2.2022081600</a> (Pixel 6a) — early release for Pixel 6a with 2022-06-01 patch level which is the latest available until there's a normal AOSP / stock OS release for it on the latest patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022081600">SQ3A.220705.003.A1.2022081600</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.004.2022081600">SQ3A.220705.004.2022081600</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022080900 release:</p>

                    <ul>
                        <li>ship our frameworks/av changes as intended in earlier releases</li>
                        <li>fastbootd: stop displaying serial number since it can already be obtained in fastboot mode and users are prone to leaking this by sharing a photo of the screen in these modes</li>
                        <li>Vanadium: backport using Android 13 SDK and changes to support using Android 13</li>
                        <li>Vanadium: update Chromium base to 104.0.5112.97</li>
                        <li>Vanadium: restore previous launcher icon</li>
                        <li>Pixel 6a: switch to SD2A.220601.004.B2 (July 2022) device sources and vendor files (AOSP / stock OS patch level for Pixel 6a is still 2022-06-01 until Android 13)</li>
                    </ul>
                </article>

                <article id="2022080900">
                    <h3><a href="#2022080900">2022080900</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022080900">SP1A.210812.016.C2.2022080900</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022080900">SP2A.220505.006.2022080900</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SD2A.220601.004.2022080900">SD2A.220601.004.2022080900</a> (Pixel 6a) — early release for Pixel 6a with 2022-06-01 patch level which is the latest available until there's a normal AOSP / stock OS release for it on the latest patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022080900">SQ3A.220705.003.A1.2022080900</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.004.2022080900">SQ3A.220705.004.2022080900</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022080500 release:</p>

                    <ul>
                        <li>update displayed patch level since we shipped all the 2022-08-01 patches in the previous release without changing the displayed patch level</li>
                        <li>allow selecting the Download directory via Storage Scopes</li>
                        <li>Sandboxed Google Play compatibility layer: stub out getPrivilegedConfiguredNetworks() to fix sharing Wi-Fi credentials with a WearOS device and other features</li>
                        <li>Sandboxed Google Play compatibility layer: add workaround for another power exemption whitelist use tied to WearOS</li>
                        <li>Sandboxed Google Play compatibility layer: notify the user about GMS crashes</li>
                        <li>Sandboxed Google Play compatibility layer: improved robust / future proofing</li>
                        <li>Sandboxed Google Play compatibility layer: add support for installing Google Chrome via Play Store via the unprivileged package installation API by safely breaking up the multi-package session</li>
                        <li>Sandboxed Google Play compatibility layer: improve compatibility with Nearby Share</li>
                        <li>exec spawning: don't close binder connection when an app crashes to fix debugging features including the crash dialog</li>
                    </ul>
                </article>

                <article id="2022080500">
                    <h3><a href="#2022080500">2022080500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022080500">SP1A.210812.016.C2.2022080500</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022080500">SP2A.220505.006.2022080500</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SD2A.220601.004.2022080500">SD2A.220601.004.2022080500</a> (Pixel 6a) — early release for Pixel 6a with 2022-06-01 patch level which is the latest available until there's a normal AOSP / stock OS release for it on the latest patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022080500">SQ3A.220705.003.A1.2022080500</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.004.2022080500">SQ3A.220705.004.2022080500</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022080300 release:</p>

                    <ul>
                        <li>full 2022-08-01 security patch level (note: displayed patch level will be updated in the next release)</li>
                        <li>partial 2022-08-05 security patch level (full set of fixes aren't public yet due to the August release of AOSP and the stock Pixel OS being delayed)</li>
                        <li>rebased onto SQ3A.220705.004 release</li>
                        <li>improve compatibility of our fix for the upstream step counter/detector privacy issue for API &lt; 29 apps by using our OTHER_SENSORS (Sensors toggle) permission for it</li>
                    </ul>
                </article>

                <article id="2022080300">
                    <h3><a href="#2022080300">2022080300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022080300">SP1A.210812.016.C2.2022080300</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022080300">SP2A.220505.006.2022080300</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SD2A.220601.004.2022080300">SD2A.220601.004.2022080300</a> (Pixel 6a) — early release for Pixel 6a with 2022-06-01 patch level which is the latest available until there's a normal AOSP / stock OS release for it on the latest patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022080300">SQ3A.220705.003.A1.2022080300</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022073000 release:</p>

                    <ul>
                        <li>overhaul the implementation of multiple features to prepare for the Android 13 migration</li>
                        <li>fix enabling VPN always on and lockdown by default before the first reboot after the VPN is added</li>
                        <li>fix for Bluetooth timeout feature with BLE devices</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro): update GKI base to ASB-2022-08-05_12-5.10</li>
                        <li>Vanadium: update Chromium base to 104.0.5112.69</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/45">version 45</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/54">version 54</a></li>
                    </ul>
                </article>

                <article id="2022073000">
                    <h3><a href="#2022073000">2022073000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022073000">SP1A.210812.016.C2.2022073000</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022073000">SP2A.220505.006.2022073000</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SD2A.220601.004.2022073000">SD2A.220601.004.2022073000</a> (Pixel 6a) — early release for Pixel 6a with 2022-06-01 patch level which is the latest available until there's a normal AOSP / stock OS release for it on the latest patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022073000">SQ3A.220705.003.A1.2022073000</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022072700 release:</p>

                    <ul>
                        <li>add support for Pixel 6a</li>
                        <li>fix regression caused by spoofing INTERNET permission self checks when the Network toggle is disabled by still reporting connectivity is unavailable as before</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/53">version 53</a></li>
                        <li>Pixel 6, Pixel 6 Pro: add missing google_dock kernel module which we were building but not including in the official builds</li>
                    </ul>
                </article>

                <article id="2022072700">
                    <h3><a href="#2022072700">2022072700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022072700">SP1A.210812.016.C2.2022072700</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022072700">SP2A.220505.006.2022072700</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022072700">SQ3A.220705.003.A1.2022072700</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022072000 release:</p>

                    <ul>
                        <li>improve compatibility with apps when the Network toggle is disabled by pretending INTERNET is still granted as a permission for self checks of the permission</li>
                        <li>Sandboxed Google Play compatibility layer: avoid crash in TelephonyManager#getCallState()</li>
                        <li>Sandboxed Google Play compatibility layer: handle updating power allowlist in broadcast PendingIntents</li>
                        <li>reorganize Storage Scopes implementation</li>
                        <li>enforce ACTIVITY_RECOGNITION sensor permission for target API &lt; 29 apps (fixes upstream Android privacy flaw)</li>
                        <li>do not forward notifications from foreground user</li>
                    </ul>
                </article>

                <article id="2022072000">
                    <h3><a href="#2022072000">2022072000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022072000">SP1A.210812.016.C2.2022072000</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022072000">SP2A.220505.006.2022072000</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022072000">SQ3A.220705.003.A1.2022072000</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022071300 release:</p>

                    <ul>
                        <li>fix Storage Scopes feature with system gallery app</li>
                        <li>skip triggering permission prompts from apps requesting storage permissions when Scoped Storage is enabled since some apps request permissions even when the system tells the app they have the permissions</li>
                        <li>reduce minimum Night Light color temperature from 2596K to 686K</li>
                        <li>Vanadium: update Chromium base to 103.0.5060.129</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/52">version 52</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/44">version 44</a></li>
                    </ul>
                </article>

                <article id="2022071300">
                    <h3><a href="#2022071300">2022071300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022071300">SP1A.210812.016.C2.2022071300</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022071300">SP2A.220505.006.2022071300</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022071300">SQ3A.220705.003.A1.2022071300</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022071100 release:</p>

                    <ul>
                        <li>do not forward other forwarded notifications between users</li>
                        <li>add learn more link to the GrapheneOS documentation for the Storage Scopes feature</li>
                        <li>Sandboxed Google Play compatibility layer: add a non-user-facing option to allow the Play Store to update itself and Play services</li>
                        <li>Sandboxed Google Play compatibility layer: conditionally stub out TelephonyManager##registerTelephonyCallback to make the Phone permission optional for the device discovery service</li>
                    </ul>
                </article>

                <article id="2022071100">
                    <h3><a href="#2022071100">2022071100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022071100">SP1A.210812.016.C2.2022071100</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022071100">SP2A.220505.006.2022071100</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022071100">SQ3A.220705.003.A1.2022071100</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022070800 release:</p>

                    <ul>
                        <li>fix adding access to files with our Storage Scopes feature on devices using the new shared storage implementation (Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro)</li>
                        <li>improve permission UI instructing the user to revoke all storage permissions before enabling storage scopes</li>
                        <li>Sandboxed Google Play compatibility layer: unblock Play Store installing Play Store and Play services in order to allow it to fetch additional split APK components</li>
                        <li>Sandboxed Google Play compatibility layer: disable Play Store updates for Play Store and Play services to replace blocking installation as a friendlier approach to preventing it from taking over these updates without the downsides of blocking installation</li>
                        <li>Sandboxed Google Play compatibility layer: disable Play Store attempting to auto-install components like Play Services for AR since the request for approval is an annoyance</li>
                        <li>Settings: do not initialize OBB toggle for non-attachable (privileged) apps</li>
                    </ul>
                </article>

                <article id="2022070800">
                    <h3><a href="#2022070800">2022070800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022070800">SP1A.210812.016.C2.2022070800</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022070800">SP2A.220505.006.2022070800</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022070800">SQ3A.220705.003.A1.2022070800</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022070600 release:</p>

                    <ul>
                        <li>add new Storage Scopes feature for granting limited access to shared storage for apps normally requiring granting the storage permission (Files and Media for legacy apps, Media for modern apps), the file management special access permission (All files access) or the media management special access permission where these apps will think they've been granted those permissions but will only have access to specific scopes you've chosen to grant to them, as if they supported granting case-by-case consent through the system file manager themselves (which is not impacted by this feature and you can still grant case-by-case access to any file / directory through it)</li>
                        <li>split out a new toggle for OBB (Opaque Binary Blob) installation (legacy approach to distributing large assets primarily used by games) so that the Play Store and other app stores with asset delivery support can be granted OBB access instead of Media access (or Files and Media for legacy apps)</li>
                        <li>fix upstream Android bug in DeviceIdleJobsController which was preventing battery optimization exceptions from fully working for system apps and resulting in delays in some cases for the Messaging app and other system apps</li>
                        <li>respect user switchability for forwarded notification UI</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro): update GKI base to ASB-2022-07-05_12-5.10</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a): drop unnecessary NETLABEL feature</li>
                    </ul>
                </article>

                <article id="2022070600">
                    <h3><a href="#2022070600">2022070600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022070600">SP1A.210812.016.C2.2022070600</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022070600">SP2A.220505.006.2022070600</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220705.003.A1.2022070600">SQ3A.220705.003.A1.2022070600</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022063000 release:</p>

                    <ul>
                        <li>full 2022-07-01 security patch level</li>
                        <li>full 2022-07-05 security patch level</li>
                        <li>rebased onto SQ3A.220705.003.A1 release</li>
                        <li>Vanadium: update Chromium base to 103.0.5060.71</li>
                    </ul>
                </article>

                <article id="2022063000">
                    <h3><a href="#2022063000">2022063000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C2.2022063000">SP1A.210812.016.C2.2022063000</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022063000">SP2A.220505.006.2022063000</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220605.009.A1.2022063000">SQ3A.220605.009.A1.2022063000</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220605.009.B1.2022063000">SQ3A.220605.009.B1.2022063000</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022062200 release:</p>

                    <ul>
                        <li>add opt-in support for forwarding notifications to the active user from users in the background with information censored in the same way as on the lockscreen (can be enabled in <b>Settings&#160;<span aria-label="and then">></span> System&#160;<span aria-label="and then">></span> Multiple users</b> for each user you want to forward their notifications)</li>
                        <li>set correct tile label for our battery share quick tile</li>
                        <li>Vanadium: update Chromium base to 103.0.5060.70</li>
                        <li>Vanadium: disable reporting support (Report-To, report-uri) again</li>
                        <li>Vanadium: add toggle for closing tabs on exit</li>
                        <li>Vanadium: add toggle for opening external links in Incognito by default (does not currently include custom tabs)</li>
                        <li>Vanadium: add toggle for WebRTC IP handling policy so that users can use a less strict value than our default disabling non-proxied (peer-to-peer) WebRTC completely</li>
                        <li>Pixel 3, Pixel 3 XL: switch to SP1A.210812.016.C2 (June 2022) vendor files</li>
                    </ul>
                </article>

                <article id="2022062200">
                    <h3><a href="#2022062200">2022062200</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022062200">SP1A.210812.016.C1.2022062200</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022062200">SP2A.220505.006.2022062200</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220605.009.A1.2022062200">SQ3A.220605.009.A1.2022062200</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220605.009.B1.2022062200">SQ3A.220605.009.B1.2022062200</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022061600 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 103.0.5060.53</li>
                        <li>implement reverse wireless charging feature for devices supporting it</li>
                    </ul>
                </article>

                <article id="2022061600">
                    <h3><a href="#2022061600">2022061600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022061600">SP1A.210812.016.C1.2022061600</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022061600">SP2A.220505.006.2022061600</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-06-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220605.009.A1.2022061600">SQ3A.220605.009.A1.2022061600</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220605.009.B1.2022061600">SQ3A.220605.009.B1.2022061600</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022060701 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: make dynamite module loading shims less intrusive</li>
                        <li>Sandboxed Google Play compatibility layer: allow Vanadium to use GMS FIDO2 implementation</li>
                        <li>Vanadium: update Chromium base to 102.0.5005.125</li>
                        <li>Vanadium: enable process isolated sandboxed iframes by default</li>
                        <li>Vanadium: replace global JIT toggle with a site setting with global configuration for the default and per-site overrides</li>
                        <li>Vanadium: disable JIT compiler by default</li>
                        <li>Vanadium: remove mremap from system call whitelist</li>
                        <li>add indicator exemption for OS cell broadcast service which uses location services to determine if alerts should be shown</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL: update end-of-life kernel source tree with backported patches</li>
                        <li>enable always-on VPN and lockdown mode by default when adding a VPN</li>
                        <li>add warning notification about insecure prototype Pixel devices since users are ending up getting prototype phones second hand that were stolen or sold by employees instead of returning / disposing of them (this is of course much more robustly detected by Auditor for users verifying with it)</li>
                        <li>Pixel 4a (5G), Pixel 5, Pixel 5a: update kernel build tools revision</li>
                    </ul>
                </article>

                <article id="2022060701">
                    <h3><a href="#2022060701">2022060701</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022060701">SP1A.210812.016.C1.2022060701</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022060701">SP2A.220505.006.2022060701</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-05-05 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220605.009.A1.2022060701">SQ3A.220605.009.A1.2022060701</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220605.009.B1.2022060701">SQ3A.220605.009.B1.2022060701</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022060700 release:</p>

                    <ul>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro: update adevtool state</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/51">version 51</a></li>
                        <li>kernel (Pixel 4a (5G), Pixel 5, Pixel 5a): temporarily disable slab canary feature added by GrapheneOS due to an upstream commit incompatible with it until we find the underlying upstream bug, which we're now much closer to understanding with this latest case</li>
                    </ul>
                </article>

                <article id="2022060700">
                    <h3><a href="#2022060700">2022060700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022060700">SP1A.210812.016.C1.2022060700</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.006.2022060700">SP2A.220505.006.2022060700</a> (Pixel 3a, Pixel 3a XL) — extended support release for legacy devices with frozen 2022-05-05 patch level (will be increased to 2022-06-01 in an upcoming release)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220605.009.A1.2022060700">SQ3A.220605.009.A1.2022060700</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ3A.220605.009.B1.2022060700">SQ3A.220605.009.B1.2022060700</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022053100 release:</p>

                    <ul>
                        <li>full 2022-06-01 security patch level</li>
                        <li>full 2022-06-05 security patch level</li>
                        <li>rebased onto SQ3A.220605.009.B1 release, which is the third quarterly maintenance/feature release for Android 12</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro): update GKI base to ASB-2022-06-05_12-5.10</li>
                        <li>Sandboxed Google Play compatibility layer: remove obsolete shims and infrastructure</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/42">version 42</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/43">version 43</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/49">version 49</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/50">version 50</a></li>
                        <li>SELinux policy: remove unused domain for com.android.vzwomatrigger</li>
                        <li>add indicator exemption for Fused Location Provider which is part of the OS location implementation wrapping the GNSS and Network location providers into a Fused provider using the best available data (GrapheneOS does not have an OS Network Location provider so it just wraps GNSS)</li>
                        <li>remove unused android-prepare-vendor repository from the main branch (kept in legacy device branches)</li>
                        <li>hardened_malloc: remove workarounds for camera service bugs for the Qualcomm SoC generation used by 3rd generation Pixels (kept in legacy device branches)</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a): drop IPv6 privacy address fix now that upstream has backported IPv6 temporary address (RFC4941) support as a replacement which we already did for 5th generation Pixels (implemented in the baseline kernel.org LTS for 6th generation)</li>
                    </ul>
                </article>

                <article id="2022053100">
                    <h3><a href="#2022053100">2022053100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022053100">SP1A.210812.016.C1.2022053100</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.002.2022053100">SP2A.220505.002.2022053100</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022052500 release:</p>

                    <ul>
                        <li>extend Network/Sensors permission handling for legacy apps not targeting Android 6 or above (API 23) to resolve a UI issue where the user choosing to grant the Network/Sensors permissions via the legacy permission review interface doesn't appear in the Settings app info page</li>
                        <li>Gallery: use date added as a fallback for sort order when date taken is unset which is particularly important on GrapheneOS due to GrapheneOS Camera and GrapheneOS screenshots not including EXIF timestamps or other sensitive metadata by default</li>
                        <li>Sandboxed Google Play compatibility layer: stub out reads of privileged settings values to avoid security exceptions</li>
                        <li>Sandboxed Google Play compatibility layer: stub out privileged media session management functionality to avoid security exceptions</li>
                        <li>Sandboxed Google Play compatibility layer: simplify implementation of many shims and remove obsolete shims</li>
                        <li>Sandboxed Google Play compatibility layer: simplify implementation of adding the standard unprivileged package permissions as requested permissions for the Play Store</li>
                        <li>Sandboxed Google Play compatibility layer: improve compatibility with Google Search app</li>
                        <li>Contacts: don't prompt to add account when creating a contact</li>
                        <li>Contacts: use common intent for getting directions instead of opening a Google Maps URL</li>
                        <li>Messaging: backport change to allow selecting text inside the selected message</li>
                        <li>fix upstream SMS/MMS database upgrade issue (meant to be shipped in a previous GrapheneOS release)</li>
                        <li>backport fix for unnecessary wake lock in telephony service (meant to be shipped in a previous GrapheneOS release)</li>
                        <li>backport fix for crash in telephony service with null subscription display name (meant to be shipped in a previous GrapheneOS release)</li>
                        <li>Dialer: add missing permission declaration</li>
                        <li>Vanadium: update Chromium base to 102.0.5005.78</li>
                        <li>TalkBack (screen reader): update base code to 12.2 and switch versioning scheme</li>
                        <li>TalkBack (screen reader): update dependencies</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/41">version 41</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/48">version 48</a></li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/7">version 7</a></li>
                    </ul>
                </article>

                <article id="2022052500">
                    <h3><a href="#2022052500">2022052500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022052500">SP1A.210812.016.C1.2022052500</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.002.2022052500">SP2A.220505.002.2022052500</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022051100 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: improve compatibility with the Nearby Share feature</li>
                        <li>Sandboxed Google Play compatibility layer: add non-privileged approach for bringing apps out of standby to avoid delays for FCM and other features</li>
                        <li>Sandboxed Google Play compatibility layer: extend compatibility layer to support making the Google Search app work as a regular sandboxed app</li>
                        <li>Sandboxed Google Play compatibility layer: generic telephony compatibility improvement</li>
                        <li>Sandboxed Google Play compatibility layer: add support for Play Store in Direct Boot mode</li>
                        <li>add indicator exemption for Default Print Service since the nearby device access is considered location access but it doesn't make sense to show this for a core OS component only using the access internally</li>
                        <li>add toggle for disallowing a user from installing apps from unknown sources which will become increasingly useful as we flesh out our app repository</li>
                        <li>Messaging: fix notification sounds in secondary users (upstream AOSP bug)</li>
                        <li>Vanadium: update Chromium base to 102.0.5005.59</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/35">version 35</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/36">version 36</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/37">version 37</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/38">version 38</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/39">version 39</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/40">version 40</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/46">version 46</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/47">version 47</a></li>
                    </ul>
                </article>

                <article id="2022051100">
                    <h3><a href="#2022051100">2022051100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022051100">SP1A.210812.016.C1.2022051100</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.002.2022051100">SP2A.220505.002.2022051100</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022050800 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer (GmsCompat): further improve location rerouting compatibility</li>
                        <li>Sandboxed Google Play compatibility layer (GmsCompat): add logging to help with debugging issues with location rerouting in the future</li>
                        <li>Vanadium: update Chromium base to 101.0.4951.61</li>
                        <li>improve compatibility with buggy apps trying to use the non-existent OS network location provider when it isn't available and reroute them to the passive provider</li>
                        <li>add hidden setting for sandboxed Google Play compatibility layer developers to bypass blocking the Play Store from updating the Google Play apps</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/34">version 34</a></li>
                    </ul>
                </article>

                <article id="2022050800">
                    <h3><a href="#2022050800">2022050800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022050800">SP1A.210812.016.C1.2022050800</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.002.2022050800">SP2A.220505.002.2022050800</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022050700 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer (GmsCompat): restore compatibility of location rerouting with old versions of the Play services client library</li>
                        <li>Sandboxed Google Play compatibility layer: fix minor background activity UX regression from several releases ago</li>
                        <li>fix adding emergency contacts</li>
                        <li>adevtool: detect outdated Node.js and report an error</li>
                    </ul>
                </article>

                <article id="2022050700">
                    <h3><a href="#2022050700">2022050700</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022050700">SP1A.210812.016.C1.2022050700</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.002.2022050700">SP2A.220505.002.2022050700</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022050301 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer (GmsCompat): significantly improve compatibility of the default enabled geolocation API rerouting feature</li>
                        <li>remove timestamp from screenshot EXIF metadata by default and add a toggle to <b>Settings&#160;<span aria-label="and then">></span> Privacy</b> for enabling it</li>
                        <li>work around slow unlock animation</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro): update GKI base to ASB-2022-05-05_12-5.10</li>
                        <li>Dialer: add fixes for Bluetooth audio call redirection and BLE devices</li>
                        <li>Settings: fix Wi-Fi timeout string issue in Settings search</li>
                        <li>Settings: add missing face unlock strings (used by the Pixel 4 and Pixel 4 XL but the fix is generic)</li>
                        <li>Pixel 6, Pixel 6 Pro: fix Settings string for boosted color mode</li>
                        <li>restore compatibility with non-bash /bin/sh for *nix factory images flashing script (was fixed for the previous release's factory images after the release was initially published)</li>
                        <li>TalkBack (screen reader): update Material library</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/31">version 31</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/32">version 32</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/33">version 33</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/14">version 14</a></li>
                        <li>adevtool (Pixel 4a): drop unused non-flattened APEX from vendor</li>
                        <li>adevtool: improve Android 13 compatibility</li>
                    </ul>
                </article>

                <article id="2022050301">
                    <h3><a href="#2022050301">2022050301</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022050301">SP1A.210812.016.C1.2022050301</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.002.2022050301">SP2A.220505.002.2022050301</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022050300 release:</p>

                    <ul>
                        <li>add Phone services privacy indicator exemption since the cellular service information it accesses is now considered location information and triggers a spurious location indicator which doesn't make sense for the OS cellular implementation</li>
                    </ul>
                </article>

                <article id="2022050300">
                    <h3><a href="#2022050300">2022050300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022050300">SP1A.210812.016.C1.2022050300</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220505.002.2022050300">SP2A.220505.002.2022050300</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022043000 release:</p>

                    <ul>
                        <li>full 2022-05-01 security patch level</li>
                        <li>full 2022-05-05 security patch level</li>
                        <li>rebased onto SP2A.220505.002 release</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/30">version 30</a></li>
                        <li>adevtool: explicitly use python3 for OTA extraction script instead of python to work around distributions still using the end-of-life python2 as python</li>
                    </ul>
                </article>

                <article id="2022043000">
                    <h3><a href="#2022043000">2022043000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022043000">SP1A.210812.016.C1.2022043000</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.003.2022043000">SP2A.220405.003.2022043000</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.004.2022043000">SP2A.220405.004.2022043000</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022042600 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer (GmsCompat): improve user interface</li>
                        <li>Sandboxed Google Play compatibility layer: improve behavior when Nearby devices permission isn't granted to Play services</li>
                        <li>remove build fingerprint from screenshot EXIF metadata</li>
                        <li>Vanadium: update Chromium base to 101.0.4951.41</li>
                        <li>carriersettings-extractor: reuse protocol buffer definitions from AOSP and improve code quality</li>
                        <li>System Updater: add user-facing Alpha channel for very basic / quick public testing after our internal testing before we release to the Beta channel</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro: stop declaring next generation assistant support as an included feature</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/25">version 25</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/26">version 26</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/28">version 28</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/29">version 29</a></li>
                    </ul>
                </article>

                <article id="2022042600">
                    <h3><a href="#2022042600">2022042600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022042600">SP1A.210812.016.C1.2022042600</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.003.2022042600">SP2A.220405.003.2022042600</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.004.2022042600">SP2A.220405.004.2022042600</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022042000 release:</p>

                    <ul>
                        <li>Settings: add support for disabling non-system apps as you can do with system apps instead of only uninstalling them</li>
                        <li>Sandboxed Google Play compatibility layer: fix compatibility with the network location implementation in recent versions of Play services (only relevant for users disabling location redirection toggle and toggling on Play services network location)</li>
                        <li>add missing change for using the GrapheneOS attestation key provisioning proxy</li>
                        <li>backport upstream workaround for hardware-based attestation on devices with a broken implementation of the CREATION_DATETIME feature (disables CREATION_DATETIME on devices without Keymint V1 (100) or later since it was only tested starting with Keymint V1 and is often broken on devices with earlier versions including the Pixel 3 and Pixel 3 XL)</li>
                        <li>Pixel 3, Pixel 3 XL: drop workaround for broken hardware-based attestation now that there's a generic solution backported</li>
                        <li>Messaging: update MMS configuration database to the one from Android Messages 20220405_01_RC04</li>
                        <li>Dialer: update visual voicemail configuration based on Google Phone 79.0.438914483</li>
                        <li>Dialer: adjust VVM configuration database entries for compatibility with AOSP</li>
                        <li>Vanadium: disable fetching optimization guides by default</li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/6">version 6</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/22">version 22</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/23">version 23</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/24">version 24</a></li>
                        <li>TalkBack (screen reader): dependency updates</li>
                        <li>adevtool: remove more unnecessary components</li>
                        <li>add warning to factory images flashing scripts strongly recommending against modifying the scripts based on misguided unofficial installation guides, along with encouraging using the web installer instead</li>
                        <li>add earlier device model check to factory images flashing scripts on Linux and macOS (Windows support is planned)</li>
                    </ul>
                </article>

                <article id="2022042000">
                    <h3><a href="#2022042000">2022042000</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022042000">SP1A.210812.016.C1.2022042000</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.003.2022042000">SP2A.220405.003.2022042000</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.004.2022042000">SP2A.220405.004.2022042000</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022041900 release:</p>

                    <ul>
                        <li>load CarrierConfig data from standalone file in the /product partition (missed in previous release, which was detected during early Beta testing)</li>
                    </ul>
                </article>

                <article id="2022041900">
                    <h3><a href="#2022041900">2022041900</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022041900">SP1A.210812.016.C1.2022041900</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.003.2022041900">SP2A.220405.003.2022041900</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.004.2022041900">SP2A.220405.004.2022041900</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022041600 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: improve Play Store uninstallation hook to avoid stalling if the user rejects the request</li>
                        <li>Sandboxed Google Play compatibility layer: improve work profile support via new compatibility shims</li>
                        <li>Sandboxed Google Play compatibility layer: fix regression resulting in the FIDO2 service not working without Nearby Devices permission being granted by improving Bluetooth compatibility shims</li>
                        <li>Sandboxed Google Play compatibility layer: fix early initialization issue occurring in some cases for Play services</li>
                        <li>Sandboxed Google Play compatibility layer: overall compatibility improvements via the added compatibility shims</li>
                        <li>Sandboxed Google Play compatibility layer: simplify initialization</li>
                        <li>fix com.android.bluetooth privacy indicator exemption (Bluetooth scanning is considered Location access but the Bluetooth implementation itself shouldn't be listed)</li>
                        <li>Pixel 6, Pixel 6 Pro: cleaner approach for the com.shannon.imsservice privacy indicator exemption by defining a new telephony exemption role (this service locally caches location for emergency calls)</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: switch from the obsolete android-prepare-vendor to the much more modern adevtool resulting in substantial improvements to device support (3rd generation devices will keep using android-prepare-vendor since they're all going to be end-of-life after May and won't be migrated to newer major OS versions)</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro: use the default carrier configuration as a base for each configuration to match the behavior of Google's CarrierSettings app, providing various minor improvements and greatly improved GNSS on 6th generation Pixels since Predicted Satellite Data Service (PSDS) for downloading GNSS almanacs was disabled with most carriers</li>
                        <li>Pixel 6, Pixel 6 Pro: use GrapheneOS Predicted Satellite Data Service (PSDS) server by default with a toggle added to Settings to choose the server similar to connectivity checks and attestation key provisioning (can be made into generic code for other Broadcom GPS devices and extended to Qualcomm GPS devices in the future)</li>
                    </ul>
                </article>

                <article id="2022041600">
                    <h3><a href="#2022041600">2022041600</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022041600">SP1A.210812.016.C1.2022041600</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.003.2022041600">SP2A.220405.003.2022041600</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.004.2022041600">SP2A.220405.004.2022041600</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022041300 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 100.0.4896.127</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/21">version 21</a></li>
                    </ul>
                </article>

                <article id="2022041300">
                    <h3><a href="#2022041300">2022041300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022041300">SP1A.210812.016.C1.2022041300</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.003.2022041300">SP2A.220405.003.2022041300</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.004.2022041300">SP2A.220405.004.2022041300</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022041100 release:</p>

                    <ul>
                        <li>temporarily enable verbose logging in DeviceIdleController in order to work towards resolving upstream bugs</li>
                        <li>Sandboxed Google Play compatibility layer: resolve DownloadManager incompatibility</li>
                        <li>revert upstream change to fix spellchecking language detection with the AOSP keyboard</li>
                        <li>GrapheneOS Keyboard: fix exception fetching theme resulting in spellchecking issues</li>
                        <li>GrapheneOS Keyboard: remove legacy Holo themes</li>
                        <li>GrapheneOS Keyboard: follow system dark mode setting by default</li>
                        <li>GrapheneOS Keyboard: properly refresh summary</li>
                        <li>Vanadium: update Chromium base to 100.0.4896.88</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/19">version 19</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/20">version 20</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/45">version 45</a></li>
                    </ul>
                </article>

                <article id="2022041100">
                    <h3><a href="#2022041100">2022041100</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022041100">SP1A.210812.016.C1.2022041100</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.003.2022041100">SP2A.220405.003.2022041100</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.004.2022041100">SP2A.220405.004.2022041100</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022040400 release:</p>

                    <ul>
                        <li>kernel (Pixel 6, Pixel 6 Pro): update GKI base to ASB-2022-04-05_12-5.10 to start using the latest Android 12 GKI as a base</li>
                        <li>Sandboxed Google Play compatibility layer: add additional compatibility shims to restore compatibility with the latest Google Play Games and to fix other issues</li>
                        <li>Sandboxed Google Play compatibility layer: restart GMS processes when permission gets granted since it has bad handling of being given permissions dynamically</li>
                        <li>Sandboxed Google Play compatibility layer: notify user when GMS needs an extra permission or a companion app</li>
                        <li>Sandboxed Google Play compatibility layer: improve code quality and performance</li>
                        <li>Sandboxed Google Play compatibility layer (GmsCompat): improve user interface</li>
                        <li>Sandboxed Google Play compatibility layer: add sandboxed Google Play link for the work profile</li>
                        <li>backport upstream fixes for MAC randomization (more important for GrapheneOS due to per-connection MAC randomization and other improvements providing proper Wi-Fi anonymity)</li>
                    </ul>
                </article>

                <article id="2022040400">
                    <h3><a href="#2022040400">2022040400</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022040400">SP1A.210812.016.C1.2022040400</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.003.2022040400">SP2A.220405.003.2022040400</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220405.004.2022040400">SP2A.220405.004.2022040400</a> (Pixel 6, Pixel 6 Pro, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2022033013 release:</p>

                    <ul>
                        <li>full 2022-04-01 security patch level</li>
                        <li>full 2022-04-05 security patch level</li>
                        <li>rebased onto SP2A.220405.004 release</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro): update GKI base to android12-5.10-2022-03_r1 from android12-5.10-2021-12_r8 for a bunch of upstream and downstream improvements (stock OS still uses android12-5.10-2021-12_r6 and is missing a bunch of important security fixes)</li>
                        <li>Sandboxed Google Play compatibility layer: add additional compatibility shims to improve compatibility with recent Play services</li>
                        <li>Sandboxed Google Play compatibility layer: drop org.grapheneos.pdfviewer from blocked updates list since that app id is no longer being used</li>
                        <li>Sandboxed Google Play compatibility layer (GmsCompat): improve code quality and robustness</li>
                        <li>Sandboxed Google Play compatibility layer (GmsCompat): stop listing having always-on scanning enabled as a potential issue especially since it can be used by other apps</li>
                        <li>Sandboxed Google Play compatibility layer (GmsCompat): prevent infinite loop in location service, which would break location services and result in battery drain</li>
                        <li>Sandboxed Google Play compatibility layer (GmsCompat): fix Google Location Accuracy state check</li>
                        <li>Pixel 3, Pixel 3 XL: remove leftover upstream iorapd testing prop</li>
                        <li>adevtool: fix hang when there are existing files to overwrite</li>
                        <li>fix upstream SMS/MMS database upgrade issue</li>
                        <li>backport fix for unnecessary wake lock in telephony service</li>
                        <li>backport fix for crash in telephony service with null subscription display name</li>
                        <li>backport Wi-Fi APEX module fix to improve robustness when chip reconfiguration fails</li>
                        <li>Settings: improve title/summary for attestation key provisioning server</li>
                        <li>Pixel 3, Pixel 3 XL: fix hardware-based attestation by rolling back an Android 12.1 change for these devices depending on updates to the firmware / device support code since these are end-of-life devices and don't receive those updates so it broke attestation support</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/18">version 18</a></li>
                        <li>Vanadium: update Chromium base to 100.0.4896.79</li>
                        <li>TalkBack (screen reader): dependency updates and crash fix</li>
                        <li>Settings: allow sorting applications by size</li>
                        <li>Settings: remove empty security status header</li>
                        <li>Settings: use framework text colors for SwitchBar</li>
                        <li>backport AOSP fix for edit button in screenshot share activity</li>
                        <li>display two rows of max ranked targets for sharesheet</li>
                        <li>fix uneven volume icon padding in status bar</li>
                        <li>remove nav bar background in Quick Settings customizer</li>
                        <li>fix Quick Settings status font weight mismatch in dark mode</li>
                        <li>switch build number style from YYYYMMDDHH to YYYYMMDDCC where CC is a counter starting at 0</li>
                    </ul>
                </article>

                <article id="2022033013">
                    <h3><a href="#2022033013">2022033013</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022033013">SP1A.210812.016.C1.2022033013</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220305.012.2022033013">SP2A.220305.012.2022033013</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220305.013.A3.2022033013">SP2A.220305.013.A3.2022033013</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022032715 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: substantially improve dynamite module support</li>
                        <li>use GrapheneOS hardware attestation key provisioning server by default with a toggle added to Settings to choose the server similar to connectivity checks</li>
                        <li>extend eSIM management code with disabling the apps in secondary users due to prior GrapheneOS releases enabling them in all users</li>
                        <li>move early boot eSIM integration code later in an attempt to fix a potential regression</li>
                        <li>Vanadium: update Chromium base to 100.0.4896.58</li>
                        <li>Pixel 6, Pixel 6 Pro: resolve problem generating over-the-air updates which led to us not being able to use incrementals for updates to this release or the previous release</li>
                    </ul>
                </article>

                <article id="2022032715">
                    <h3><a href="#2022032715">2022032715</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022032715">SP1A.210812.016.C1.2022032715</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220305.012.2022032715">SP2A.220305.012.2022032715</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220305.013.A3.2022032715">SP2A.220305.013.A3.2022032715</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022032110 release:</p>

                    <ul>
                        <li>ThemePicker: add toggle for using wallpaper-extracted colors as the color scheme (Monet)</li>
                        <li>add toggle for exec-based spawning in <b>Settings&#160;<span aria-label="and then">></span> Security</b></li>
                        <li>GrapheneOS Keyboard: enable spellchecking for Czech and Dutch languages</li>
                        <li>Vanadium: update Chromium base to 99.0.4844.88</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/17">version 17</a></li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro: remove unnecessary configuration/permissions for apps not included in AOSP/GrapheneOS</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro: add RCS packages</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro: remove AOSP / stock OS configuration pinning the system camera and launcher in memory since it's wasteful</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro: stop forcing camera shutter sound on the Japanese hardware SKUs</li>
                    </ul>
                </article>

                <article id="2022032110">
                    <h3><a href="#2022032110">2022032110</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022032110">SP1A.210812.016.C1.2022032110</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220305.012.2022032110">SP2A.220305.012.2022032110</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220305.013.A3.2022032110">SP2A.220305.013.A3.2022032110</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022031103 release:</p>

                    <ul>
                        <li>Pixel 6, Pixel 6 Pro: full Pixel 2022-03-05 security patch level (Android 2022-03-05 security patch level was already provided early by GrapheneOS)</li>
                        <li>Pixel 6, Pixel 6 Pro: rebased onto SP2A.220305.013.A3 release</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro): update GKI base to android12-5.10-2021-12_r8 from the android12-5.10-2021-12_r6 version still used by the AOSP / stock Pixel OS March release for a few additional security fixes beyond the ones already backported early by GrapheneOS along with latency improvements under certain heavy real-time loads</li>
                        <li>add eSIM activation support as an optional toggle available when using sandboxed Google Play in the Owner profile (note: regular apps including sandboxed Google Play do not have additional access in the Owner profile)</li>
                        <li>Sandboxed Google Play compatibility layer: expand PhenoTypeFlags workaround to all Play services clients</li>
                        <li>GmsCompat: call startForegroundService from the main thread to avoid potential issues</li>
                        <li>Vanadium: restore new tab page behavior by working around regressions in Chromium 99</li>
                        <li>Vanadium: update certain Chromium dependencies to avoid crashes caused by incompatibilities with Android 12 (will allow for multiple kinds of FIDO2 support via sandboxed Google Play once we extend the sandboxed Google Play compatibility layer to support it or once Play services whitelists Vanadium as a browser allowed to use FIDO2)</li>
                        <li>Vanadium: update Chromium base to 99.0.4844.73</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 5a): temporarily revert disabling SECURITY_SELINUX_DEVELOP to work around upstream AOSP bug in early userspace (Pixel 4a (5G), Pixel 5, Pixel 6 and Pixel 6 Pro had this change made in the previous release since it blocked the over-the-air update path for them despite not blocking it for these devices)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro): backport CVE-2021-41073 fix (not reachable from apps due to standard AOSP seccomp-bpf allowlist)</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro): backport CVE-2022-25375 fix</li>
                        <li>enable conversations feature flag</li>
                        <li>enable charging ripple feature flag</li>
                        <li>skip screen-on animation</li>
                        <li>Dialer: fix theme colors in dark mode</li>
                        <li>Apps: update to <a href="https://github.com/GrapheneOS/Apps/releases/tag/5">version 5</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/13">version 13</a></li>
                        <li>improve Android 12 PendingIntent security check compatibility due to buggy apps including Chromium targeting API 31+ with outdated Play services client libraries lacking Android 12 support (triggered much more frequently on GrapheneOS due to PendingIntent being used to request runtime permissions on behalf of Play services)</li>
                        <li>fix compatibility of PIN scrambling with physical keyboards</li>
                        <li>Settings: convert PIN scrambling toggle into a switch preference from a list preference</li>
                        <li>improve USB connection icon</li>
                        <li>backport fixes for battery usage history</li>
                        <li>add fix for Monet color generation</li>
                    </ul>
                </article>

                <article id="2022031103">
                    <h3><a href="#2022031103">2022031103</a></h3>

                    <p>This release is only being pushed out for the Pixel 6 and Pixel 6 Pro due
                    to lack of changes applicable to other devices.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/S2B3.220205.007.A1.2022031103">S2B3.220205.007.A1.2022031103</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022030801 release:</p>

                    <ul>
                        <li>Pixel 6, Pixel 6 Pro: temporarily exclude our work on eSIM support since the full implementation requires Google services and we're taking a new approach which will result in full eSIM support including activation across all supported devices in the near future as part of sandboxed Google Play (in the long term, it can be supported without using these Google eSIM apps from the stock Pixel OS)</li>
                    </ul>
                </article>

                <article id="2022030801">
                    <h3><a href="#2022030801">2022030801</a></h3>

                    <p>Tags:</p>

                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022030801">SP1A.210812.016.C1.2022030801</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP2A.220305.012.2022030801">SP2A.220305.012.2022030801</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/S2B3.220205.007.A1.2022030801">S2B3.220205.007.A1.2022030801</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Pixel 6 and Pixel 6 Pro release is a preliminary March release with the
                    2022-03-01 security update since there isn't an AOSP or stock OS release for
                    it yet. It also includes several other vulnerability fixes.</p>

                    <p>Changes since the 2022030501 release:</p>

                    <ul>
                        <li>full 2022-03-01 security patch level</li>
                        <li>full 2022-03-05 security patch level (Pixel 6 and Pixel 6 Pro can reach the 2022-03-05 Android patch level but not the 2022-03-05 Pixel patch level until the March AOSP/Android release for them is available, and the upstream release is delayed)</li>
                        <li>rebased onto SP2A.220305.012 release, the initial release of Android 12.1 (Android 12L) which is the second quarterly maintenance/feature release for Android 12</li>
                        <li>disable Monet (color scheme based on wallpaper) by default since AOSP 12.1 has no way to opt-out of the feature or to manually choose colors instead (we'll add a toggle for enabling it later this month and we could also include a color picker before AOSP 13 but likely not this month)</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro): apply downstream fix for CVE-2022-0847</li>
                        <li>kernel (Pixel 5a): re-apply January audio driver security patch which was accidentally dropped upstream for 12L due to it being branched earlier than January and this patch not being applied again as it was for other 5th generation devices (consequence of AOSP having the Pixel 5a kernel unnecessarily separate from the other 5th generation devices instead of merging them a year ago)</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): fix audio driver build reproducibility issue</li>
                        <li>Sandboxed Google Play compatibility layer: extend, optimize and improve the robustness of the compatiblity shims to improve the compatibility layer in general</li>
                        <li>Sandboxed Google Play compatibility layer: fix regressions in compatibility with the Google Play geolocation service for users choosing to disable redirection to the OS geolocation service in order to use their network location and other features</li>
                        <li>Sandboxed Google Play compatibility layer: prevent Play services from trying to update OS fonts since it requires a privileged permission and the service will crash from the SecurityException</li>
                        <li>make DownloadManager even friendlier to apps with the Network permission revoked by avoiding SecurityExceptions in more cases and giving them errors they know how to handle instead</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/14">version 14</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/15">version 15</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/16">version 16</a></li>
                        <li>Settings: always show ICCID in SIM status</li>
                        <li>Settings: show hardware SKU</li>
                        <li>Settings (Pixel 6, Pixel 6 Pro): add saturated color mode</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: mark IncFS as being built into the kernel</li>
                        <li>add support code for Pixel 6 and Pixel 6 Pro APEX enablement and under display fingerprint reader to the main branch as preparation for eliminating the device branch</li>
                        <li>SELinux policy: add missing auditallow for base untrusted_app domains</li>
                        <li>SELinux policy: add missing seinfo=base rules</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5, Pixel 6, Pixel 6 Pro): temporarily revert disabling SECURITY_SELINUX_DEVELOP to work around upstream AOSP bug in early userspace</li>
                    </ul>
                </article>

                <article id="2022030501">
                    <h3><a href="#2022030501">2022030501</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022030501">SP1A.210812.016.C1.2022030501</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220205.002.2022030501">SQ1A.220205.002.2022030501</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.220205.004.2022030501">SQ1D.220205.004.2022030501</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022030219 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 99.0.4844.58</li>
                    </ul>
                </article>

                <article id="2022030219">
                    <h3><a href="#2022030219">2022030219</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022030219">SP1A.210812.016.C1.2022030219</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220205.002.2022030219">SQ1A.220205.002.2022030219</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.220205.004.2022030219">SQ1D.220205.004.2022030219</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022022818 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 99.0.4844.48</li>
                        <li>GmsCompat: fix typo</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: disable broken Google Camera sepolicy for now to restore it back to how it previously worked (also fixes Google Photos when Google Camera is installed)</li>
                    </ul>
                </article>

                <article id="2022022818">
                    <h3><a href="#2022022818">2022022818</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022022818">SP1A.210812.016.C1.2022022818</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220205.002.2022022818">SQ1A.220205.002.2022022818</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.220205.004.2022022818">SQ1D.220205.004.2022022818</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022021721 release:</p>

                    <ul>
                        <li>include beta release (v4) of GrapheneOS app repository client which is still in early development but now robust enough to be ready for inclusion in the OS and production use</li>
                        <li>Sandboxed Google Play compatibility layer: prevent Play Store from trying to update Auditor, PDF Viewer, Google Services Framework, Google Play services and the Play Store since we'll be updating these via our own app repository client (we'll be regularly updating the mirror of Google Play in our repository once the staged rollouts reach our test devices and it passes basic testing)</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/43">version 43</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/44">version 44</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/13">version 13</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/11">version 11</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/12">version 12</a></li>
                        <li>Contacts: add support for vCard 4.0</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, Pixel 6, Pixel 6 Pro: include current eSIM firmware, EuiccPixel and EuiccPixel integration (this improves eSIM support by keeping the eSIM firmware up-to-date but does not provide eSIM activation yet)</li>
                        <li>Sandboxed Google Play compatibility layer: improve code quality / robustness</li>
                        <li>mark Bluetooth service as an extra location package to avoid showing misleading/unhelpful location indicators (Bluetooth scanning is considered location access for apps, but it makes no sense to show it for the Bluetooth implementation itself rather than only actual apps using it)</li>
                        <li>Pixel 6, Pixel 6 Pro: mark Shannon IMS service as an extra location package to avoid showing unhelpful location indicators (it retrieves location information regularly in order to have it ready for an emergency call)</li>
                    </ul>
                </article>

                <article id="2022021721">
                    <h3><a href="#2022021721">2022021721</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022021721">SP1A.210812.016.C1.2022021721</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220205.002.2022021721">SQ1A.220205.002.2022021721</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.220205.004.2022021721">SQ1D.220205.004.2022021721</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022021602 release:</p>

                    <ul>
                        <li>Pixel 6, Pixel 6 Pro: rebased onto SQ1D.220205.004 release (2nd February update for 6th generation Pixels with additional security fixes separate from the February security update)</li>
                        <li>Sandboxed Google Play compatibility layer: add shim to stop Play services from trying to use the privileged android.hardware.uwb API to prevent a SecurityException on the Pixel 6 Pro and future devices with the feature</li>
                        <li>Clock: use clock icon for the app icon instead of alarm icon</li>
                    </ul>
                </article>

                <article id="2022021602">
                    <h3><a href="#2022021602">2022021602</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022021602">SP1A.210812.016.C1.2022021602</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220205.002.2022021602">SQ1A.220205.002.2022021602</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.220205.003.2022021602">SQ1D.220205.003.2022021602</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022021415 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: add shim for compatibility with on-demand dynamite modules</li>
                        <li>Sandboxed Google Play compatibility layer: update dynamite module compatibility layer for upcoming changes to Play services</li>
                        <li>Sandboxed Google Play compatibility layer: friendlier error for apps without Location permission attempting to use redirected Play services geolocation to match Play services behavior</li>
                        <li>Vanadium: update Chromium base to 98.0.4758.101</li>
                        <li>cancel pending over-the-air update snapshot when flashing factory images via flash-all.sh / flash-all.bat</li>
                        <li>Pixel 6, Pixel 6 Pro: add missing camera shutter sound change from the <a href="#2022021314">2022021314 release</a></li>
                    </ul>
                </article>

                <article id="2022021415">
                    <h3><a href="#2022021415">2022021415</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022021415">SP1A.210812.016.C1.2022021415</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220205.002.2022021415">SQ1A.220205.002.2022021415</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.220205.003.2022021415">SQ1D.220205.003.2022021415</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022021314 release:</p>

                    <ul>
                        <li>GmsCompat: handle edge cases for network location opt-in mode preventing settings menu from loading</li>
                    </ul>
                </article>

                <article id="2022021314">
                    <h3><a href="#2022021314">2022021314</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022021314">SP1A.210812.016.C1.2022021314</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220205.002.2022021314">SQ1A.220205.002.2022021314</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.220205.003.2022021314">SQ1D.220205.003.2022021314</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022020800 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: simplify and optimize initialization</li>
                        <li>Sandboxed Google Play compatibility layer: add support for redirecting apps from the Google Play geolocation service to the GrapheneOS geolocation service with a toggle added to the "Sandboxed Google Play settings" configuration menu for disabling redirection to use the Google Play implementation (redirection is enabled by default at first launch unless Play services has been granted the Location permission)</li>
                        <li>GmsCompat: add suggestions to the settings menu</li>
                        <li>fix editing APNs in certain edge cases with certain carriers</li>
                        <li>Pixel 6, Pixel 6 Pro: bind power + volume up key chord to mute like other devices, since long pressing power already opens the power menu</li>
                        <li>stop enforcing camera sound when using a carrier based in India/Japan/Korea since we aren't required to enforce it and is trivially bypassed in multiple ways so it's nothing more than an annoyance</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/42">version 42</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/12">version 12</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/10">version 10</a></li>
                        <li>Calculator: improve app icon</li>
                        <li>Clock: improve app icon</li>
                        <li>Contacts: improve app icon</li>
                        <li>Dialer: improve app icon</li>
                        <li>Files: improve app icon</li>
                        <li>Gallery: improve app icon</li>
                        <li>Messaging: improve app icon</li>
                        <li>Settings: improve app icon</li>
                    </ul>
                </article>

                <article id="2022020800">
                    <h3><a href="#2022020800">2022020800</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.C1.2022020800">SP1A.210812.016.C1.2022020800</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220205.002.2022020800">SQ1A.220205.002.2022020800</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.220205.003.2022020800">SQ1D.220205.003.2022020800</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022013120 release:</p>

                    <ul>
                        <li>full 2022-02-01 security patch level</li>
                        <li>full 2022-02-05 security patch level</li>
                        <li>rebased onto SQ1A.220205.002 and SQ1D.220205.003 releases</li>
                        <li>Pixel 3, Pixel 3 XL: switch to SP1A.210812.016.C1 (February 2022) vendor files</li>
                        <li>Vanadium: update Chromium base to 98.0.4758.87</li>
                        <li>Vanadium: enable CFI cast checks</li>
                        <li>change GmsCompat app label from "Sandboxed Google Play" to "GmsCompat" and the activity name to "Sandboxed Google Play settings"</li>
                        <li>add GmsCompat to list of essential system components in Settings</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/11">version 11</a></li>
                        <li>restrict granting the special added GrapheneOS runtime permissions (Network, Sensors) on upgrades to system apps (only relevant to Network in practice)</li>
                        <li>add workaround for Microsoft apps detecting that Network is revoked and crashing the app with a runtime exception due to them adding this to a library as a debugging check for development to detect the INTERNET permission not being declared (we've <a href="https://github.com/AzureAD/azure-activedirectory-library-for-android/issues/1675">asked them to fix the compatibility issue</a>)</li>
                        <li>do not mark dun APN types as read-only (allows editing more carrier APNs)</li>
                        <li>temporarily suppress SystemUI ANRs due to AOSP 12 screenshot service bug which triggers an ANR in SystemUI by not handling an event some time after taking a screenshot (also occurs on the stock OS and elsewhere, and the main issue is the error message since it's otherwise harmless)</li>
                        <li>disable running clang-tidy as part of regular builds by default since it wastes time and isn't very useful to us</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro): make Wi-Fi driver module build reproducible</li>
                        <li>kernel (Pixel 6, Pixel 6 Pro): make tarball generation reproducible</li>
                        <li>Settings: add package name to app overview page</li>
                        <li>Settings: add GrapheneOS icon</li>
                        <li>Files: add GrapheneOS icon</li>
                        <li>Files: define app category (productivity)</li>
                        <li>Clock: add GrapheneOS icon</li>
                        <li>Clock: define app category (productivity)</li>
                        <li>Contacts: add GrapheneOS icon</li>
                        <li>Contacts: define app category (productivity)</li>
                        <li>Gallery: add GrapheneOS icon</li>
                        <li>Gallery: define app category (image)</li>
                        <li>Messaging: add GrapheneOS icon</li>
                        <li>Messaging: define app category (social)</li>
                        <li>Dialer: add GrapheneOS icon</li>
                        <li>Dialer: define app category (social)</li>
                        <li>Calculator: add GrapheneOS icon</li>
                        <li>Calculator: define app category (productivity)</li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/8">version 8</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/9">version 9</a></li>
                    </ul>
                </article>

                <article id="2022013120">
                    <h3><a href="#2022013120">2022013120</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.A2.2022013120">SP1A.210812.016.A2.2022013120</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220105.002.2022013120">SQ1A.220105.002.2022013120</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.220105.007.2022013120">SQ1D.220105.007.2022013120</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022013010 release:</p>

                    <ul>
                        <li>Pixel 3, Pixel 3 XL: add GmsCompat app which was meant to be added by the previous release</li>
                        <li>Pixel 6, Pixel 6 Pro: revert accidental enabling of dark mode by default, which we plan to do by default in the future across devices once the Contacts and Messaging apps are updated to support it (you can set your own preference in <b>Settings&#160;<span aria-label="and then">></span> Display&#160;<span aria-label="and then">></span> Dark theme</b>)</li>
                    </ul>
                </article>

                <article id="2022013010">
                    <h3><a href="#2022013010">2022013010</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.A2.2022013010">SP1A.210812.016.A2.2022013010</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220105.002.2022013010">SQ1A.220105.002.2022013010</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.220105.007.2022013010">SQ1D.220105.007.2022013010</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022011423 release:</p>

                    <ul>
                        <li>make DownloadManager friendlier to apps with the Network permission revoked instead of triggering SecurityException</li>
                        <li>Sandboxed Google Play compatibility layer: revert marking location service as a foreground location service (not necessary)</li>
                        <li>Sandboxed Google Play compatibility layer: add compatibility shims enabling full support for using Play services geolocation</li>
                        <li>Sandboxed Google Play compatibility layer: add GmsCompat app providing infrastructure for the compatibility layer and shortcuts to Google Play configuration activities (will provide a toggle for redirecting the Google Play geolocation API to the OS API in a future release)</li>
                        <li>Sandboxed Google Play compatibility layer: replace converting Google Play services to foreground services with keeping them alive using the GmsCompat app (improves compatibility with apps calling Play services or the Play Store in the background)</li>
                        <li>Dialer: update visual voicemail configuration based on Google Phone 73.0.414822266</li>
                        <li>Messaging: replace obsolete AOSP MMS configuration database with one generated from the stock OS app</li>
                        <li>Vanadium: update Chromium base to 97.0.4692.98</li>
                        <li>Vanadium: use Google Chrome branding for client hints to help with blending in</li>
                        <li>Vanadium: enable HTTPS-only mode by default (can connect via HTTP through the warning screen if HTTPS upgrade fails)</li>
                        <li>Vanadium: enable strict origin isolation by default</li>
                        <li>Vanadium: disable appending variations header</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/10">version 10</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/41">version 41</a></li>
                        <li>hardened_malloc: code cleanup and micro-optimizations</li>
                        <li>adevtool: initial public release replacing pre-generated vendor trees</li>
                        <li>adevtool: overhaul of GrapheneOS specific configuration</li>
                    </ul>
                </article>

                <article id="2022011423">
                    <h3><a href="#2022011423">2022011423</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.A2.2022011423">SP1A.210812.016.A2.2022011423</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220105.002.2022011423">SQ1A.220105.002.2022011423</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.220105.007.2022011423">SQ1D.220105.007.2022011423</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022011009 release:</p>

                    <ul>
                        <li>Pixel 6, Pixel 6 Pro: Pixel 2022-01-05 patch level (instead of the Android 2022-01-05 patch level and Pixel 2022-01-01 patch level)</li>
                        <li>Pixel 6, Pixel 6 Pro: rebased onto SQ1D.211205.017 release</li>
                        <li>Sandboxed Google Play compatibility layer: add support for Play Asset Delivery and Play Feature Delivery by extending relevant hooks to the Play Store in addition to Play services</li>
                        <li>Sandboxed Google Play compatibility layer: improve getSharedLibraries shim by disabling MATCH_ANY_USER instead of stubbing it out completely (stops the Play Store from filtering out apps with dependencies it thinks are missing)</li>
                        <li>remove g.co/wallpaper link support from wallpaper app which had an incorrect <code>autoVerify="true"</code> property despite not being authorized by g.co</li>
                        <li>Vanadium: update Chromium base to 97.0.4692.87</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): backport USB security patch for CVE-2021-30313 which was missed upstream</li>
                        <li>adevtool: improve Pixel 6 and Pixel 6 Pro device support scripting</li>
                    </ul>
                </article>

                <article id="2022011009">
                    <h3><a href="#2022011009">2022011009</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.016.A2.2022011009">SP1A.210812.016.A2.2022011009</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220105.002.2022011009">SQ1A.220105.002.2022011009</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.211205.017.2022011009">SQ1D.211205.017.2022011009</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2022010500 release:</p>

                    <ul>
                        <li>remove obsolete AOSP CarrierConfig resources to greatly improve support for many carriers</li>
                        <li>fix handling of MVNOs in CarrierConfig database generation to greatly improve out-of-the-box MVNO support</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/9">version 9</a></li>
                        <li>TalkBack (screen reader): update base version to 370044210 and port our changes (other than Play services vision library removal since it now provides useful OCR functionality we need to replace rather than removing)</li>
                        <li>Sandboxed Google Play compatibility layer: extend compatibility layer to Play Games Services (Google Play Games can be installed from the Play Store)</li>
                        <li>Sandboxed Google Play compatibility layer: always allow removing Google account to bypass broken check for whether removal is allowed</li>
                        <li>Sandboxed Google Play compatibility layer: improve account sign in UX by pretending the backup service is inactive so Play services doesn't try to access it</li>
                        <li>Pixel 4a (5G), Pixel 5, Pixel 5a: add SELinux policy to allow the hardware keystore secure confirmation UI</li>
                        <li>Pixel 3, Pixel 3 XL: switch to SP1A.210812.016.A2 vendor files (minor APN update for 1 carrier)</li>
                    </ul>
                </article>

                <article id="2022010500">
                    <h3><a href="#2022010500">2022010500</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2022010500">SP1A.210812.015.2022010500</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.220105.002.2022010500">SQ1A.220105.002.2022010500</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.211205.017.2022010500">SQ1D.211205.017.2022010500</a> (Pixel 6, Pixel 6 Pro) — early release with the full Android 2022-01-05 patch level but only the 2022-01-01 Pixel patch level since the AOSP / stock OS January update for the Pixel 6 and Pixel 6 Pro is happening in late January so the patches specific to them aren't publicly available yet</li>
                    </ul>

                    <p>Changes since the 2021122018 release:</p>

                    <ul>
                        <li>full 2022-01-01 security patch level</li>
                        <li>full 2022-01-05 security patch level</li>
                        <li>rebased onto SQ1A.220105.002 release</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/8">version 8</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/39">version 39</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/40">version 40</a></li>
                        <li>Pixel 6, Pixel 6 Pro: add SoC SELinux policy extensions from December release</li>
                        <li>Pixel 6, Pixel 6 Pro: remove support for FIPS disk encryption mode</li>
                        <li>hardened_malloc: minor code cleanups</li>
                        <li>Vanadium: update Chromium base to 97.0.4692.70</li>
                    </ul>
                </article>

                <article id="2021122018">
                    <h3><a href="#2021122018">2021122018</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021122018">SP1A.210812.015.2021122018</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.211205.008.2021122018">SQ1A.211205.008.2021122018</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1D.211205.017.2021122018">SQ1D.211205.017.2021122018</a> (Pixel 6, Pixel 6 Pro)</li>
                    </ul>

                    <p>Changes since the 2021121602 release:</p>

                    <ul>
                        <li>initial production support for the Pixel 6 and Pixel 6 Pro</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/38">version 38</a></li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: erase both apdp partition slots as part of flashing factory images to wipe persistent debugging policy</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a: erase both msadp partition slots as part of flashing factory images to wipe persistent debugging policy</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): enable BUG_ON_DATA_CORRUPTION since it was backported upstream</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a): enable legacy Qualcomm PANIC_ON_DATA_CORRUPTION since it hasn't been fully phased out yet</li>
                        <li>Seedvault: temporarily revert change to restore requiring that the profile is unlocked for the hardware keystore key (uncovers an upstream bug)</li>
                    </ul>
                </article>

                <article id="2021121602">
                    <h3><a href="#2021121602">2021121602</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021121602">SP1A.210812.015.2021121602</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.211205.008.2021121602">SQ1A.211205.008.2021121602</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021121012 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 96.0.4664.104</li>
                        <li>skip reporting network connectivity to the OS from apps with the Network (INTERNET) permission revoked to avoid triggering a SecurityException</li>
                        <li>remove special case of throwing SecurityException for socket errors caused by EACCES/EPERM as a debugging aid since it causes compatibility issues when the Network (INTERNET) permission is revoked</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a): fix incorrect alloc_size annotation (already fixed in older kernels and no real world impact)</li>
                    </ul>
                </article>

                <article id="2021121012">
                    <h3><a href="#2021121012">2021121012</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021121012">SP1A.210812.015.2021121012</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.211205.008.2021121012">SQ1A.211205.008.2021121012</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021120717 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: mark location service as a foreground location service</li>
                        <li>Vanadium: update Chromium base to 96.0.4664.92</li>
                        <li>TalkBack (screen reader): update dependencies</li>
                        <li>Seedvault: restore requiring that the profile is unlocked for the hardware keystore key</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: add support for increased touch sensitivity option</li>
                        <li>fix overly aggressive fastboot version check in flash-all.bat triggered by version requirement increase in the SQ1A.211205.008 update (was also fixed for the factory images for the last official release)</li>
                    </ul>
                </article>

                <article id="2021120717">
                    <h3><a href="#2021120717">2021120717</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021120717">SP1A.210812.015.2021120717</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SQ1A.211205.008.2021120717">SQ1A.211205.008.2021120717</a> (Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021112404 release:</p>

                    <ul>
                        <li>full 2021-12-01 security patch level</li>
                        <li>full 2021-12-05 security patch level</li>
                        <li>rebased onto SQ1A.211205.008 release, the first quarterly maintenance/feature release for Android 12</li>
                        <li>Sandboxed Google Play compatibility layer: improve robustness of Play Store compatibility layer</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/7">version 7</a></li>
                        <li>TalkBack (screen reader): update dependencies</li>
                        <li>avoid per-network randomization mode (AOSP default) being displayed as per-connection randomization mode (GrapheneOS default not available in AOSP) after rebooting despite persisting and working properly (caused by an additional abstraction layer introduced in Android 12)</li>
                    </ul>
                </article>

                <article id="2021112404">
                    <h3><a href="#2021112404">2021112404</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021112404">SP1A.210812.015.2021112404</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.002.2021112404">SP1A.211105.002.2021112404</a> (Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.003.2021112404">SP1A.211105.003.2021112404</a> (Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.004.2021112404">SP1A.211105.004.2021112404</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021112123 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: add another UserManager shim to fix issue with FCM in secondary user profiles</li>
                        <li>Sandboxed Google Play compatibility layer: mark the compatibility layer's Play Store confirmation notification as ongoing to avoid users dismissing the notification and then being unable to accept or reject the install/update/uninstall action</li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/6">version 6</a></li>
                    </ul>
                </article>

                <article id="2021112123">
                    <h3><a href="#2021112123">2021112123</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021112123">SP1A.210812.015.2021112123</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.002.2021112123">SP1A.211105.002.2021112123</a> (Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.003.2021112123">SP1A.211105.003.2021112123</a> (Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.004.2021112123">SP1A.211105.004.2021112123</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021112021 release:</p>

                    <ul>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/7">version 7</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/5">version 5</a></li>
                    </ul>
                </article>

                <article id="2021112021">
                    <h3><a href="#2021112021">2021112021</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021112021">SP1A.210812.015.2021112021</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.002.2021112021">SP1A.211105.002.2021112021</a> (Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.003.2021112021">SP1A.211105.003.2021112021</a> (Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.004.2021112021">SP1A.211105.004.2021112021</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021111414 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: expand Play Store compatibility layer to fully support app installation, uninstallation and unattended updates via the standard unprivileged APIs</li>
                        <li>Sandboxed Google Play compatibility layer: expand Play Store compatibility layer to support the Play Store updating itself via the standard unprivileged APIs</li>
                        <li>Settings: clearer wording for the default GrapheneOS per-connection MAC randomization</li>
                        <li>Vanadium: update Chromium base to 96.0.4664.45</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/35">version 35</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/36">version 36</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/37">version 37</a></li>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/4">version 4</a></li>
                        <li>TalkBack (screen reader): update dependencies and tools</li>
                    </ul>
                </article>

                <article id="2021111414">
                    <h3><a href="#2021111414">2021111414</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021111414">SP1A.210812.015.2021111414</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.002.2021111414">SP1A.211105.002.2021111414</a> (Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.003.2021111414">SP1A.211105.003.2021111414</a> (Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.004.2021111414">SP1A.211105.004.2021111414</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021110617 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: improve AppOps compatibility layer for long-lived operations via the new startProxyOp/finishProxyOp API which previously had to be mimicked via the existing APIs</li>
                        <li>System Updater: only allow privileged apps including Settings to open the settings activity since other apps like the launcher have no reason to open it</li>
                        <li>android-prepare-vendor carriersettings-extractor: strip out carrier provisioning configuration (OMA device management is not included in GrapheneOS so this references an app that's not present)</li>
                        <li>android-prepare-vendor carriersettings-extractor: always enable the ability to disable 2G</li>
                        <li>android-prepare-vendor carriersettings-extractor: remove unused Google Dialer configuration for Wi-Fi calling</li>
                        <li>android-prepare-vendor: improve Pixel 5a support</li>
                        <li>add CameraX vendor extensions library to compile-time class loader path for GrapheneOS Camera to make dexpreopt usable</li>
                    </ul>
                </article>

                <article id="2021110617">
                    <h3><a href="#2021110617">2021110617</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021110617">SP1A.210812.015.2021110617</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.002.2021110617">SP1A.211105.002.2021110617</a> (Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.003.2021110617">SP1A.211105.003.2021110617</a> (Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.004.2021110617">SP1A.211105.004.2021110617</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021110507 release:</p>

                    <ul>
                        <li>Camera: update to <a href="https://github.com/GrapheneOS/Camera/releases/tag/3">version 3</a></li>
                        <li>revert hard-wiring camera gesture handler as a workaround for AOSP 12 bug with the gesture on the lockscreen (only has an impact when multiple camera apps are installed and can be worked around, so we'll just wait for an upstream resolution)</li>
                        <li>Vanadium: add workaround for upstream bug with login when sandboxed Play services is present</li>
                        <li>android-prepare-vendor: overhaul Pixel 4a (5G), Pixel 5 and Pixel 5a support including building more AOSP modules</li>
                    </ul>
                </article>

                <article id="2021110507">
                    <h3><a href="#2021110507">2021110507</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021110507">SP1A.210812.015.2021110507</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.002.2021110507">SP1A.211105.002.2021110507</a> (Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.003.2021110507">SP1A.211105.003.2021110507</a> (Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.004.2021110507">SP1A.211105.004.2021110507</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021110122 release:</p>

                    <ul>
                        <li>replace AOSP Camera app with next-generation GrapheneOS Camera app</li>
                        <li>set GrapheneOS Camera app as the hard-wired handler for camera gesture, similar to Android 11+ hard-wiring it as the camera media intent handler (should work around AOSP 12 lockscreen camera bugs) — note: this will be undone in a follow-up release before this reaches the Stable channel</li>
                        <li>invalidate icon cache between OS releases instead of only between major Android versions so that system theme/icon changes take effect immediately</li>
                        <li>system theme: switch to a more unique blue Material You color palette based around #1565C0</li>
                        <li>System Updater: adjust colors to match Settings app</li>
                        <li>Vanadium: update Chromium base to 95.0.4638.74</li>
                    </ul>
                </article>

                <article id="2021110122">
                    <h3><a href="#2021110122">2021110122</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021110122">SP1A.210812.015.2021110122</a> (Pixel 3, Pixel 3 XL) — extended support release for legacy devices with frozen 2021-11-01 patch level</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.002.2021110122">SP1A.211105.002.2021110122</a> (Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.003.2021110122">SP1A.211105.003.2021110122</a> (Pixel 5a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.211105.004.2021110122">SP1A.211105.004.2021110122</a> (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021102613 release:</p>

                    <ul>
                        <li>full 2021-11-01 security patch level</li>
                        <li>full 2021-11-05 security patch level</li>
                        <li>full 2021-11-06 security patch level</li>
                        <li>rebased onto SP1A.211105.004 release</li>
                        <li>system theme: switch to pure blue Material You color palette as a starting point for a GrapheneOS theme</li>
                        <li>System Updater: drop unused androidx legacy support library</li>
                        <li>System Updater: raise minSdkVersion to 31 (Android 12)</li>
                        <li>System Updater: stop marking settings activity as direct boot aware since it's never used before unlocking</li>
                        <li>System Updater: remove obsolete receiver from manifest</li>
                        <li>android-prepare-vendor: overhaul Pixel 4, Pixel 4 XL and Pixel 4a support including building more AOSP modules</li>
                    </ul>
                </article>

                <article id="2021102613">
                    <h3><a href="#2021102613">2021102613</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021102613">SP1A.210812.015.2021102613</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021102503 release:</p>

                    <ul>
                        <li>System Updater: split up install progress notification into stages</li>
                        <li>include standard display cutout overlays across all devices</li>
                        <li>temporarily disable broken 'Render apps below cutout area' display cutout developer option to avoid it breaking loading SystemUI on boot</li>
                        <li>temporarily disable user-facing crash reporting for com.android.systemui due to an upstream AOSP 12 bug causing false positive reports of it being frozen (this change didn't end up successfully silencing the false positives so a different approach will be needed)</li>
                    </ul>
                </article>

                <article id="2021102503">
                    <h3><a href="#2021102503">2021102503</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021102503">SP1A.210812.015.2021102503</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021102300 release:</p>

                    <ul>
                        <li>enable gestural navigation overlay to match default nav mode (fixes navigation bar style after factory reset or provisioning new users)</li>
                        <li>Launcher: temporarily disable new animation feature flags (these appear to be buggy)</li>
                        <li>Clock: roll back to GrapheneOS Android 11 Clock app since the AOSP 12 Clock app is buggy</li>
                        <li>Dialer: revert to prior visual voicemail configuration until the new configuration is properly handled</li>
                    </ul>
                </article>

                <article id="2021102300">
                    <h3><a href="#2021102300">2021102300</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021102300">SP1A.210812.015.2021102300</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021102203 release:</p>

                    <ul>
                        <li>revert our change enabling the legacy wifi/cellular quick tiles until the upstream code is fixed</li>
                        <li>improve delta generation script</li>
                        <li>Messaging: add built-in battery optimization exception</li>
                        <li>Messaging: fix cellbroadcast package name</li>
                        <li>Messaging: stop using platform certificate</li>
                        <li>Dialer: update visual voicemail configuration for SP1A.210812.015</li>
                        <li>keep PIN scrambling keypad number descriptions in sync with digits</li>
                        <li>update PIN UI appearance for Android 12 in PIN scrambling implementation</li>
                    </ul>
                </article>

                <article id="2021102203">
                    <h3><a href="#2021102203">2021102203</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021102203">SP1A.210812.015.2021102203</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021102020 release:</p>

                    <ul>
                        <li>Settings: add back reset text change lost in the port to Android 12</li>
                        <li>fix inclusion of up-to-date per-device APN database for Pixels</li>
                        <li>Pixel 4a: fix build system issue causing device specific APN / carrier configuration to be omitted</li>
                        <li>support using the legacy wifi/cellular quick tiles (combined internet quick tile will still be used by default)</li>
                        <li>Dialer: improve swipe to accept/reject calls</li>
                        <li>Dialer: fix issue with USB headset audio routing</li>
                        <li>Dialer: add dark theme and fix issues tied to it</li>
                        <li>improve release signing and delta generation scripts</li>
                    </ul>
                </article>

                <article id="2021102020">
                    <h3><a href="#2021102020">2021102020</a></h3>

                    <p>This is the initial production release of GrapheneOS based on Android 12.
                    It's already fully functional and quite stable. Android 12 brings substantial
                    improvements to privacy, security, functionality, performance and aesthetics.
                    GrapheneOS features have been fully ported to Android 12 and also
                    substantially improved as part of the migration process. The release notes
                    below cover the full port of our features to Android 12 as a single entry in
                    the list and improvements beyond porting are listed separately.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/SP1A.210812.015.2021102020">SP1A.210812.015.2021102020</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021100606 release:</p>

                    <ul>
                        <li>full port of <a href="/features">all existing GrapheneOS features</a> to Android 12</li>
                        <li>full 2021-10-05 security patch level for userspace device support code (kernel already on 2021-10-05)</li>
                        <li>rebased onto SP1A.210812.015 release</li>
                        <li>Sandboxed Google Play compatibility layer: add support for Play services Android 12 releases (Android 11 releases still mostly work but we'll be recommending/mirroring the Android 12 releases)</li>
                        <li>make release signing otacerts.zip generation reproducible</li>
                        <li>Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: target ARMv8.2-DotProd architecture and Cortex-A76 CPU for ART and native code instead of producing generic ARMv8 code</li>
                        <li>use modern rounded corners by default</li>
                        <li>use new privacy indicators for location</li>
                        <li>raise permission usage history from 1 day to 7 days</li>
                        <li>enable permission history for all permission groups</li>
                        <li>use speed compiler filter for dexpreopt by default (converted from build configuration to build system to cover product/vendor/system_ext)</li>
                        <li>temporarily disable user-facing crash reporting for com.android.statementservice (Intent Filter Verification Service) due to an upstream AOSP 12 bug causing an uncaught exception when it tries to send too much data in the intents for jobs it runs via WorkManager</li>
                        <li>Launcher: backport multiple fixes from AOSP master</li>
                        <li>Launcher: enable new app open/close animations</li>
                        <li>Launcher: enable crossfade when changing theme</li>
                        <li>Launcher: enable new keyguard-to-launcher animation</li>
                        <li>Launcher: add Settings to center of default 5x5 dock</li>
                        <li>Launcher: add 2x2 workspace grid option</li>
                        <li>Launcher: reduce app label text size</li>
                        <li>Launcher: fix upstream issue causing missing screenshot button</li>
                        <li>Launcher: add ripple animation to task menu items</li>
                        <li>Launcher: fix all apps header color in dark mode</li>
                        <li>Launcher: fix Personal/Work profile tab colors in All Apps</li>
                        <li>Launcher: improve search bar UI in All Apps</li>
                        <li>SystemUI: change default quick tiles and quick tile order</li>
                        <li>Settings: update screen reader configuration for TalkBack so it shows up as a system screen reader again</li>
                        <li>Settings: add dark mode support for app installation restriction icon</li>
                        <li>SetupWizard: update to latest upstream code</li>
                        <li>SetupWizard: remove mention of pattern unlock in strings</li>
                        <li>System Updater: update to target API level 31 (Android 12)</li>
                        <li>System Updater: use Android 12 foreground service setup</li>
                        <li>Vanadium: update Chromium base to 94.0.4606.80</li>
                        <li>Vanadium: update Chromium base to 94.0.4606.85</li>
                        <li>Vanadium: update Chromium base to 95.0.4638.50</li>
                        <li>Vanadium: temporarily disable dexpreopt for browser and WebView (but not the library) due to <a href="https://source.android.com/docs/core/runtime/art-class-loader-context">lack of support in the Android 12 dexpreopt system</a></li>
                        <li>Seedvault: update to latest revision</li>
                        <li>TalkBack (screen reader): set app label to TalkBack</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/34">version 34</a></li>
                    </ul>
                </article>

                <article id="2021100606">
                    <h3><a href="#2021100606">2021100606</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.211001.001.2021100606">RQ3A.211001.001.2021100606</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RD2A.211001.002.2021100606">RD2A.211001.002.2021100606</a> (Pixel 5a)</li>
                    </ul>

                    <p>Changes since the 2021100502 release:</p>

                    <ul>
                        <li>backport of the Android 12 GrapheneOS Pixel kernels to Android 11 GrapheneOS including the full 2021-10-05 kernel patch level (full set of fixes for firmware and userspace aren't public yet and will be provided by the upcoming release of Android 12 for Pixels)</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 5, Pixel 5a): rebase onto Android 12 SP1A.210812.016 kernel releases</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 5, Pixel 5a): temporarily disable unnecessary DEBUG_NOTIFIERS feature (type-based CFI obsoletes it as a security feature) due to an incompatibility with the updated Android 12 kernel LLVM toolchain (discovered issue is benign but we'll be fixing it in a future release)</li>
                    </ul>
                </article>

                <article id="2021100502">
                    <h3><a href="#2021100502">2021100502</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.211001.001.2021100502">RQ3A.211001.001.2021100502</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RD2A.211001.002.2021100502">RD2A.211001.002.2021100502</a> (Pixel 5a)</li>
                    </ul>

                    <p>Changes since the 2021100103 release:</p>

                    <ul>
                        <li>full 2021-10-01 security patch level</li>
                        <li>partial 2021-10-05 security patch level (full set of fixes aren't public yet and will be provided by the upcoming release of Android 12 for Pixels)</li>
                        <li>rebased onto RQ3A.211001.001 and RD2A.211001.002 releases</li>
                        <li>drop our downstream workaround for use-after-free vulnerability in init now that the issue we reported is fixed upstream</li>
                    </ul>
                </article>

                <article id="2021100103">
                    <h3><a href="#2021100103">2021100103</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210905.001.2021100103">RQ3A.210905.001.2021100103</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RD2A.210905.003.2021100103">RD2A.210905.003.2021100103</a> (Pixel 5a)</li>
                    </ul>

                    <p>Changes since the 2021092612 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 94.0.4606.71</li>
                        <li>change generated carrier configurations to always allow editing APNs</li>
                        <li>always show APN settings on CDMA carriers</li>
                        <li>automate APN / carrier settings updates</li>
                    </ul>
                </article>

                <article id="2021092612">
                    <h3><a href="#2021092612">2021092612</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210905.001.2021092612">RQ3A.210905.001.2021092612</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RD2A.210905.003.2021092612">RD2A.210905.003.2021092612</a> (Pixel 5a)</li>
                    </ul>

                    <p>Changes since the 2021092220 release:</p>

                    <ul>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): apply upstream fix for ION use-after-free vulnerability</li>
                        <li>Vanadium: update Chromium base to 94.0.4606.61</li>
                        <li>android-prepare-vendor: remove a bunch of unused code / functionality</li>
                        <li>android-prepare-vendor: skip all kernel modules</li>
                    </ul>
                </article>

                <article id="2021092220">
                    <h3><a href="#2021092220">2021092220</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210905.001.2021092220">RQ3A.210905.001.2021092220</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RD2A.210905.003.2021092220">RD2A.210905.003.2021092220</a> (Pixel 5a)</li>
                    </ul>

                    <p>Changes since the 2021091407 release:</p>

                    <ul>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/32">version 32</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/33">version 33</a></li>
                        <li>Vanadium: update Chromium base to 94.0.4606.50</li>
                        <li>TalkBack (screen reader): update SDK and build tools versions</li>
                        <li>clean up build scripts</li>
                    </ul>
                </article>

                <article id="2021091407">
                    <h3><a href="#2021091407">2021091407</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210905.001.2021091407">RQ3A.210905.001.2021091407</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RD2A.210905.003.2021091407">RD2A.210905.003.2021091407</a> (Pixel 5a)</li>
                    </ul>

                    <p>Changes since the 2021090819 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: stub out DeviceConfig APIs by ignoring device configuration writes instead of throwing a SecurityException</li>
                        <li>Sandboxed Google Play compatibility layer: stub out DropBoxManager API by pretending no crash dumps, logs, etc. are available instead of throwing a SecurityException</li>
                        <li>Sandboxed Google Play compatibility layer: stub out getImei API by pretending IMEI cannot be retrieved instead of throwing a SecurityException</li>
                        <li>Seedvault: add missing permission needed for UserManager restriction security fix in the last release</li>
                        <li>Seedvault: update to latest revision</li>
                        <li>TalkBack (screen reader): update base version to 370044210 and port our changes (Switch Access service has been dropped upstream)</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/30">version 30</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/31">version 31</a></li>
                        <li>Vanadium: update Chromium base to 93.0.4577.82</li>
                    </ul>
                </article>

                <article id="2021090819">
                    <h3><a href="#2021090819">2021090819</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210905.001.2021090819">RQ3A.210905.001.2021090819</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RD2A.210905.003.2021090819">RD2A.210905.003.2021090819</a> (Pixel 5a)</li>
                    </ul>

                    <p>Changes since the 2021090401 release:</p>

                    <ul>
                        <li>full 2021-09-01 security patch level</li>
                        <li>full 2021-09-05 security patch level</li>
                        <li>rebased onto RQ3A.210905.001 and RD2A.210905.003 releases</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): use device-specific dtbo.img</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, Pixel 5a: update APNs</li>
                        <li>Pixel 5a: add missing configuration for biometric sensors (fingerprint sensor)</li>
                        <li>Pixel 5a: declare Pixel features are available so that apps with Pixel-specific features will use them</li>
                        <li>Seedvault: respect UserManager restrictions on app installation to avoid providing a way to bypass device management restrictions</li>
                        <li>Seedvault: show experimental restore backup option in backup settings instead of only supporting restore in the initial setup wizard</li>
                    </ul>
                </article>

                <article id="2021090401">
                    <h3><a href="#2021090401">2021090401</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210805.001.A1.2021090401">RQ3A.210805.001.A1.2021090401</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RD2A.210605.007.2021090401">RD2A.210605.007.2021090401</a> (Pixel 5a)</li>
                    </ul>

                    <p>Changes since the 2021082501 release:</p>

                    <ul>
                        <li>add experimental Pixel 5a support via device support branch</li>
                        <li>Settings: add back past GrapheneOS feature for toggling whether secondary users can install new apps</li>
                        <li>Vanadium: update Chromium base to 92.0.4515.166</li>
                        <li>Vanadium: update Chromium base to 93.0.4577.62</li>
                        <li>Vanadium: hide sign in preference when disallowed</li>
                        <li>Vanadium: disable using Play services as a source for certain Google fonts</li>
                        <li>automatically disable UART debugging when flashing factory images (GrapheneOS already extends the notification about it to production builds)</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/29">version 29</a></li>
                        <li>SetupWizard: properly disable system UI navigation for the entire setup process</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): drop unnecessary Wi-Fi driver change from our previous downstream security fixes</li>
                        <li>Pixel 4, Pixel 4 XL: enable saturated color option</li>
                    </ul>
                </article>

                <article id="2021082501">
                    <h3><a href="#2021082501">2021082501</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210805.001.A1.2021082501">RQ3A.210805.001.A1.2021082501</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021081822 release:</p>

                    <ul>
                        <li>System Updater: move settings into a preference category</li>
                        <li>System Updater: add detailed information to the error messages</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/28">version 28</a></li>
                        <li>Vanadium: move search suggestions toggle to privacy menu</li>
                        <li>Vanadium: remove empty account category and Services menu from the main menu</li>
                        <li>Sandboxed Google Play compatibility layer: add shim to make Play services use the regular cellular geolocation API instead of attempting and failing to use a special API requiring MODIFY_PHONE_STATE to attribute power consumption to the app responsible for the request to Play services</li>
                        <li>Sandboxed Google Play compatibility layer: add shims making Play services use the unprivileged AppOps proxy API instead of attempting and failing to use the privileged APIs for blaming other apps (it can still blame other apps via the proxy API, but the OS treats it as an untrusted claim)</li>
                        <li>Sandboxed Google Play compatibility layer: add shim making Play services use UserManager.hasUserRestriction instead of UserManager.hasBaseUserRestriction to avoid requiring privileged permissions and to return correct answers since it can't bypass device management</li>
                    </ul>
                </article>

                <article id="2021081822">
                    <h3><a href="#2021081822">2021081822</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210805.001.A1.2021081822">RQ3A.210805.001.A1.2021081822</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021081411 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 92.0.4515.159</li>
                        <li>Vanadium: improved implementation of not giving the default search engine permissions now that Chromium has support for it</li>
                        <li>System Updater: avoid error messages being truncated by using expandable notifications for them</li>
                        <li>Settings: fix upstream bug preventing setting pictures for user profiles</li>
                        <li>Settings: backport upstream fix for user edit dialog breaking from rotation</li>
                        <li>Settings: add LTE only mode entry when carrier enables world mode too</li>
                        <li>Sandboxed Google Play compatibility layer: fix detection of system processes in secondary users</li>
                        <li>Sandboxed Google Play compatibility layer: handle edge case of packages without data directories</li>
                    </ul>
                </article>

                <article id="2021081411">
                    <h3><a href="#2021081411">2021081411</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210805.001.A1.2021081411">RQ3A.210805.001.A1.2021081411</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.08.09.02 release:</p>

                    <ul>
                        <li>remove periods from build number (2nd half of the full version) to improve compatibility with apps wrongly assuming they can parse it as an integer (including Google Camera for Night Sight feature detection)</li>
                        <li>Settings: add 3rd option to connectivity check setting for disabling it (will prevent falling back to other networks from a broken one and handling captive portals)</li>
                        <li>Settings: ignore carrier asking the OS not to show the preferred network setting, similar to how we already ignore being instructed to disallow tethering</li>
                        <li>further fixes for the upstream code implementing the eBPF-based INTERNET permission (fixes cases where it was overly restrictive for secondary users, but we already prevented it from being overly permissive by adding back the simpler pre-eBPF approach as a 2nd layer of enforcement)</li>
                        <li>Sandboxed Google Play compatibility layer: disable shared user id check since it isn't relevant to GrapheneOS and it appears that it may be causing issues</li>
                    </ul>
                </article>

                <article id="2021.08.09.02">
                    <h3><a href="#2021.08.09.02">2021.08.09.02</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210805.001.A1.2021.08.09.02">RQ3A.210805.001.A1.2021.08.09.02</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.08.03.03 release:</p>

                    <ul>
                        <li>Sandboxed Google Play compatibility layer: add infrastructure / shims to support dynamite modules (dynamically loaded modules including Maps API support)</li>
                        <li>Vanadium: update Chromium base to 92.0.4515.131</li>
                        <li>Vanadium: disable trials of privacy-aware analytics/advertising APIs</li>
                        <li>Vanadium: remove unwanted sync and services link</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: update APNs</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: update CarrierConfig vendor.xml</li>
                    </ul>
                </article>

                <article id="2021.08.03.03">
                    <h3><a href="#2021.08.03.03">2021.08.03.03</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210805.001.A1.2021.08.03.03">RQ3A.210805.001.A1.2021.08.03.03</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.07.26.20 release:</p>

                    <ul>
                        <li>full 2021-08-01 security patch level</li>
                        <li>full 2021-08-05 security patch level</li>
                        <li>rebased onto RQ3A.210805.001.A1 release</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): backport implementation of <a href="https://datatracker.ietf.org/doc/html/rfc8981">IPv6 temporary addresses (RFC4941)</a> as a replacement for the legacy privacy address implementation, removing the need for our work on mitigating the issues with them (still used for older generation devices)</li>
                        <li>System Updater: use <em>System Updater</em> as the app name</li>
                        <li>System Updater: show when status notifications occurred</li>
                        <li>System Updater: add notification settings shortcut to update settings</li>
                        <li>Sandboxed Google Play compatibility layer: add compatibility shims for secondary user support</li>
                        <li>Sandboxed Google Play compatibility layer: use unified GmsCompat/ prefix for log tags</li>
                        <li>Sandboxed Google Play compatibility layer: add shim for AppOpsManager#startOpNoThrow</li>
                        <li>Sandboxed Google Play compatibility layer: move foreground service notification channel to dedicated Compatibility notification channel group</li>
                        <li>Sandboxed Google Play compatibility layer: add proper description to foreground service notification</li>
                        <li>Sandboxed Google Play compatibility layer: add shortcut for opening the notification channel settings from the foreground service notifications</li>
                    </ul>
                </article>

                <article id="2021.07.26.20">
                    <h3><a href="#2021.07.26.20">2021.07.26.20</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210705.001.2021.07.26.20">RQ3A.210705.001.2021.07.26.20</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.07.19.18 release:</p>

                    <ul>
                        <li>System Updater: add detailed failure / success notifications. The next release will enable the timestamp to show when it happened. You can turn off the 'Already Updated' notification channel if you don't want those minimum priority notifications with no status icon collapsed at the bottom.</li>
                        <li>Vanadium: update Chromium base to 92.0.4515.105</li>
                        <li>Vanadium: update Chromium base to 92.0.4515.115</li>
                        <li>Vanadium: drop removal of speculative service worker start for search</li>
                        <li>init: fix use-after-free from event handling callbacks (issue uncovered by hardened_malloc in certain situations like unplugging a USB keyboard, etc.)</li>
                        <li>fix PermissionController UI for Sensors/Network permissions with legacy API &lt; 23 apps (i.e. apps without proper support for Android Marshmallow and beyond)</li>
                        <li>Sandboxed Google Play compatibility layer: disable badge for foreground service notification by default</li>
                        <li>Settings: drop support for showing nearby devices from Play since it can't function without Play having any special privileges</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL): improve support for hosting servers by enabling SYN cookies for denial of service resistance like newer generation devices</li>
                        <li>hardened_malloc: update libdivide to 5.0</li>
                    </ul>
                </article>

                <article id="2021.07.19.18">
                    <h3><a href="#2021.07.19.18">2021.07.19.18</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210705.001.2021.07.19.18">RQ3A.210705.001.2021.07.19.18</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.07.16.19 release:</p>

                    <ul>
                        <li>Settings: fix displaying setting for GrapheneOS USB accessory policy (deny new usb)</li>
                        <li>Settings: hide insecure pattern lock option (either use a randomly generated 6-8 digit PIN for secure encryption based on secure element throttling or a strong randomly generated passphrase to avoid depending on the secure element, not this misguided pattern option with ridiculously low entropy)</li>
                        <li>Sandboxed Google Play compatibility layer: return false for SIM card lock check rather than throwing a SecurityException</li>
                        <li>Sandboxed Google Play compatibility layer: avoid throwing an exception in certain edge cases for secondary users when checking whether the compatibility shims should be enabled for a process (i.e. when checking if the process is one of the 3 core Play apps)</li>
                        <li>Vanadium: update Chromium base to 91.0.4472.164</li>
                    </ul>
                </article>

                <article id="2021.07.16.19">
                    <h3><a href="#2021.07.16.19">2021.07.16.19</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210705.001.2021.07.16.19">RQ3A.210705.001.2021.07.16.19</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.07.07.19 release:</p>

                    <ul>
                        <li>add <a href="/usage#sandboxed-google-play">experimental support for running Play services and friends as sandboxed user-installed apps without any special privileges</a></li>
                        <li>Settings: use alternate implementation of Wi-Fi auto-turn-off setting matching the Bluetooth auto-turn-off UX</li>
                        <li>overhaul Wi-Fi auto-turn-off implementation including handling the case of Wi-Fi being turned on without connecting to a network</li>
                        <li>add lower auto-reboot timeout options</li>
                        <li>display notification when UART is enabled in the bootloader configuration for user builds too (where it isn't supported by userspace, but still provides firmware and kernel logs) rather than only in userdebug builds</li>
                        <li>Seedvault: update to latest revision</li>
                        <li>Seedvault: switch to GrapheneOS fork with intent access restricted to prevent other apps from spawning the activities</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: set product brand to hardware brand</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: remove aosp_ prefix from product names</li>
                    </ul>
                </article>

                <article id="2021.07.07.19">
                    <h3><a href="#2021.07.07.19">2021.07.07.19</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210705.001.2021.07.07.19">RQ3A.210705.001.2021.07.07.19</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.06.20.20 release:</p>

                    <ul>
                        <li>full 2021-07-01 security patch level</li>
                        <li>full 2021-07-05 security patch level</li>
                        <li>rebased onto RQ3A.210705.001 release</li>
                        <li>reimplement Bluetooth auto-turn-off feature to avoid using the Settings app for the implementation (fixes reliability issues)</li>
                        <li>add experimental Wi-Fi auto-turn-off feature based on reimplementation of Bluetooth auto-turn-off (will not kick in when Wi-Fi is turned on without connecting to a network until the next release)</li>
                        <li>System Updater: display progress for the short phase of verifying the update</li>
                        <li>System Updater: reuse the same progress notification for downloading, verifying and installing the update</li>
                        <li>System Updater: only alert once for progress notifications if the user raises the notification importance level</li>
                        <li>System Updater: use foreground service via progress notification</li>
                        <li>Vanadium: update Chromium base to 91.0.4472.120</li>
                        <li>Vanadium: update Chromium base to 91.0.4472.134</li>
                        <li>Seedvault: update to latest revision</li>
                    </ul>
                </article>

                <article id="2021.06.20.20">
                    <h3><a href="#2021.06.20.20">2021.06.20.20</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210605.005.2021.06.20.20">RQ3A.210605.005.2021.06.20.20</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.06.09.13 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 91.0.4472.101</li>
                        <li>Vanadium: update Chromium base to 91.0.4472.114</li>
                        <li>Vanadium: add toggle to Privacy and security settings for <a href="https://v8.dev/blog/jitless">disabling JIT compilation and using fully interpreted JavaScript via fast interpreter</a></li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): fix upstream module load order issues when modules are built into the kernel</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): build in every module and disable dynamic kernel module support again to restore finer-grained Control Flow Integrity (CFI) and attack surface reduction</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5): generate a new privacy address when connecting to a network as a temporary partial workaround for the broken upstream privacy address implementation before Linux 5.8 (the privacy address standard itself was flawed and Linux 5.8+ has an implementation of the fixed standard, which we've suggested that Android backport in our upstream report)</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: declare Pixel features are available so that apps with Pixel-specific features will use them</li>
                    </ul>
                </article>

                <article id="2021.06.09.13">
                    <h3><a href="#2021.06.09.13">2021.06.09.13</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210605.005.2021.06.09.13">RQ3A.210605.005.2021.06.09.13</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.06.08.06 release:</p>

                    <ul>
                        <li>re-enable current camera/microphone privacy indicator implementation</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): use new GNU assembler (gas) prebuilts and drop all other usage of the GNU toolchain since LLVM provides everything else (LLVM assembler is used for userspace, but can't yet handle the Linux kernel)</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): temporarily move to building and using dynamic kernel modules (same list as AOSP) to work around new issues with monolithic builds until we have time to resolve it to improve CFI granularity again</li>
                        <li>android-prepare-vendor (Pixel 4a (5G), Pixel 5): remove previously unused stock OS kernel modules now that we're temporarily enabling dynamic kernel module support so that only our builds of kernel modules are being used</li>
                        <li>System Updater: add support for custom accent color</li>
                    </ul>
                </article>

                <article id="2021.06.08.06">
                    <h3><a href="#2021.06.08.06">2021.06.08.06</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ3A.210605.005.2021.06.08.06">RQ3A.210605.005.2021.06.08.06</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.05.29.09 release:</p>

                    <ul>
                        <li>full 2021-06-01 security patch level</li>
                        <li>full 2021-06-05 security patch level</li>
                        <li>rebased onto RQ3A.210605.005 release, initial release of Android 11 QPR3 (Quarterly Platform Release 3)</li>
                        <li>experimental new feature for configuring auto-reboot after N hours of the device being locked to put all logged in user profiles back at rest (i.e. data inaccessible to the OS until logged in again) when the device isn't in your possession</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): apply fixes for 2 Qualcomm Wi-Fi driver vulnerabilities from CAF missed in the upstream December 2020 security update for Pixels</li>
                        <li>Vanadium: update Chromium base to 91.0.4472.88</li>
                        <li>android-prepare-vendor: fix resuming image downloads due to broken HTTP/2 server semantics</li>
                        <li>Settings: fix hardcoded black text in storage summary</li>
                        <li>remove redundant property for disabling OpenGL preloading</li>
                        <li>update kernel build tools used for Pixel 4a (5G), Pixel 5 and beyond</li>
                    </ul>
                </article>

                <article id="2021.05.29.09">
                    <h3><a href="#2021.05.29.09">2021.05.29.09</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210505.002.2021.05.29.09">RQ2A.210505.002.2021.05.29.09</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210505.003.2021.05.29.09">RQ2A.210505.003.2021.05.29.09</a> (Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.05.19.06 release:</p>

                    <ul>
                        <li>prevent DHCP (IPv4) from reusing state across connections to the same network when full MAC randomization is enabled</li>
                        <li>Vanadium: update Chromium base to 91.0.4472.77</li>
                        <li>Vanadium: enable opportunistic HTTPS by default</li>
                        <li>Vanadium: disable mobile identity consistency by default</li>
                        <li>revert our change adding the screenshot button to the power menu for 3-button navigation since it's provided by the recent apps activity for both gesture and 3-button navigation (we originally added it back for both 2-button and 3-button navigation even though it was only needed for 2-button navigation, and then the stock OS implemented the same fix only for 2-button navigation, which makes more sense)</li>
                    </ul>
                </article>

                <article id="2021.05.19.06">
                    <h3><a href="#2021.05.19.06">2021.05.19.06</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210505.002.2021.05.19.06">RQ2A.210505.002.2021.05.19.06</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210505.003.2021.05.19.06">RQ2A.210505.003.2021.05.19.06</a> (Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.05.16.04 release:</p>

                    <ul>
                        <li>Settings: remove field referencing the mainline module (APEX) version (also known as the Google Play system update version) since we ship these changes as part of the OS and have out-of-band module updates disabled since we have no use for them</li>
                        <li>remove legacy Calendar widget</li>
                        <li>add toggle for disabling fingerprint unlock while having fingerprints registered for usage in apps (authentication and protecting hardware keystore keys)</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/27">version 27</a></li>
                    </ul>
                </article>

                <article id="2021.05.16.04">
                    <h3><a href="#2021.05.16.04">2021.05.16.04</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210505.002.2021.05.16.04">RQ2A.210505.002.2021.05.16.04</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210505.003.2021.05.16.04">RQ2A.210505.003.2021.05.16.04</a> (Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.05.04.01 release:</p>

                    <ul>
                        <li>enable gesture navigation by default (see <a href="/usage#system-navigation">our guide on system navigation</a> for details on using gesture navigation and switching to a button-based navigation)</li>
                        <li>System Updater: fix minor theme issue for light theme when pressing preferences</li>
                        <li>replace our workaround for an upstream user profile crash issue with a proper upstream fix from Sony</li>
                        <li>replace our workaround for another upstream user profile crash issue with a proper fix based on the approach of the fix from Sony</li>
                        <li>Vanadium: update Chromium base to 90.0.4430.210</li>
                        <li>hardened_malloc: purge memory even if VMA exhaustion causes munmap or MAP_FIXED mmap calls to fail</li>
                        <li>hardened_malloc: increase class region size on x86_64 to 32GiB</li>
                        <li>hardened_malloc: increase class region size on arm64 to 2GiB (should be 32GiB on devices where we've enabled 4-level page tables but that requires setting up build configuration infrastructure)</li>
                        <li>raise vm.max_map_count further to have even more leeway before VMA exhaustion occurs from fine-grained guard regions</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): fix build reproducibility issue by backporting upstream fix</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5): make CONFIG_LOCALVERSION_AUTO ignore Git tags so adding tags doesn't change the result of a build</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5): apply fixes for 2 Qualcomm audio driver vulnerabilities from CAF including one missed in the upstream May 2021 security update for Pixels</li>
                        <li>kernel (Pixel 4a): apply fix for use-after-free in GPU driver missed in the upstream security updates for the Pixel 4a</li>
                        <li>switch HTTPS network time URL from <code>/</code> to <code>/generate_204</code> to allow for a future <code>/</code> redirect</li>
                    </ul>
                </article>

                <article id="2021.05.04.01">
                    <h3><a href="#2021.05.04.01">2021.05.04.01</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210505.002.2021.05.04.01">RQ2A.210505.002.2021.05.04.01</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210505.003.2021.05.04.01">RQ2A.210505.003.2021.05.04.01</a> (Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.04.22.20 release:</p>

                    <ul>
                        <li>full 2021-05-01 security patch level</li>
                        <li>full 2021-05-05 security patch level</li>
                        <li>rebased onto RQ2A.210505.003 release</li>
                        <li>enable backup service for non-owner users so that secondary users can be backed up</li>
                        <li>add SetupWizard activities for secondary users including support for restoring backups</li>
                        <li>Settings (Accessibility): add Monochromacy (grayscale) option to color correction</li>
                        <li>improve the newer generation eBPF-based implementation of the INTERNET permission to properly support revoking the permission in secondary profiles (we'll be keeping our restoration of the much simpler non-eBPF-based approach to avoid relying on this on devices using our hardened kernels) </li>
                        <li>Vanadium: update Chromium base to 90.0.4430.91</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: set slot number for eSIM (still need an eSIM activation app since it's one of the remaining missing components from not including Google apps and services)</li>
                        <li>hardened_malloc: use 1 slot for all extended size classes (reduces memory usage and improves security in combination with the guard slab feature)</li>
                        <li>use system theme accent color for fingerprint dialog instead of teal</li>
                        <li>integrate modern Android theme and wallpaper configuration</li>
                        <li>remove legacy WallpaperPicker app</li>
                        <li>System Updater: modernize update settings via androidx preference library (new theme has minor quirks we'll be fixing in the next release)</li>
                        <li>use alternate grapheneos.online domain for connectivity check / captive portal fallback URLs to improve handling of future issues comparable to Quad9 temporarily blocking grapheneos.network due to some kind of false positive</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: update APNs</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: update CarrierConfig vendor.xml</li>
                    </ul>
                </article>

                <article id="2021.04.22.20">
                    <h3><a href="#2021.04.22.20">2021.04.22.20</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210405.005.2021.04.22.20">RQ2A.210405.005.2021.04.22.20</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.04.16.04 release:</p>

                    <ul>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5): update our change to use max ASLR entropy before the init process enables it for the larger address space enabled by GrapheneOS</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5): add back hard-wired check for the INTERNET permission on socket creation at least until the eBPF code is improved and fixed to work properly for secondary profiles</li>
                        <li>Vanadium: disable unused FLOC feature</li>
                        <li>Vanadium: update Chromium base to 90.0.4430.82</li>
                    </ul>
                </article>

                <article id="2021.04.16.04">
                    <h3><a href="#2021.04.16.04">2021.04.16.04</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210405.005.2021.04.16.04">RQ2A.210405.005.2021.04.16.04</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.04.05.20 release:</p>

                    <ul>
                        <li>kernel (Pixel 4a (5G), Pixel 5): rebuild with updated techpack/camera submodule</li>
                        <li>add back support for fully disabling native debugging (ptrace) support in <b>Settings&#160;<span aria-label="and then">></span> Security</b></li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5): enable support for native debugging (ptrace) toggle via Yama</li>
                        <li>Settings: add back extra field with bootloader version</li>
                        <li>Settings: only allow disabling Vanadium WebView library via developer tools since disabling it breaks app compatibility and almost always results in crashes rather than user friendly errors, including for base OS components using it</li>
                        <li>Vanadium: update Chromium base to 90.0.4430.66</li>
                        <li>Vanadium: fully disable autofill assistant</li>
                        <li>Vanadium: disable unused autofill assistant configuration</li>
                        <li>Vanadium: disable speculative service worker start by default</li>
                        <li>Vanadium: disable safety check for Android by default</li>
                        <li>Vanadium: disable new interest feed feature too</li>
                        <li>Vanadium: disable unused password check feature</li>
                    </ul>
                </article>

                <article id="2021.04.05.20">
                    <h3><a href="#2021.04.05.20">2021.04.05.20</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210405.005.2021.04.05.20">RQ2A.210405.005.2021.04.05.20</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.03.30.02 release:</p>

                    <ul>
                        <li>full 2021-04-01 security patch level</li>
                        <li>full 2021-04-05 security patch level</li>
                        <li>rebased onto RQ2A.210405.005 release</li>
                        <li>SetupWizard: rebrand to GrapheneOS for other languages</li>
                    </ul>
                </article>

                <article id="2021.03.30.02">
                    <h3><a href="#2021.03.30.02">2021.03.30.02</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210305.006.2021.03.30.02">RQ2A.210305.006.2021.03.30.02</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.03.19.14 release:</p>

                    <ul>
                        <li>hardened_malloc: add initial malloc_trim slab quarantine purging to reduce system memory usage from the slab quarantine without sacrificing security</li>
                        <li>Vanadium: update Chromium base to 89.0.4389.105</li>
                        <li>android-prepare-vendor (Pixel 4a (5G), Pixel 5): stop incorrectly treating new vendor_boot partition as a firmware partition and use our own build</li>
                        <li>SetupWizard: update to latest upstream code</li>
                    </ul>
                </article>

                <article id="2021.03.19.14">
                    <h3><a href="#2021.03.19.14">2021.03.19.14</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210305.006.2021.03.19.14">RQ2A.210305.006.2021.03.19.14</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.03.06.00 release:</p>

                    <ul>
                        <li>integrate the latest open source release of TalkBack and Switch Access as first party accessibility services again (a text-to-speech service like RHVoice needs to be installed, configured and enabled to be able to use TalkBack)</li>
                        <li>SELinux policy: add back removing tmpfs execute for all base system app domains</li>
                        <li>SELinux policy: expand exception from ashmem execute restriction to legacy non-base system app domains (was more strict than currently intended since we don't want to break app compatibility)</li>
                        <li>add Bluetooth timeout feature with a security fix applied to the original implementation</li>
                        <li>System Updater: rename title of the management activity launched via Settings</li>
                        <li>set GrapheneOS launcher as a default notification listener on fresh installs so that the default enabled notification integration is permitted by default like the stock OS (existing users still need to manually enable the permission for the built-in launcher)</li>
                        <li>add back removing DUN requirement for tethering</li>
                        <li>add back ignoring tethering provisioning requirement</li>
                        <li>enable app compaction by default</li>
                        <li>enable app freezer by default</li>
                        <li>enable camera/microphone usage indicators by default</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5): switch from standard 39-bit address space to 48-bit address space via 4-level page tables</li>
                        <li>Vanadium: update Chromium base to 89.0.4389.86</li>
                        <li>Vanadium: update Chromium base to 89.0.4389.90</li>
                        <li>Vanadium: enable partitioning connections by default</li>
                        <li>hardened_malloc: update libdivide to 4.0.0</li>
                        <li>hardened_malloc: use longer region quarantine random array (256 regions instead of 128)</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/26">version 26</a></li>
                    </ul>
                </article>

                <article id="2021.03.06.00">
                    <h3><a href="#2021.03.06.00">2021.03.06.00</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210305.006.2021.03.06.00">RQ2A.210305.006.2021.03.06.00</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.03.02.10 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 89.0.4389.72</li>
                        <li>Vanadium: enable user agent freeze by default</li>
                        <li>Vanadium: disable building code as dynamic feature modules</li>
                        <li>kernel (Pixel 4a): fix techpack/audio build reproducibility issue</li>
                        <li>backport upstream fix for building on compressed filesystems</li>
                        <li>Calendar: remove launcher icon since the app exists for compatibility / testing</li>
                        <li>Seedvault: update to latest revision</li>
                    </ul>
                </article>

                <article id="2021.03.02.10">
                    <h3><a href="#2021.03.02.10">2021.03.02.10</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ2A.210305.006.2021.03.02.10">RQ2A.210305.006.2021.03.02.10</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.02.26.16 release:</p>

                    <ul>
                        <li>full 2021-03-01 security patch level</li>
                        <li>full 2021-03-05 security patch level</li>
                        <li>rebased onto RQ2A.210305.006 release, initial release of Android 11 QPR2 (Quarterly Platform Release 2)</li>
                        <li>Settings (Pixel 4, Pixel 4 XL, Pixel 5): enable refresh rate control</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: update APNs</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: update CarrierConfig vendor.xml</li>
                        <li>Pixel 4a: fix SystemUI memory pinning</li>
                    </ul>
                </article>

                <article id="2021.02.26.16">
                    <h3><a href="#2021.02.26.16">2021.02.26.16</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.210205.004.2021.02.26.16">RQ1A.210205.004.2021.02.26.16</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.02.23.15 release:</p>

                    <ul>
                        <li>hardened_malloc: add back workarounds for camera driver bugs on the Pixel 3, Pixel 3 XL, Pixel 3a and Pixel 3a XL</li>
                    </ul>
                </article>

                <article id="2021.02.23.15">
                    <h3><a href="#2021.02.23.15">2021.02.23.15</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.210205.004.2021.02.23.15">RQ1A.210205.004.2021.02.23.15</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.02.19.15 release:</p>

                    <ul>
                        <li>Camera: set flash mode to off by default (camera flash causes a
                        substantial delay and substantially lower image quality so it generally
                        isn't desirable)</li>
                        <li>system theme: use black for settings background in the dark theme</li>
                        <li>drop legacy code for setting Seedvault as the enabled backup service</li>
                        <li>hardened_malloc: drop workarounds for camera driver bugs on the Pixel 3, Pixel 3 XL, Pixel 3a and Pixel 3a XL</li>
                        <li>hardened_malloc: drop workaround for USB audio bug</li>
                    </ul>
                </article>

                <article id="2021.02.19.15">
                    <h3><a href="#2021.02.19.15">2021.02.19.15</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.210205.004.2021.02.19.15">RQ1A.210205.004.2021.02.19.15</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.02.07.17 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 88.0.4324.181</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: update APNs</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5: update CarrierConfig vendor.xml</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/24">version 24</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/25">version 25</a></li>
                        <li>Pixel 4a: set boot security patch level to leverage the YYYY-MM-01 vs. YYYY-MM-05 distinction for attestation</li>
                        <li>Pixel 4a (5G), Pixel 5: complete initial device support including porting hardening features</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): enable slab canary feature</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): set correct variable for 32-bit vdso toolchain</li>
                        <li>kernel (Pixel 5): disable unnecessary touch driver</li>
                        <li>kernel (Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5): use LLVM toolchain for everything other than the assembler</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): use LLVM toolchain for everything other than the assembler and target linker</li>
                        <li>kernel (Pixel 4a (5G), Pixel 5): use new kernel build-tools prebuilts repository</li>
                    </ul>
                </article>

                <article id="2021.02.07.17">
                    <h3><a href="#2021.02.07.17">2021.02.07.17</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.210205.004.2021.02.07.17">RQ1A.210205.004.2021.02.07.17</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.02.06.05 release:</p>

                    <ul>
                        <li>fix added error reporting code for HTTPS-based network time updates</li>
                        <li>Seedvault: update to latest revision</li>
                    </ul>
                </article>

                <article id="2021.02.06.05">
                    <h3><a href="#2021.02.06.05">2021.02.06.05</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.210205.004.2021.02.06.05">RQ1A.210205.004.2021.02.06.05</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, Pixel 4a (5G), Pixel 5, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.02.02.09 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 88.0.4324.152</li>
                        <li>rework the GrapheneOS HTTPS-based network time updates to enforce certificate expiry based on the OS build date for the whole certificate chain to avoid failing to fix significant time sync issues while still having a reasonable expiry check</li>
                    </ul>
                </article>

                <article id="2021.02.02.09">
                    <h3><a href="#2021.02.02.09">2021.02.02.09</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.210205.004.2021.02.02.09">RQ1A.210205.004.2021.02.02.09</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.01.23.03 release:</p>

                    <ul>
                        <li>full 2021-02-01 security patch level</li>
                        <li>full 2021-02-05 security patch level</li>
                        <li>rebased onto RQ1A.210205.004 release</li>
                        <li>Vanadium: update Chromium base to 88.0.4324.141</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): make more data read-only per newer device kernels</li>
                    </ul>
                </article>

                <article id="2021.01.23.03">
                    <h3><a href="#2021.01.23.03">2021.01.23.03</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.210105.002.2021.01.23.03">RQ1A.210105.002.2021.01.23.03</a> (Pixel 3a, Pixel 3a XL, Pixel 4a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.210105.003.2021.01.23.03">RQ1A.210105.003.2021.01.23.03</a> (Pixel 3, Pixel 3 XL, Pixel 4, Pixel 4 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2021.01.05.03 release:</p>

                    <ul>
                        <li>system theme: use slightly different accent color for the dark theme</li>
                        <li>Dialer: add carrier-specific visual voicemail configurations</li>
                        <li>Vanadium: update Chromium base to 87.0.4280.141</li>
                        <li>Vanadium: update Chromium base to 88.0.4324.93</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a): use UTC for kernel timestamp to make reproducible builds easier</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a): update toolchain's toybox prebuilt for various fixes including fixing an issue with the date command causing a build reproducibility issue</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a): apply upstream patch avoiding truncation of kernel debug symbol names generated when using Clang type-based CFI</li>
                        <li>adjust kernel configuration tests to permit disabling dynamic kernel modules for new kernel variants</li>
                        <li>fix dark theme issue with Settings app search panel</li>
                        <li>Camera2: backport fix for interaction with lockscreen</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a: update APNs with carriersettings-extractor</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a: add CarrierConfig vendor.xml from the stock OS with entries depending on Google and carrier apps stripped out</li>
                    </ul>
                </article>

                <article id="2021.01.05.03">
                    <h3><a href="#2021.01.05.03">2021.01.05.03</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.210105.002.2021.01.05.03">RQ1A.210105.002.2021.01.05.03</a> (Pixel 3a, Pixel 3a XL, Pixel 4a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.210105.003.2021.01.05.03">RQ1A.210105.003.2021.01.05.03</a> (Pixel 3, Pixel 3 XL, Pixel 4, Pixel 4 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.12.12.03 release:</p>

                    <ul>
                        <li>full 2021-01-01 security patch level</li>
                        <li>full 2021-01-05 security patch level</li>
                        <li>rebased onto RQ1A.210105.003 release</li>
                        <li>Settings: update GrapheneOS connectivity check URLs to match NetworkStack</li>
                        <li>Camera: remove unused Wi-Fi state permissions</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a: update APNs with carriersettings-extractor</li>
                        <li>adjust kernel configuration tests to permit not having BPF_JIT since we don't have it enabled</li>
                        <li>add check for empty TTS engine name to address upstream bug</li>
                        <li>Vanadium: enable split cache by default</li>
                        <li>Vanadium: add back legacy media file access support for now</li>
                        <li>Vanadium: rename WebView and library apps based on the vanadium.app domain</li>
                        <li>Seedvault: update to latest revision</li>
                        <li>remove unnecessary vendor overlays</li>
                        <li>SetupWizard: change OS name to GrapheneOS for backup activity strings again</li>
                        <li>fix use-after-free in adbd authentication which was breaking support for persistently trusting keys due to zero-on-free</li>
                        <li>system theme: use blue accent color</li>
                        <li>replace default AOSP wallpaper with a solid black wallpaper — may get a bit fancier in the near future</li>
                        <li>update round icon mask</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a: always use dark theme for boot chain firmware</li>
                        <li>Pixel 3a, Pixel 3a XL: disable unused dynamic kernel module support to match other devices</li>
                        <li>System Updater: disconnect keepalive connection when service is done</li>
                    </ul>
                </article>

                <article id="2020.12.12.03">
                    <h3><a href="#2020.12.12.03">2020.12.12.03</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.201205.003.2020.12.12.03">RQ1A.201205.003.2020.12.12.03</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.201205.008.2020.12.12.03">RQ1A.201205.008.2020.12.12.03</a> (Pixel 4, Pixel 4 XL, Pixel 4a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.201205.010.2020.12.12.03">RQ1A.201205.010.2020.12.12.03</a> (emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.12.08.08 release:</p>

                    <ul>
                        <li>Vanadium: disable WebView variations support</li>
                        <li>SetupWizard: update to latest upstream code</li>
                        <li>NetworkStack: switch to grapheneos.network for connectivity checks to improve compatibility with captive portals lacking support for the built-in login interface (HSTS preloading for grapheneos.org breaks the fallback browser login notification)</li>
                    </ul>
                </article>

                <article id="2020.12.08.08">
                    <h3><a href="#2020.12.08.08">2020.12.08.08</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.201205.003.2020.12.08.08">RQ1A.201205.003.2020.12.08.08</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.201205.008.2020.12.08.08">RQ1A.201205.008.2020.12.08.08</a> (Pixel 4, Pixel 4 XL, Pixel 4a)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RQ1A.201205.010.2020.12.08.08">RQ1A.201205.010.2020.12.08.08</a> (emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.11.27.15 release:</p>

                    <ul>
                        <li>full 2020-12-01 security patch level</li>
                        <li>full 2020-12-05 security patch level</li>
                        <li>rebased onto RQ1A.201205.010 release</li>
                        <li>script: support any number of source versions for deltas</li>
                        <li>set read timeout for HTTPS network time connections</li>
                        <li>disable keepalive for HTTPS network time connections</li>
                        <li>always disconnect HTTPS network time connections</li>
                        <li>remove unnecessary Accept-Charset header for HTTPS network time requests</li>
                        <li>Vanadium: ask permission to play protected media by default</li>
                        <li>Vanadium: disable autofill server communication by default</li>
                        <li>Vanadium: update Chromium base to 87.0.4280.86</li>
                        <li>Vanadium: update Chromium base to 87.0.4280.101</li>
                        <li>Settings: remove partial MAC randomization translations</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/23">version 23</a></li>
                        <li>downstream fix for VPN lockdown being overridden when stopping users replaced by upstream fix</li>
                    </ul>
                </article>

                <article id="2020.11.27.15">
                    <h3><a href="#2020.11.27.15">2020.11.27.15</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.201105.002.2020.11.27.15">RP1A.201105.002.2020.11.27.15</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.11.25.22 release:</p>

                    <ul>
                        <li>Vanadium: disable autofill assistant by default (restores previous Vanadium behavior)</li>
                        <li>Vanadium: backport upstream fix for missing manifest changes (this fixes issues with opening URLs in external apps)</li>
                        <li>Vanadium: disable component updater pings by default</li>
                        <li>Settings: disallow configuring connectivity checks for users disallowed to configure Private DNS by the administrator (in theory, it could be a separate option, but we need to use one that's already part of the public API)</li>
                    </ul>
                </article>

                <article id="2020.11.25.22">
                    <h3><a href="#2020.11.25.22">2020.11.25.22</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.201105.002.2020.11.25.22">RP1A.201105.002.2020.11.25.22</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.11.05.18 release:</p>

                    <ul>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/6">version 6</a></li>
                        <li>NFC: backport compatibility fix for certain broken apps from AOSP master</li>
                        <li>Bluetooth: backport fix for Bluetooth capacity string</li>
                        <li>Vanadium: update Chromium base to 86.0.4240.198</li>
                        <li>Vanadium: update Chromium base to 87.0.4280.66</li>
                        <li>Vanadium: disable new high-level functionality for fetching variations</li>
                        <li>Vanadium: disable unused Omaha update check support</li>
                        <li>Vanadium: disable GaiaAuthFetcher code due to upstream bug</li>
                        <li>Vanadium: disable deprecated FTP support by default</li>
                        <li>Pixel 4 XL: correctly mark certain unsupported features as unavailable per the Pixel 4</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a: use device-specific NFC configuration</li>
                        <li>add initial runtime flags handling for exec-based spawning to improve compatibility</li>
                        <li>Pixel 3, Pixel 3 XL, Pixel 4, Pixel 4 XL, Pixel 4a: disable chained vbmeta to simplify verified boot and improve attestation (Pixel 3a and Pixel 3a XL never used this)</li>
                        <li>Seedvault: update to latest revision</li>
                        <li>NetworkStack: remove change to connectivity check handling that's no longer required with Android 11</li>
                        <li>use GrapheneOS connectivity check server by default for connectivity checks in the OS</li>
                        <li>Settings: add setting to toggle between GrapheneOS connectivity check server and the standard Android connectivity check URLs to continue supporting blending in with other Android devices without a VPN</li>
                        <li>System Updater: remove unused READ_PHONE_STATE permission</li>
                    </ul>
                </article>

                <article id="2020.11.05.18">
                    <h3><a href="#2020.11.05.18">2020.11.05.18</a></h3>

                    <p>While waiting for this release to become available, you can manually add a
                    battery optimization exemption for the Clock app via <b>Settings&#160;<span
                    aria-label="and then">></span> Apps &amp; notifications&#160;<span
                    aria-label="and then">></span> Special app access&#160;<span aria-label="and then">></span>
                    Battery optimization</b> where you can select <b>All apps</b>, scroll
                    down to the Clock app and manually add an exemption. Should get this added upstream.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.201105.002.2020.11.05.18">RP1A.201105.002.2020.11.05.18</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.11.03.03 release:</p>

                    <ul>
                        <li>Clock: add battery optimization exemption required for the new target API level (this is missing in AOSP)</li>
                    </ul>
                </article>

                <article id="2020.11.03.03">
                    <h3><a href="#2020.11.03.03">2020.11.03.03</a></h3>

                    <p>Pixel 2 and Pixel 2 XL support will now be provided via separate extended support
                    releases for obsolete devices. We'll be making the first one based on an official
                    release in the near future. They can only reach the 2020-11-01 security patch this
                    month due to the lack of a release with changes outside the scope of AOSP such as new
                    GPU firmware.</p>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.201105.002.2020.11.03.03">RP1A.201105.002.2020.11.03.03</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.10.23.04 release:</p>

                    <ul>
                        <li>full 2020-11-01 security patch level</li>
                        <li>full 2020-11-05 security patch level</li>
                        <li>rebased onto RP1A.201105.002 release</li>
                        <li>Vanadium: update Chromium base to 86.0.4240.110</li>
                        <li>Vanadium: update Chromium base to 86.0.4240.114</li>
                        <li>Vanadium: update Chromium base to 86.0.4240.185</li>
                        <li>Vanadium: enable prefetch privacy changes by default</li>
                        <li>Vanadium: enable reduced referrer granularity by default</li>
                        <li>Camera: request fine location instead of coarse location for the disabled-by-default geotagging feature</li>
                        <li>Camera: remove unused INTERNET permission</li>
                        <li>Clock: apply assorted fixes from upstream</li>
                        <li>add explicit detection of fastboot being missing to the factory images flash-all scripts</li>
                        <li>Gallery: apply upstream fix from NXP for null pointer dereference bug</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/22">version 22</a></li>
                        <li>script: make generate_deltas ask for the password only once</li>
                        <li>enable screenshot action for 3 button nav too (the upstream release limited it to being enabled for 2 button navigation)</li>
                    </ul>
                </article>

                <article id="2020.10.23.04">
                    <h3><a href="#2020.10.23.04">2020.10.23.04</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.201005.004.2020.10.23.04">RP1A.201005.004.2020.10.23.04</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.201005.006.2020.10.23.04">RP1A.201005.006.2020.10.23.04</a> (Pixel 4a, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.10.06.02 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 86.0.4240.75</li>
                        <li>Vanadium: update Chromium base to 86.0.4240.99</li>
                        <li>Vanadium: remove deprecated, unused storage permissions</li>
                        <li>replace standard WebView with Vanadium WebView again</li>
                        <li>Pixel 4, Pixel 4 XL: disable unsupported aware feature so that ambient display is available</li>
                        <li>Seedvault: switch to upstream development branch now that it supports Android 11</li>
                        <li>SELinux policy: port hardening from Android 10</li>
                        <li>hardened_malloc: log fatal errors (detected memory corruption bugs) to Android's log system</li>
                        <li>fix minor issues with Android 11 port of Wi-Fi and Bluetooth quick tile unlock requirement</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, Pixel 4a): apply Bluetooth fixes from the stable kernel branch including fixes for CVE-2020-12351, CVE-2020-12352 and CVE-2020-24490</li>
                        <li>improve experimental support for the Pixel 4a including porting most device-specific changes implemented for other devices</li>
                    </ul>
                </article>

                <article id="2020.10.06.02">
                    <h3><a href="#2020.10.06.02">2020.10.06.02</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.201005.004.2020.10.06.02">RP1A.201005.004.2020.10.06.02</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.201005.006.2020.10.06.02">RP1A.201005.006.2020.10.06.02</a> (emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.10.01.23 release:</p>

                    <ul>
                        <li>full 2020-10-01 security patch level</li>
                        <li>full 2020-10-05 security patch level</li>
                        <li>rebased onto RP1A.201005.006 release</li>
                        <li>hardened_malloc: optimize and harden initialization sanity checks</li>
                        <li>work around upstream bug causing null pointer crashes from media notifications in secondary profiles</li>
                        <li>enable secondary user logout support by default (purges credential encrypted storage keys from memory)</li>
                        <li>add back screenshot action to global action list as an alternative to the key chord (power button + volume down) and screenshot button in the gesture navigation recent apps list</li>
                        <li>reject received unix timestamps before build unix time for HTTPS-based network time implementation</li>
                        <li>Clock: apply fixes for various upstream issues</li>
                        <li>System Updater: harden PendingIntent usage</li>
                    </ul>
                </article>

                <article id="2020.10.01.23">
                    <h3><a href="#2020.10.01.23">2020.10.01.23</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.200720.009.2020.10.01.23">RP1A.200720.009.2020.10.01.23</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.200720.011.2020.10.01.23">RP1A.200720.011.2020.10.01.23</a> (emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.09.29.20 release:</p>

                    <ul>
                        <li>Pixel 4 (non-XL): stop overriding default Bluetooth toggle to disable it by default like other devices</li>
                        <li>use otatools.zip for generating delta updates</li>
                        <li>Settings: fix integration of LTE only mode option to preferred network setting</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/21">version 21</a></li>
                    </ul>
                </article>

                <article id="2020.09.29.20">
                    <h3><a href="#2020.09.29.20">2020.09.29.20</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.200720.009.2020.09.29.20">RP1A.200720.009.2020.09.29.20</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.200720.011.2020.09.29.20">RP1A.200720.011.2020.09.29.20</a> (emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.09.25.00 release:</p>

                    <ul>
                        <li>add overlay to show 2 button navigation option in Settings again</li>
                        <li>Calculator: gesture compatibility fix</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/20">version 20</a></li>
                        <li>WebView: update to 85.0.4183.120</li>
                        <li>WebView: update to 85.0.4183.127</li>
                        <li>Vanadium: update Chromium base to 85.0.4183.127</li>
                        <li>fix syncing time for the port of our HTTPS-based network time update implementation to Android 11</li>
                        <li>stop using dedicated keys for signing OsuLogin and ServiceWifiResources rather than simply using the regular testkey/releasekey</li>
                    </ul>
                </article>

                <article id="2020.09.25.00">
                    <h3><a href="#2020.09.25.00">2020.09.25.00</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.200720.009.2020.09.25.00">RP1A.200720.009.2020.09.25.00</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.200720.011.2020.09.25.00">RP1A.200720.011.2020.09.25.00</a> (emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.09.18.13 release:</p>

                    <ul>
                        <li>fix Wi-Fi MAC randomization settings for translations that were missing our added option</li>
                        <li>Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL: add missing configuration for biometric sensors in Android 11</li>
                        <li>fix upstream bug in the NFC quick settings tile for Android 11 breaking it after reboot</li>
                        <li>fix NFC quick settings tile icon handling for Android 11</li>
                        <li>Settings: fix upstream NFC preference so that it listens for changes and can see it being toggled via the NFC tile</li>
                        <li>Vanadium: update Chromium base to 85.0.4183.120</li>
                        <li>Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL: update APNs with carriersettings-extractor</li>
                        <li>add back SetupWizard</li>
                        <li>Settings: fix launching WifiSettings</li>
                    </ul>

                    <p>We're no longer going to be listing out restored past features in a separate section for the release notes.</p>
                </article>

                <article id="2020.09.18.13">
                    <h3><a href="#2020.09.18.13">2020.09.18.13</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.200720.009.2020.09.18.13">RP1A.200720.009.2020.09.18.13</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/RP1A.200720.011.2020.09.18.13">RP1A.200720.011.2020.09.18.13</a> (emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.09.11.14 release:</p>

                    <ul>
                        <li>initial port to Android 11 with most GrapheneOS changes ported over (missing most SELinux policy hardening, some Pixel 4 / 4 XL kernel side channel mitigations, finer-grained Pixel 4 kernel Control Flow Integrity and the setup wizard)</li>
                        <li>full 2020-09-05 security patch level</li>
                        <li>temporarily use stock WebView until the next release of Chromium is available with public support for Android 11 to provide the WebView via Vanadium again</li>
                        <li>fix VPN lockdown setting getting overridden on user stop</li>
                        <li>SELinux policy: disable gmscore_app domain</li>
                        <li>SELinux policy: use dedicated SELinux domain for Updater app based on the modern untrusted_app domain</li>
                        <li>stop disabling support for stable local privacy addresses since Android 11 handles it better by only using it when MAC randomization is disabled</li>
                        <li>update to a new version of Seedvault for Android 11</li>
                        <li>build and use otatools.zip for signing releases instead of an ad-hoc approach</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/19">version 19</a></li>
                        <li>System Updater: update targetSdkVersion to 30</li>
                        <li>disable Scudo on 64-bit since we use the substantially more secure hardened_malloc</li>
                        <li>fully replace jemalloc with Scudo on 32-bit</li>
                        <li>hardened_malloc: improve stats implementation</li>
                    </ul>

                    <p>Installations made before this project was renamed to GrapheneOS and before the
                    first official release of the Android Hardening project will be forced to factory
                    reset as part of this upgrade, due to lack of backwards compatibility with the
                    unaltered AOSP encryption format.</p>
                </article>

                <article id="2020.09.11.14">
                    <h3><a href="#2020.09.11.14">2020.09.11.14</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ3A.200805.001.2020.09.11.14">QQ3A.200805.001.2020.09.11.14</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Testing the Android 11 kernels was useful, but we weren't able to ship the previous
                    release due to issues uncovered during testing. The Android 11 kernels have minor
                    backwards incompatible changes in the drivers for at least a subset of the devices so
                    we'll need to ship them with the rest of the changes. Thanks to our testers for
                    helping us with this. This will be the new final Android 10 release, assuming no
                    further problems are uncovered during testing.</p>

                    <p>Changes since the 2020.09.10.05 release:</p>

                    <ul>
                        <li>revert to using the Android 10 kernels on the devices that were switched over early due to backwards incompatible changes in some drivers</li>
                    </ul>
                </article>

                <article id="2020.09.10.05">
                    <h3><a href="#2020.09.10.05">2020.09.10.05</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ3A.200805.001.2020.09.10.05">QQ3A.200805.001.2020.09.10.05</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>This should be the final GrapheneOS release based on Android 10. It ships the
                    device-independent monthly security patches and migrates over to using the Android 11
                    branch of the GrapheneOS kernels for most devices, which brings all the upstream
                    kernel hardening in Android 11 along with the full September kernel updates. The
                    remaining patches for the full 2020-09-05 patch level require finishing the migration
                    to Android 11 in order to ship the September update for the other device support code.
                    It's possible we could ship some of this early, but instead we're going to be focusing
                    on finishing the enormous task of migrating to Android 11. Further help with bringing
                    up support for the devices with Android 11 and porting over each of the GrapheneOS
                    hardening features to it would be greatly appreciated. Donations are also extremely
                    helpful. GrapheneOS has brought on another full time developer using donated funds and
                    there are 3 part time developers helping with Android 11.</p>

                    <p>Changes since the 2020.08.07.01 release:</p>

                    <ul>
                        <li>full 2020-09-01 security patch level</li>
                        <li>partial 2020-09-05 security patch level (missing userspace device support changes until port to Android 11 is finished)</li>
                        <li>Vanadium: update Chromium base to 84.0.4147.125</li>
                        <li>Vanadium: update Chromium base to 85.0.4183.81</li>
                        <li>Vanadium: update Chromium base to 85.0.4183.101</li>
                        <li>Vanadium: remove unused learn more link from Incognito page</li>
                        <li>recovery: reject updates with serialno constraints to match the GrapheneOS Updater app</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): update base kernel to Android 11</li>
                        <li>SetupWizard: update to latest upstream code</li>
                        <li>conscrypt: drop temporary upstream revert of version code which was accidentally kept during a rebase</li>
                        <li>backport fix for USB audio regression from Android 11</li>
                    </ul>

                    <p>Restoration of past features since the 2020.07.06.20 release:</p>

                    <ul>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL): enable intra-object FORTIFY_SOURCE overflow checks</li>
                    </ul>
                </article>

                <article id="2020.08.07.01">
                    <h3><a href="#2020.08.07.01">2020.08.07.01</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ3A.200805.001.2020.08.07.01">QQ3A.200805.001.2020.08.07.01</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.08.03.22 release:</p>

                    <ul>
                        <li>SELinux policy: fix executing apk libraries as executables for third party applications</li>
                    </ul>
                </article>

                <article id="2020.08.03.22">
                    <h3><a href="#2020.08.03.22">2020.08.03.22</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ3A.200805.001.2020.08.03.22">QQ3A.200805.001.2020.08.03.22</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.07.06.20 release:</p>

                    <ul>
                        <li>full 2020-08-01 security patch level</li>
                        <li>full 2020-08-05 security patch level</li>
                        <li>rebased onto QQ3A.200805.001 release</li>
                        <li>fix build for Pixel 3 when Pixel 3 XL kernel is not built</li>
                        <li>fix secondary stack hardening when a non-page-size multiple stack size is specified</li>
                        <li>fix picking up previous build date when doing incremental builds</li>
                        <li>Vanadium: update Chromium base to 84.0.4147.89</li>
                        <li>Vanadium: update Chromium base to 84.0.4147.105</li>
                        <li>Vanadium: update Chromium base to 84.0.4147.111</li>
                        <li>Vanadium: remove Chromium logo in chrome://version</li>
                    </ul>

                    <p>Restoration of past features since the 2020.07.06.20 release:</p>

                    <ul>
                        <li>kernel (Pixel 4, Pixel 4 XL): read-only data expansion</li>
                    </ul>
                </article>

                <article id="2020.07.06.20">
                    <h3><a href="#2020.07.06.20">2020.07.06.20</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ3A.200705.002.2020.07.06.20">QQ3A.200705.002.2020.07.06.20</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.06.22.21 release:</p>

                    <ul>
                        <li>full 2020-07-01 security patch level</li>
                        <li>full 2020-07-05 security patch level</li>
                        <li>rebased onto QQ3A.200705.002 release</li>
                        <li>change TrichromeLibrary package name</li>
                        <li>drop MAC randomization preference migration code</li>
                        <li>Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL: update APNs with carriersettings-extractor</li>
                        <li>disable network time refresh when network time is disabled (previous behavior inherited from upstream)</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL): make reproducible builds simpler</li>
                        <li>kernel (Pixel 4, Pixel 4 XL): use max ASLR entropy before the init process enables it</li>
                    </ul>

                    <p>Restoration of past features since the 2020.06.22.21 release:</p>

                    <ul>
                        <li>kernel (Pixel 4, Pixel 4 XL): enable UNMAP_KERNEL_AT_EL0 Meltdown mitigation (KPTI)</li>
                        <li>kernel (Pixel 4, Pixel 4 XL): enable ARM64_SSBD Spectre v4 mitigation</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL): enable PANIC_ON_OOPS</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL): set PANIC_TIMEOUT to -1</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, Pixel 4, Pixel 4 XL): disable SECURITY_SELINUX_DEVELOP</li>
                    </ul>
                </article>

                <article id="2020.06.22.21">
                    <h3><a href="#2020.06.22.21">2020.06.22.21</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ3A.200605.001.2020.06.22.21">QQ3A.200605.001.2020.06.22.21</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 4, Pixel 4 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ3A.200605.002.2020.06.22.21">QQ3A.200605.002.2020.06.22.21</a> (Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.06.02.02 release:</p>

                    <ul>
                        <li>SystemUI: handle non-SRGB wallpapers</li>
                        <li>Vanadium: update Chromium base to 83.0.4103.96</li>
                        <li>Vanadium: update Chromium base to 83.0.4103.101</li>
                        <li>Vanadium: update Chromium base to 83.0.4103.106</li>
                        <li>script/generate_metadata.py: add channel name to update channel metadata</li>
                        <li>System Updater: sanity check channel name in update channel metadata</li>
                        <li>System Updater: raise minSdkVersion to 29</li>
                        <li>System Updater: extract care_map.pb rather than care_map.txt</li>
                        <li>System Updater: use a different zip for streaming updates (still an experimental / hidden feature)</li>
                        <li>disable RFC 7217 support (stable link-local IPv6 privacy addresses) and stick to link-local IP addresses based on the (random) MAC addresses</li>
                        <li>SetupWizard: update to latest upstream code</li>
                        <li>SetupWizard: use system captive portal URL, rather than a custom Google URL</li>
                        <li>NetworkStack: ignore captive portal fallbacks when one is set at runtime</li>
                        <li>factory images flash-all script: reboot to bootloader after installing update</li>
                        <li>make_key: use 4096-bit RSA keys</li>
                        <li>script/release.sh: auto-detect AVB algorithm to support 4096-bit RSA keys for verified boot</li>
                        <li>add experimental Pixel 4 and Pixel 4 XL support</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/18">version 18</a></li>
                    </ul>

                    <p>Restoration of past features since the 2020.06.02.02 release:</p>

                    <ul>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): add back FORTIFY_SOURCE enhancements</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): add back userspace ASLR improvements</li>
                    </ul>
                </article>

                <article id="2020.06.02.02">
                    <h3><a href="#2020.06.02.02">2020.06.02.02</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ3A.200605.001.2020.06.02.02">QQ3A.200605.001.2020.06.02.02</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ3A.200605.002.2020.06.02.02">QQ3A.200605.002.2020.06.02.02</a> (Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.05.29.00 release:</p>

                    <ul>
                        <li>full 2020-06-01 security patch level</li>
                        <li>full 2020-06-05 security patch level</li>
                        <li>rebased onto QQ3A.200605.002 release</li>
                        <li>Vanadium: update Chromium base to 83.0.4103.83</li>
                        <li>factory images: add fastboot version detection to flash-all.bat on Windows</li>
                    </ul>
                </article>

                <article id="2020.05.29.00">
                    <h3><a href="#2020.05.29.00">2020.05.29.00</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200501.001.B2.2020.05.29.00">QQ2A.200501.001.B2.2020.05.29.00</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200501.001.B3.2020.05.29.00">QQ2A.200501.001.B3.2020.05.29.00</a> (Pixel 2, Pixel 2 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.05.23.12 release:</p>

                    <ul>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/4">version 4</a></li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/5">version 5</a></li>
                        <li>revert attempt at fixing audio DeviceDescriptor sorting</li>
                        <li>hardened_malloc: temporarily disable SLOT_RANDOMIZE for audioserver to work around DeviceDescriptor sorting bug</li>
                    </ul>
                </article>

                <article id="2020.05.23.12">
                    <h3><a href="#2020.05.23.12">2020.05.23.12</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200501.001.B2.2020.05.23.12">QQ2A.200501.001.B2.2020.05.23.12</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200501.001.B3.2020.05.23.12">QQ2A.200501.001.B3.2020.05.23.12</a> (Pixel 2, Pixel 2 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.05.05.02 release:</p>

                    <ul>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): use Clang for compiling code for the host too</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): add build-tools prebuilts to PATH to reduce external dependencies and avoid potential reproducibility issues</li>
                        <li>add build-tools prebuilts to PATH in the release signing and delta generation scripts to reduce external dependencies and avoid potential reproducibility issues</li>
                        <li>fix upstream bug relying on malloc addresses for sort order of 3 items, causing Bluetooth A2DP audio to fail 2/3 of the time with hardened_malloc when the expected item isn't first</li>
                        <li>use the same datetime for build number and build date</li>
                        <li>always use UTC as the time zone for build dates</li>
                        <li>update GrapheneOS fork of android-prepare-vendor to the collaborative AOSPAlliance fork</li>
                        <li>raise minimum supported API level to 28 from 23, producing a warning for apps targeting API &lt; 28 (the Play Store disallows uploading new apps or app updates targeting API &lt; 28 so this isn't an aggressive warning)</li>
                        <li>Vanadium: update Chromium base to 81.0.4044.138</li>
                        <li>Vanadium: update Chromium base to 83.0.4103.60</li>
                        <li>Vanadium: disable media DRM preprovisioning</li>
                        <li>Vanadium: most private WebRTC IP handling policy by default</li>
                        <li>set SCHED_BATCH in the kernel build scripts</li>
                    </ul>

                    <p>Restoration of past features since the 2020.05.05.02 release:</p>

                    <ul>
                        <li>Settings: allow disabling Vanadium browser app via the Settings UI now that Trichrome (browser, WebView, shared library) has replaced Monochrome (monolithic app) for providing the WebView without having 2 copies of the browser engine</li>
                    </ul>
                </article>

                <article id="2020.05.05.02">
                    <h3><a href="#2020.05.05.02">2020.05.05.02</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a
                        href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200501.001.B2.2020.05.05.02">QQ2A.200501.001.B2.2020.05.05.02</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL)</li>
                        <li><a
                        href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200501.001.B3.2020.05.05.02">QQ2A.200501.001.B3.2020.05.05.02</a> (Pixel 2, Pixel 2 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.04.14.23 release:</p>

                    <ul>
                        <li>full 2020-05-01 security patch level</li>
                        <li>full 2020-05-05 security patch level</li>
                        <li>rebased onto QQ2A.200501.001.B3 release</li>
                        <li>Vanadium: update Chromium base to 81.0.4044.111</li>
                        <li>Vanadium: update Chromium base to 81.0.4044.117</li>
                        <li>disable safe volume feature everywhere instead of only the US</li>
                        <li>hardened_malloc: implement slab allocation memory corruption checks for malloc_usable_size</li>
                        <li>set SCHED_BATCH in the build system and release generation scripts instead of the interactive shell</li>
                        <li>use more sensible factory images zip naming scheme</li>
                        <li>Settings: add missing title for top_level_settings to fix showing it as null in search results</li>
                    </ul>

                    <p>Restoration of past features since the 2020.04.14.23 release:</p>

                    <ul>
                        <li>Vanadium: use 64-bit Trichrome browser processes</li>
                    </ul>
                </article>

                <article id="2020.04.14.23">
                    <h3><a href="#2020.04.14.23">2020.04.14.23</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200405.005.2020.04.14.23">QQ2A.200405.005.2020.04.14.23</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.04.13.21 release:</p>

                    <ul>
                        <li>Settings: adjust wifi_privacy_values to the new values</li>
                        <li>Settings: remove unnecessary workaround for MAC randomization preference</li>
                        <li>Settings: tweak MAC randomization preference wording</li>
                    </ul>
                </article>

                <article id="2020.04.13.21">
                    <h3><a href="#2020.04.13.21">2020.04.13.21</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200405.005.2020.04.13.21">QQ2A.200405.005.2020.04.13.21</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.04.07.10 release:</p>

                    <ul>
                        <li>Vanadium: update Chromium base to 81.0.4044.96</li>
                        <li>Vanadium: remove unsupported password leak detection option</li>
                        <li>Vanadium: expand automated string rebranding</li>
                        <li>Vanadium: remove Google prefix from storage settings label</li>
                        <li>reword random MAC options to make them clearer</li>
                        <li>start the final phase of the migration process for random MAC preference values</li>
                        <li>generate manifests for stable releases directly referencing revisions by hash instead of tag name to simplify signature verification for the sources</li>
                    </ul>

                    <p>Restoration of past features since the 2020.04.07.10 release:</p>

                    <ul>
                        <li>globally enable -ftrivial-auto-var-init=zero rather than porting our downstream -fsanitize=local-init feature</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): globally enable -ftrivial-auto-var-init=zero rather than porting our downstream -fsanitize=local-init feature</li>
                        <li>Vanadium: enable -ftrivial-auto-var-init=zero rather than porting our downstream -fsanitize=local-init feature</li>
                    </ul>
                </article>

                <article id="2020.04.07.10">
                    <h3><a href="#2020.04.07.10">2020.04.07.10</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200405.005.2020.04.07.10">QQ2A.200405.005.2020.04.07.10</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.03.23.22 release:</p>

                    <ul>
                        <li>full 2020-04-01 security patch level</li>
                        <li>full 2020-04-05 security patch level</li>
                        <li>rebased onto QQ2A.200405.005 release</li>
                        <li>Pixel 3a, Pixel 3a XL: fix SystemUI paths in memory pinning configuration</li>
                        <li>only include Updater app when OFFICIAL_BUILD=true is set in the environment to avoid accidental use of the default update server with unofficial builds that are not compatible</li>
                        <li>Vanadium: update Chromium base to 80.0.3987.162</li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/3">version 3</a></li>
                        <li>update SELinux policy for officially supported devices based on isolated_app domain split</li>
                        <li>raise protected_fifos / protected_regular from 1 (world-writable directories) to 2 (group-writable directories too)</li>
                        <li>remove use of "Hey Google" as an example feature for battery saver in Settings</li>
                    </ul>
                </article>

                <article id="2020.03.23.22">
                    <h3><a href="#2020.03.23.22">2020.03.23.22</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200305.002.2020.03.23.22">QQ2A.200305.002.2020.03.23.22</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.03.04.16 release:</p>

                    <ul>
                        <li>integrate <a href="https://github.com/seedvault-app/seedvault">Seedvault</a> backup app as the default backup service</li>
                        <li>integrate SetupWizard app to support restoring with Seedvault and other initial setup</li>
                        <li>Vanadium: disable unused safe browsing feature by default (Safe Browsing is
                        currently a no-op due to the lack of Play services, and support for using the
                        local database backend hasn't been implemented. Various changes would be needed to
                        make it available and to make sure that privacy is preserved.)</li>
                        <li>Vanadium: disable unused Google VR support</li>
                        <li>Vanadium: disable content feed suggestions by default</li>
                        <li>Vanadium: update Chromium base to 80.0.3987.149</li>
                        <li>Settings: fix broken upstream MAC randomization value mapping uncovered by the always randomize option value</li>
                        <li>make_key: use scrypt for key derivation used to encrypt keys</li>
                        <li>add script/encrypt_keys.sh and script/decrypt_keys.sh for handling key encryption</li>
                        <li>improve UX, performance and algorithm support for encrypted keys in script/release.sh and script/generate_delta.sh</li>
                        <li>dexpreopt: disable BOARD_USES_SYSTEM_OTHER_ODEX for mainline devices, which was causing odex files to be unintentionally omitted from the system image for modern devices</li>
                        <li>dexpreopt: use speed filter for boot images and non-prebuilts rather than unintentionally only setting it for prebuilts</li>
                        <li>dexpreopt: disable pre-optimization for apps bundled by android-prepare-vendor to work around unresolved issues with conflicting inlined definitions</li>
                    </ul>
                </article>

                <article id="2020.03.04.16">
                    <h3><a href="#2020.03.04.16">2020.03.04.16</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200305.002.2020.03.04.16">QQ2A.200305.002.2020.03.04.16</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.03.03.03 release:</p>

                    <ul>
                        <li>Vanadium: backport upstream fix for Android 10 downloads</li>
                        <li>Vanadium: update Chromium base to 80.0.3987.132</li>
                        <li>Settings: avoid overriding MAC address with random persistent MAC address when viewing MAC address</li>
                        <li>finish porting support for per-connection random MAC rather than using the per-network random address</li>
                    </ul>
                </article>

                <article id="2020.03.03.03">
                    <h3><a href="#2020.03.03.03">2020.03.03.03</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ2A.200305.002.2020.03.03.03">QQ2A.200305.002.2020.03.03.03</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.02.07.19 release:</p>

                    <ul>
                        <li>full 2020-03-01 security patch level</li>
                        <li>full 2020-03-05 security patch level</li>
                        <li>rebased onto QQ2A.200305.002 release</li>
                        <li>use time.grapheneos.org instead of grapheneos.org for HTTPS-based time updates</li>
                        <li>Vanadium: migrate to Trichrome for unified builds of separate browser and WebView apps with a shared library app</li>
                        <li>Vanadium: use org.grapheneos.vanadium.webview instead of com.android.webview as the WebView package name</li>
                        <li>Vanadium: rename WebView to Vanadium System WebView from Android System WebView</li>
                        <li>Vanadium: update Chromium base to 80.0.3987.99</li>
                        <li>Vanadium: update Chromium base to 80.0.3987.117</li>
                        <li>Vanadium: update Chromium base to 80.0.3987.119</li>
                        <li>SELinux policy: remove base system app apk_data_file execute</li>
                        <li>SELinux policy: remove zygote access to apk_data_file</li>
                    </ul>

                    <p>Restoration of past features since the 2020.02.07.19 release:</p>

                    <ul>
                        <li>Vanadium: stop replacing signature from the Vanadium signing key with the OS release key</li>
                        <li>Settings: add back control over camera access while the screen is locked</li>
                        <li>fix MAC randomization after reboot for the always randomize MAC option</li>
                        <li>SELinux policy: split out base system untrusted_app (normal unprivileged apps) and isolated_app (isolatedProcess sandbox) SELinux policy domains for future work</li>
                        <li>SELinux policy: remove base system app execmod</li>
                        <li>SELinux policy: remove base system app execmem</li>
                        <li>SELinux policy: remove base system app execute_no_trans</li>
                        <li>SELinux policy: remove base system app app_data_file execute</li>
                        <li>SELinux policy: remove base system app ashmem execute</li>
                        <li>SELinux policy: remove base system app tmpfs execute</li>
                        <li>SELinux policy: remove zygote execmem</li>
                        <li>SELinux policy: remove system_server_startup domain</li>
                        <li>add LTE only mobile network configuration option</li>
                    </ul>
                </article>

                <article id="2020.02.07.19">
                    <h3><a href="#2020.02.07.19">2020.02.07.19</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ1A.200205.002.2020.02.07.19">QQ1A.200205.002.2020.02.07.19</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2020.02.04.01 release:</p>

                    <ul>
                        <li>rebuild crosshatch kernel to correct build environment issue</li>
                        <li>Vanadium (including WebView): update Chromium base to 80.0.3987.87</li>
                        <li>Vanadium (including WebView): drop partially working AImageReader workarounds</li>
                        <li>fully work around bug with AImageReader caught by CFI on 64-bit to fix crashes during video rendering in Vanadium and other Chromium-based browsers</li>
                    </ul>

                    <p>Restoration of past features since the 2020.02.04.01 release:</p>

                    <ul>
                        <li>WebView: use Vanadium WebView as provider</li>
                    </ul>
                </article>

                <article id="2020.02.04.01">
                    <h3><a href="#2020.02.04.01">2020.02.04.01</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ1A.200205.002.2020.02.04.01">QQ1A.200205.002.2020.02.04.01</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2019.01.06.21 release:</p>

                    <ul>
                        <li>full 2020-02-01 security patch level</li>
                        <li>full 2020-02-05 security patch level</li>
                        <li>rebased onto QQ1A.200205.002 release</li>
                        <li>remove obsolete Email app</li>
                        <li>Vanadium: update Chromium base to 79.0.3945.116</li>
                        <li>WebView: update to 79.0.3945.116</li>
                        <li>Vanadium: update Chromium base to 79.0.3945.136</li>
                        <li>WebView: update to 79.0.3945.136</li>
                        <li>Vanadium: fully disable AImageReader to fix remaining issues with video playback uncovered by CFI on 64-bit</li>
                        <li>Settings: fix MAC randomization setting for other locales by removing incomplete translations</li>
                    </ul>

                    <p>Restoration of past features since the 2019.01.06.21 release:</p>

                    <ul>
                        <li>add PIN scrambling feature</li>
                    </ul>
                </article>

                <article id="2020.01.06.21">
                    <h3><a href="#2020.01.06.21">2020.01.06.21</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ1A.200105.002.2020.01.06.21">QQ1A.200105.002.2020.01.06.21</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2019.12.02.23 release:</p>

                    <ul>
                        <li>full 2020-01-01 security patch level</li>
                        <li>full 2020-01-05 security patch level</li>
                        <li>rebased onto QQ1A.200105.002 release</li>
                        <li>Vanadium: update Chromium base to 79.0.3945.93</li>
                        <li>Vanadium: disable hiding trivial subdomains</li>
                        <li>WebView: update to 79.0.3945.93</li>
                        <li>add the option to randomize the MAC address for each connection instead of per-network</li>
                        <li>authenticated network time updates via HTTPS</li>
                    </ul>

                    <p>Restoration of past features since the 2019.12.02.23 release:</p>

                    <ul>
                        <li>Settings: expose control over USB peripheral denial feature</li>
                    </ul>
                </article>

                <article id="2019.12.02.23">
                    <h3><a href="#2019.12.02.23">2019.12.02.23</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ1A.191205.008.2019.12.02.23">QQ1A.191205.008.2019.12.02.23</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QQ1A.191205.011.2019.12.02.23">QQ1A.191205.011.2019.12.02.23</a> (Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2019.11.05.23 release:</p>

                    <ul>
                        <li>full 2019-12-01 security patch level</li>
                        <li>full 2019-12-05 security patch level</li>
                        <li>rebased onto QQ1A.191205.011 release</li>
                        <li>Pixel 3a, Pixel 3a XL: fix userspace hw_random stirring service</li>
                        <li>Vanadium: update Chromium base to 78.0.3904.96</li>
                        <li>WebView: update to 78.0.3904.96</li>
                        <li>Vanadium: update Chromium base to 78.0.3904.108</li>
                        <li>WebView: update to 78.0.3904.108</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/17">version 17</a></li>
                        <li>QuickSearchBox: disable widget</li>
                        <li>QuickSearchBox: disable launcher icon</li>
                        <li>Launcher: rebranding</li>
                        <li>require unlocking to use work tile</li>
                    </ul>
                </article>

                <article id="2019.11.05.23">
                    <h3><a href="#2019.11.05.23">2019.11.05.23</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QP1A.191105.003.2019.11.05.23">QP1A.191105.003.2019.11.05.23</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QP1A.191105.004.2019.11.05.23">QP1A.191105.004.2019.11.05.23</a> (Pixel 2, Pixel 2 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2019.11.04.23 release:</p>

                    <ul>
                        <li>Vanadium: fix Services preferences menu</li>
                        <li>WebView: avoid incompatibility due to wrong apk variant</li>
                    </ul>
                </article>

                <article id="2019.11.04.23">
                    <h3><a href="#2019.11.04.23">2019.11.04.23</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QP1A.191105.003.2019.11.04.23">QP1A.191105.003.2019.11.04.23</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QP1A.191105.004.2019.11.04.23">QP1A.191105.004.2019.11.04.23</a> (Pixel 2, Pixel 2 XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2019.10.07.21 release:</p>

                    <ul>
                        <li>full 2019-11-01 security patch level</li>
                        <li>full 2019-11-05 security patch level</li>
                        <li>rebased onto QP1A.191105.004 release</li>
                        <li>Settings: disable legacy suggestions mode</li>
                        <li>recovery: GrapheneOS branding for fastboot mode</li>
                        <li>Vanadium: update Chromium base to 77.0.3865.116</li>
                        <li>WebView: update to 77.0.3865.116</li>
                        <li>Vanadium: update Chromium base to 78.0.3904.62</li>
                        <li>WebView: update to 78.0.3904.62</li>
                        <li>Vanadium: update Chromium base to 78.0.3904.90</li>
                        <li>WebView: update to 78.0.3904.90</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): mark functions with address taken via assembly (this fixes compatibility with CFI in a build with !CONFIG_MODULES)</li>
                        <li>protect static TLS from stack buffer overflows</li>
                        <li>drop legacy Pixel and Pixel XL support due to absence of any GrapheneOS device maintainers, the end of vendor support and an increasingly large security gap with current generation devices for the hardware, firmware and device / generation specific software</li>
                    </ul>

                    <p>Restoration of past features since the 2019.09.25.00 release:</p>

                    <ul>
                        <li>Bluetooth: add alloc_size attribute to OSI allocator</li>
                        <li>protect pthread_internal_t from stack buffer overflows</li>
                        <li>add secondary stack randomization</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): disable dynamic kernel module support (resulting in substantially improved CFI granularity)</li>
                    </ul>
                </article>

                <article id="2019.10.07.21">
                    <h3><a href="#2019.10.07.21">2019.10.07.21</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QP1A.191005.007.A1.2019.10.07.21">QP1A.191005.007.A1.2019.10.07.21</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QP1A.191005.007.2019.10.07.21">QP1A.191005.007.2019.10.07.21</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL)</li>
                    </ul>

                    <p>Changes since the 2019.09.25.00 release:</p>

                    <ul>
                        <li>full 2019-10-01 security patch level</li>
                        <li>full 2019-10-05 security patch level</li>
                        <li>full 2019-10-06 security patch level</li>
                        <li>rebased onto QP1A.191005.007.A1 release</li>
                        <li>add changes to support disabling full preloading with exec spawning to the public libcore API</li>
                        <li>add OTHER_SENSORS to the public frameworks/base API</li>
                        <li>Messaging app: fix notifications with a backport</li>
                        <li>Vanadium: switch back to ChromeModern (standalone browser app) from Monochrome (monolithic browser + WebView app, no longer supported for Android 10) until Vanadium is moved to Trichrome (separate browser and WebView apps with a third shared library app)</li>
                        <li>unified kernel tree (kernel/google/crosshatch) for Pixel 3, Pixel 3 XL, Pixel 3a and Pixel 3a XL</li>
                    </ul>

                    <p>Restoration of past features since the 2019.09.25.00 release:</p>

                    <ul>
                        <li>begin generating / uploading delta updates from the last release to the current release</li>
                    </ul>
                </article>

                <article id="2019.09.25.00">
                    <h3><a href="#2019.09.25.00">2019.09.25.00</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QP1A.190711.020.C3.2019.09.25.00">QP1A.190711.020.C3.2019.09.25.00</a> (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QP1A.190711.020.2019.09.25.00">QP1A.190711.020.2019.09.25.00</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL)</li>
                    </ul>

                    <p>Changes since the 2019.09.23.19 release:</p>

                    <ul>
                        <li>update to QP1A.190711.020.C3 bug fix release</li>
                        <li>fix granting Network and Sensors permissions at install time</li>
                        <li>fix wording for Network permission group</li>
                    </ul>
                </article>

                <article id="2019.09.23.19">
                    <h3><a href="#2019.09.23.19">2019.09.23.19</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QP1A.190711.020.2019.09.23.19">QP1A.190711.020.2019.09.23.19</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2019.09.21.18 release:</p>

                    <ul>
                        <li>disable enforcing Runtime Resource Overlays for baseline overlays to work around incompatibility with exec spawning</li>
                        <li>enable exec spawning for com.android.phone again</li>
                    </ul>
                </article>

                <article id="2019.09.21.18">
                    <h3><a href="#2019.09.21.18">2019.09.21.18</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QP1A.190711.020.2019.09.21.18">QP1A.190711.020.2019.09.21.18</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2019.09.18.14 release:</p>

                    <ul>
                        <li>Settings: use Mainline branding for APEX components</li>
                        <li>Vanadium: update Chromium base to 77.0.3865.92</li>
                        <li>WebView: update to 77.0.3865.92</li>
                        <li>temporarily disable exec spawning for com.android.phone</li>
                        <li>Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, mainline: disable updatable apex for simplicity</li>
                        <li>Pixel 2, Pixel 2 XL: enable increased system.img inode count</li>
                        <li>script: replace networkstack key</li>
                    </ul>
                </article>

                <article id="2019.09.18.14">
                    <h3><a href="#2019.09.18.14">2019.09.18.14</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/QP1A.190711.020.2019.09.18.14">QP1A.190711.020.2019.09.18.14</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL, emulator, generic, other targets)</li>
                    </ul>

                    <p>Changes since the 2019.08.25.15 release:</p>

                    <ul>
                        <li>full port to Android 10 with some exceptions (listed below)</li>
                        <li>full 2019-08-05 security patch level</li>
                        <li>full 2019-09-01 security patch level</li>
                        <li>full 2019-09-05 security patch level</li>
                        <li>temporarily add back standalone WebView (77.0.3865.73) until Vanadium supports it for Android 10</li>
                        <li>Vanadium: update Chromium base to 76.0.3809.132</li>
                        <li>Vanadium: update Chromium base to 77.0.3865.73</li>
                        <li>System Updater: update targetSdkVersion to 29</li>
                        <li>retrofit dynamic partitions for Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL</li>
                        <li>disable GSI keys</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): temporarily disable slab canary implementation until an issue is narrowed down and addressed</li>
                        <li>kernel (Pixel 3, Pixel 3 XL): temporarily re-enable dynamic kernel module support until an issue is narrowed down and addressed (no dynamic kernel modules are ever actually loaded but something breaks internally with it disabled)</li>
                        <li>add guard page between the stack and the new static TLS region</li>
                        <li>bionic: pthread_internal_t changes have not yet been ported over so that feature is temporarily gone</li>
                    </ul>
                </article>

                <article id="2019.08.25.15">
                    <h3><a href="#2019.08.25.15">2019.08.25.15</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190801.002.2019.08.25.15">PQ3A.190801.002.2019.08.25.15</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, emulator, generic, other targets)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3B.190801.002.2019.08.25.15">PQ3B.190801.002.2019.08.25.15</a> (Pixel 3a, Pixel 3a XL)</li>
                    </ul>

                    <p>Changes since the 2019.08.05.19 release:</p>

                    <ul>
                        <li>add missing privileged permission whitelist for SdkSetup in SDK emulator builds</li>
                        <li>set up Vanadium for other architectures (arm, x86, x86_64)</li>
                        <li>hardened_malloc (GrapheneOS only): remove workaround for use-after-free in the citadel (Titan M) driver's key attestation support since it was fixed upstream</li>
                        <li>hardened_malloc: update libdivide to 2.0</li>
                        <li>Vanadium (browser and WebView): update Chromium base to 76.0.3809.111</li>
                        <li>Vanadium: redirect settings help icon</li>
                        <li>Vanadium: set default search engine to DuckDuckGo</li>
                        <li>apply partial fix for package manager original-package feature</li>
                        <li>PDF Viewer: update to <a href="https://github.com/GrapheneOS/PdfViewer/releases/tag/2">version 2</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/16">version 16</a></li>
                        <li>add Vanadium to the apps that cannot be disabled via Settings (can still be disabled) since the warning isn't enough to deter people from unknowingly breaking apps using the WebView</li>
                        <li>System Updater: add settings entry to manually trigger check for updates</li>
                        <li>System Updater: reschedule update check job on channel change</li>
                        <li>arm, x86 and x86_64 are now supported / tested architectures</li>
                        <li>generic and emulator build targets are now supported / tested for development usage (not suitable for secure production releases)</li>
                    </ul>
                </article>

                <article id="2019.08.05.19">
                    <h3><a href="#2019.08.05.19">2019.08.05.19</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190801.002.2019.08.05.19">PQ3A.190801.002.2019.08.05.19</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, other devices)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3B.190801.002.2019.08.05.19">PQ3B.190801.002.2019.08.05.19</a> (Pixel 3a, Pixel 3a XL)</li>
                    </ul>

                    <p>Changes since the 2019.07.16.22 release:</p>

                    <ul>
                        <li>full 2019-08-01 security patch level</li>
                        <li>partial 2019-08-05 security patch level (not yet fully available)</li>
                        <li>Vanadium (browser and WebView): update Chromium base to 76.0.3809.89</li>
                        <li>Vanadium: expand string rebranding including covering translations</li>
                        <li>Vanadium: rename Sync and Google services to Services</li>
                        <li>Vanadium: remove data reduction preference</li>
                        <li>Vanadium: remove translate offer preference</li>
                        <li>Vanadium: remove sync preferences</li>
                        <li>Vanadium: remove navigation error preference</li>
                        <li>Vanadium: remove safe browsing reporting preference</li>
                        <li>Vanadium: remove usage and crash reports preference</li>
                        <li>Vanadium: remove url keyed anonymized data preference</li>
                        <li>Vanadium: disable contextual search by default</li>
                        <li>Vanadium: remove redundant services preference category</li>
                        <li>Vanadium (browser and WebView): use a unified Vanadium signing key instead of the device-specific release key</li>
                        <li>rename WebView provider to Vanadium</li>
                        <li>SELinux policy: label protected_{fifos,regular} as proc_security (this is needed for init to override the default values)</li>
                    </ul>
                </article>

                <article id="2019.07.16.22">
                    <h3><a href="#2019.07.16.22">2019.07.16.22</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190705.001.2019.07.16.22">PQ3A.190705.001.2019.07.16.22</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190705.003.2019.07.16.22">PQ3A.190705.003.2019.07.16.22</a> (Pixel 3, Pixel 3 XL, other devices)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3B.190705.003.2019.07.16.22">PQ3B.190705.003.2019.07.16.22</a> (Pixel 3a, Pixel 3a XL)</li>
                    </ul>

                    <p>Changes since the 2019.07.01.21 release:</p>

                    <ul>
                        <li>Vanadium (browser and WebView): update Chromium base to 75.0.3770.143</li>
                        <li>Vanadium: disable media router media remoting by default</li>
                        <li>Vanadium: disable media router by default (avoids the triggering warning about not having Play services)</li>
                        <li>Vanadium: remove Help &amp; feedback menu entry</li>
                        <li>Vanadium: further string rebranding from Chromium / Chrome to Vanadium</li>
                        <li>Vanadium: disable unused reporting feature at compile-time</li>
                        <li>Vanadium: disable unused remoting feature at compile-time</li>
                        <li>Vanadium (browser and WebView): move from external/chromium to external/vanadium in the GrapheneOS source tree and rename module from Chromium to Vanadium</li>
                        <li>Vanadium: disable offering translations by default</li>
                        <li>Vanadium: disable prefetching suggested pages by default</li>
                        <li>Vanadium: disable browser sign in feature by default</li>
                        <li>Vanadium: disable safe browsing reporting opt-in by default</li>
                        <li>extend release.sh to call the script for signing factory images</li>
                        <li>extend release.sh to call the script for generating update channel metadata</li>
                        <li>kernel build script (Pixel, Pixel XL, Pixel 3a, Pixel 3a XL): verify that no arguments are passed</li>
                        <li>kernel build script (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL): verify that a single argument (device variant) is passed</li>
                        <li>enable kernel mitigations for file spoofing</li>
                    </ul>

                    <p>Restoration of past features since the 2019.07.01.21 release:</p>

                    <ul>
                        <li>Vanadium (browser and WebView): enable type-based CFI for virtual calls</li>
                        <li>enable kernel mitigations for link races</li>
                        <li>kernel (Pixel 2, Pixel 2 XL): backport fixes for SLAB_FREELIST_RANDOM</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): enable SLAB_FREELIST_RANDOM</li>
                        <li>kernel (Pixel 2, Pixel 2 XL): backport slub dynamic DEBUG_PAGEALLOC setting</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): backport slub free list pointer obfuscation</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): backport slub free list pointer obfuscation prefetch fix</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): backport slub native double free detection</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): enable SLAB_FREELIST_HARDENED</li>
                        <li>kernel (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): enable DEBUG_LIST</li>
                        <li>kernel (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): enable DEBUG_SG</li>
                        <li>kernel (Pixel, Pixel XL): reduce DEBUG_SG virt_addr_valid check to a warning (this works around a bug in the legacy QCE driver)</li>
                        <li>kernel (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): enable DEBUG_NOTIFIERS</li>
                        <li>kernel (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): enable DEBUG_CREDENTIALS</li>
                        <li>kernel (Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): enable SCHED_STACK_END_CHECK</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): bug on !PageSlab &amp;&amp; !PageCompound in ksize</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): always perform cache_from_obj consistency checks</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): bug on kmem_cache_free with the wrong cache</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): real slab_equal_or_root check for !MEMCG_KMEM</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): add missing cache_from_obj !PageSlab check</li>
                        <li>kernel (Pixel 2, Pixel 2 XL): backport upstreamed FORTIFY_SOURCE implementation</li>
                        <li>kernel (Pixel 2, Pixel 2 XL): backport upstreamed leading zero byte for stack canary</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): add simpler page sanitization</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): add support for verifying page sanitization</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): slub: add basic full slab sanitization</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): slub: add support for verifying slab sanitization</li>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, Pixel 3a, Pixel 3a XL): slub: add multi-purpose random canaries</li>
                    </ul>
                </article>

                <article id="2019.07.01.21">
                    <h3><a href="#2019.07.01.21">2019.07.01.21</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190705.001.2019.07.01.21">PQ3A.190705.001.2019.07.01.21</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190705.003.2019.07.01.21">PQ3A.190705.003.2019.07.01.21</a> (Pixel 3, Pixel 3 XL, other devices)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3B.190705.003.2019.07.01.21">PQ3B.190705.003.2019.07.01.21</a> (Pixel 3a, Pixel 3a XL)</li>
                    </ul>

                    <p>Changes since the 2019.06.23.05 release:</p>

                    <ul>
                        <li>full 2019-07-01 security patch level</li>
                        <li>full 2019-07-05 security patch level</li>
                        <li>rebased onto PQ3A.190705.003/PQ3B.190705.003 releases</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/15">version 15</a></li>
                    </ul>

                    <p>Restoration of past features since the 2019.06.23.05 release:</p>

                    <ul>
                        <li>add GrapheneOS PDF Viewer app (version 1)</li>
                        <li>Vanadium: stop ignoring download location prompt setting</li>
                        <li>Vanadium: show download prompt again by default</li>
                    </ul>
                </article>

                <article id="2019.06.23.05">
                    <h3><a href="#2019.06.23.05">2019.06.23.05</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190605.003.2019.06.23.05">PQ3A.190605.003.2019.06.23.05</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, other devices)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3B.190605.006.2019.06.23.05">PQ3B.190605.006.2019.06.23.05</a> (Pixel 3a, Pixel 3a XL)</li>
                    </ul>

                    <p>Changes since the 2019.06.14.02 release:</p>

                    <ul>
                        <li>hardened_malloc: use copy_size to check for canaries (tiny performance / hardening fix and avoids an erroneous abort in a corner case with realloc from 0 byte allocations)</li>
                        <li>hardened_malloc: update libdivide to 1.1</li>
                        <li>Pixel 3a, Pixel 3a XL: raise maximum users to 16</li>
                        <li>Pixel 3a, Pixel 3a XL: disable system_other odex</li>
                        <li>Pixel 3a, Pixel 3a XL: disable system_other preloads_copy</li>
                        <li>Pixel 3a, Pixel 3a XL: show connected mac randomization feature</li>
                        <li>Pixel 3a, Pixel 3a XL: move to custom kernel</li>
                        <li>Pixel 3a, Pixel 3a XL: use monolithic kernel builds</li>
                        <li>kernel (Pixel 3a, Pixel 3a XL): disable slab merging</li>
                        <li>kernel (Pixel 3a, Pixel 3a XL): add toggle for disabling newly added USB devices</li>
                        <li>kernel (Pixel 3a, Pixel 3a XL): replace SECURITY_SMACK with SECURITY_NETWORK</li>
                        <li>kernel (Pixel 3a, Pixel 3a XL): mark qcedev data const</li>
                        <li>Vanadium (browser and WebView): update Chromium base to 75.0.3770.101</li>
                        <li>Vanadium: disable sensors access by default</li>
                        <li>Vanadium: disable third party cookies by default</li>
                        <li>Vanadium: disable background sync by default</li>
                        <li>Vanadium (browser and WebView): stub out battery API</li>
                        <li>Vanadium: disable search logo</li>
                        <li>Vanadium: always use local new tab page</li>
                        <li>Vanadium: disable payment support by default</li>
                    </ul>

                    <p>Restoration of past features since the 2019.06.14.02 release:</p>

                    <ul>
                        <li>Vanadium: do not enable default search engine notification permission by default</li>
                    </ul>
                </article>

                <article id="2019.06.14.02">
                    <h3><a href="#2019.06.14.02">2019.06.14.02</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190605.003.2019.06.14.02">PQ3A.190605.003.2019.06.14.02</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, other devices)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3B.190605.006.2019.06.14.02">PQ3B.190605.006.2019.06.14.02</a> (Pixel 3a, Pixel 3a XL)</li>
                    </ul>

                    <p>Changes since the 2019.06.03.18 release:</p>

                    <ul>
                        <li>Vanadium (browser and WebView): update Chromium base to 75.0.3770.67</li>
                        <li>add back brk system call to the seccomp whitelist for compatibility with Go</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/13">version 13</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/14">version 14</a></li>
                        <li>Music: backport bug fix for passing CTS</li>
                        <li>System Updater: replace seamlessupdate.app with releases.grapheneos.org alias</li>
                        <li>add initial experimental support for the Pixel 3a and Pixel 3a XL</li>
                        <li>Pixel 2, Pixel 2 XL: set AVB rollback index to security patch timestamp (backport of the implementation for the Pixel 3)</li>
                    </ul>

                    <p>Restoration of past features since the 2019.06.03.18 release:</p>

                    <ul>
                        <li>kernel (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL): replace SECURITY_SMACK with SECURITY_NETWORK</li>
                    </ul>
                </article>

                <article id="2019.06.03.18">
                    <h3><a href="#2019.06.03.18">2019.06.03.18</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190605.003.2019.06.03.18">PQ3A.190605.003.2019.06.03.18</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, other devices)</li>
                    </ul>

                    <p>Changes since the 2019.05.18.20 release:</p>

                    <ul>
                        <li>full 2019-06-01 security patch level</li>
                        <li>full 2019-06-05 security patch level</li>
                        <li>rebased onto PQ3A.190605.003 release</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/11">version 11</a></li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/12">version 12</a></li>
                        <li>hardened_malloc (GrapheneOS only): further expand workaround for Pixel 3 and Pixel 3 XL camera issues</li>
                    </ul>

                    <p>Restoration of past features since the 2019.05.18.20 release:</p>

                    <ul>
                        <li>disable exec spawning when using debugging options</li>
                        <li>enable exec spawning by default</li>
                        <li>enable Verizon visual voicemail support</li>
                        <li>kernel (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL): add toggle for disabling newly added USB devices</li>
                        <li>add properties for controlling deny_new_usb</li>
                        <li>implement dynamic deny_new_usb toggle mode</li>
                        <li>set deny_new_usb feature to dynamic by default</li>
                        <li>sepolicy: deny_new_usb sysctl and system property policy</li>
                    </ul>
                </article>

                <article id="2019.05.18.20">
                    <h3><a href="#2019.05.18.20">2019.05.18.20</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190505.001.2019.05.18.20">PQ3A.190505.001.2019.05.18.20</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190505.002.2019.05.18.20">PQ3A.190505.002.2019.05.18.20</a> (Pixel 3, Pixel 3 XL, other devices)</li>
                    </ul>

                    <p>Changes since the 2019.05.08.15 release:</p>

                    <ul>
                        <li>GrapheneOS logo mask</li>
                        <li>Auditor: update to <a href="https://github.com/GrapheneOS/Auditor/releases/tag/10">version 10</a></li>
                        <li>add preload parameter for avoiding full preload with exec</li>
                        <li>raise maximum users to 16</li>
                        <li>Vanadium (browser and WebView): update Chromium base to 74.0.3729.157</li>
                        <li>hardened_malloc (GrapheneOS only): apply temporary workaround for citadel HAL
                            use-after-free (need to start building vendor HALs from the sources to fix
                            issues like this)</li>
                    </ul>

                    <p>Restoration of past features since the 2019.05.08.15 release:</p>

                    <ul>
                        <li>disable OpenGL preloading for exec spawning</li>
                        <li>disable resource preloading for exec spawning</li>
                        <li>disable ICU cache pinning for exec spawning</li>
                        <li>disable class preloading for exec spawning</li>
                        <li>disable WebView reservation for exec spawning</li>
                        <li>disable JCA provider warm up for exec spawning</li>
                        <li>avoid AssetManager errors with exec spawning</li>
                    </ul>
                </article>

                <article id="2019.05.08.15">
                    <h3><a href="#2019.05.08.15">2019.05.08.15</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190505.001.2019.05.08.15">PQ3A.190505.001.2019.05.08.15</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190505.002.2019.05.08.15">PQ3A.190505.002.2019.05.08.15</a> (Pixel 3, Pixel 3 XL, other devices)</li>
                    </ul>

                    <p>Changes since the 2019.05.07.00 release:</p>

                    <ul>
                        <li>fix cellular, hotspot and battery saver quick settings tiles (they became no-ops when unlocked)</li>
                    </ul>
                </article>

                <article id="2019.05.07.00">
                    <h3><a href="#2019.05.07.00">2019.05.07.00</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190505.001.2019.05.07.00">PQ3A.190505.001.2019.05.07.00</a> (Pixel, Pixel XL, Pixel 2, Pixel 2 XL)</li>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ3A.190505.002.2019.05.07.00">PQ3A.190505.002.2019.05.07.00</a> (Pixel 3, Pixel 3 XL, other devices)</li>
                    </ul>

                    <p>Changes since the 2019.04.01.19 release:</p>

                    <ul>
                        <li>full 2019-05-01 security patch level</li>
                        <li>full 2019-05-05 security patch level</li>
                        <li>rebased onto PQ3A.190505.002 release</li>
                        <li>add Pixel and Pixel XL support including standard changes to kernel and device code</li>
                        <li>Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL: fix hw_random permissions</li>
                        <li>bundle Auditor (version 9)</li>
                        <li>Chromium (browser and WebView): update to 74.0.3729.136</li>
                        <li>Chromium: enable strict site isolation by default</li>
                        <li>Chromium: initial rebranding to Vanadium including icon recolor</li>
                        <li>hardened_malloc: extensive work on refactoring, micro-optimization and documentation (see commits for details)</li>
                        <li>hardened_malloc: implement mallinfo and mallinfo extensions for Android</li>
                        <li>hardened_malloc: implement Android API for requesting purging</li>
                        <li>hardened_malloc: implement the option of large size classes (enabled by default)</li>
                        <li>hardened_malloc: support extended range of small size classes (enabled by default)</li>
                        <li>hardened_malloc: support for slabs with 1 slot for largest sizes</li>
                        <li>hardened_malloc: use round-robin assignment to arenas</li>
                        <li>hardened_malloc: disable current in-place growth code path</li>
                        <li>hardened_malloc: harden arena implementation</li>
                        <li>hardened_malloc: fix non-init size for malloc_object_size extension</li>
                        <li>hardened_malloc: shrink initial region table size to fit in 1 page</li>
                        <li>hardened_malloc (GrapheneOS only): expand workaround for Pixel 3 and Pixel 3 XL camera issues</li>
                        <li>Pixel 3, Pixel 3 XL: change SystemUIGoogle pinning to SystemUI</li>
                    </ul>

                    <p>Restoration of past features since the 2019.04.01.19 release:</p>

                    <ul>
                        <li>use -fwrapv when signed overflow checking is off</li>
                        <li>add exec-based spawning support (disabled by default for now)</li>
                        <li>require unlocking to use battery saver quick tile</li>
                        <li>require unlocking to use cellular quick tile</li>
                        <li>require unlocking to use hotspot quick tile</li>
                        <li>require unlocking to use data saver quick tile</li>
                        <li>require unlocking to use rotation lock quick tile</li>
                        <li>require unlocking to use wifi quick tile</li>
                        <li>require unlocking to use airplane mode quick tile</li>
                        <li>require unlocking to use bluetooth quick tile</li>
                        <li>require unlocking to use nfc quick tile</li>
                        <li>add support for kernels without module support enabled to the VTS and compatibility tests</li>
                        <li>kernel (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL): disable slab merging</li>
                        <li>kernel (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL): disable loadable kernel module support</li>
                        <li>kernel (Pixel, Pixel XL, Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL): mark qcedev data const</li>
                        <li>kernel (Pixel 2, Pixel 2 XL): disable unused ramdisk compression formats</li>
                        <li>SELinux policy: remove priv_app app_data_file execute</li>
                        <li>SELinux policy: remove dumpstate ashmem execute and execmem (GrapheneOS doesn't use the ART JIT compiler)</li>
                        <li>SELinux policy: remove healthd ashmem execute and execmem (GrapheneOS doesn't use the ART JIT compiler)</li>
                        <li>SELinux policy: auditallow app execmem (moving back towards an exception system)</li>
                        <li>SELinux policy: auditallow app ashmem execute (moving back towards an exception system)</li>
                        <li>SELinux policy: auditallow ephemeral_app app_data_file execute (moving back towards an exception system)</li>
                        <li>SELinux policy: auditallow untrusted_app_all execmod (moving back towards an exception system)</li>
                        <li>SELinux policy: auditallow untrusted_app_all app_data_file execute (moving back towards an exception system)</li>
                        <li>SELinux policy: auditallow untrusted_app_all app_data_file execute_no_trans (moving back towards an exception system)</li>
                    </ul>
                </article>

                <article id="2019.04.01.19">
                    <h3><a href="#2019.04.01.19">2019.04.01.19</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ2A.190405.003.2019.04.01.19">PQ2A.190405.003.2019.04.01.19</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, other devices)</li>
                    </ul>

                    <p>Initial rebranding to GrapheneOS. This was not the initial release of the
                    project but rather when we switched away from the Android Hardening branding
                    used as a temporary placeholder while we chose a new name to replace our prior
                    CopperheadOS branding.</p>

                    <p>Detailed changelogs were not written at this point.</p>
                </article>

                <article id="2019.03.05.03">
                    <h3><a href="#2019.03.05.03">2019.03.05.03</a></h3>

                    <p>Tags:</p>
                    <ul>
                        <li><a href="https://github.com/GrapheneOS/platform_manifest/releases/tag/PQ2A.190305.002.2019.03.05.03">PQ2A.190305.002.2019.03.05.03</a> (Pixel 2, Pixel 2 XL, Pixel 3, Pixel 3 XL, other devices)</li>
                    </ul>

                    <p>Final and only tagged release branded as the Android Hardening project
                    before it was renamed to GrapheneOS. Earlier AndroidHardening releases were
                    only snapshots and are not listed here. Prior to the AndroidHardening
                    placeholder name, the project was known as CopperheadOS. For more details, <a
                    href="/history/#history">see the page on the project's history</a>.</p>

                    <p>Detailed changelogs were not written at this point.</p>
                </article>
            </section>
        </main>
        {% include "footer.html" %}
    </body>
</html>