Android is moving towards completing one of the areas of verified boot which currently only works in GrapheneOS. They never fully adopted verifying out-of-band system APK updates with fs-verity and then disabled it. They're now moving towards using APK Signature Scheme v4.
Discussion
The kind of progress I want to see! nostr:npub19af7yjy0x52ewdj8yqhrzqak0gnnfnukcyzgvc2yhc24w3lv9m7qsyu82d