GrapheneOS Foundation Suggests Improvements For Early Security Patch Previews


Our security preview releases have provided the December 2025 security patches for the Android Open Source Project since September 2025. December 2025 security patches are now public and being integrated into our regular releases while our security previews have up to March 2026.

A bunch of the patches previously scheduled for December 2025 were made optional and deferred to future months so they're not listed in the public bulletin. That's why even our September 2025 security preview releases list CVEs which are still not public in December 2025.

The reason patches get deferred is because OEMs aren't capable of quickly integrating, testing and shipping patches. When issues are identified including an OEM having trouble with it, they'll often defer it to a future month. Our security previews can continue shipping these.

GrapheneOS is the only Android-based OS providing the full security preview patches. Samsung ships a small subset of their flagship devices. Pixel stock OS gets a portion of it early but we aren't sure exactly how much since they don't follow their guidelines for listing patches.

Providing our security preview patches is a lot of work for us. It requires a full time developer spending a significant fraction of their time on it. It's hard to understand why large companies can't keep up with these patches but what matters is that we can provide them early.

Android security preview patches are currently backports to Android 13, 14, 15 and 16. Since GrapheneOS is based on Android 16 QPR1, we need to forward port the patches from 16 to 16 QPR1. Our understanding is they're going to start backporting to some quarterly releases too.

Android 16 QPR2 appears to be the first quarterly release of Android which is going to be shipped by non-Pixel devices. If that's the case, they'll need to start providing security preview patches backported to it too. It's not clear if it will happen for every quarterly release.

Spending a significant amount of time on this is part of the reason GrapheneOS feature development has slowed down. Expanding our servers and now migrating away from OVH is another. We'll be hiring more people and improving our organization structure to get things moving better.

We would greatly prefer it if patches were disclosed to OEMs 1 week ahead instead of 2-4 months ahead so our security preview releases would only need to exist for a week and regular releases would get the patches much faster. OEMs should just hire far more people and do better.

Fixing old Android code, integrating with the upcoming Thunderbird Pro, and making a balanced iOS roadmap are all part of our mobile development goals in 2026.

#Thunderbird #OpenSource

blog.thunderbird.net/2025/12/s…

Aleca reshared this.

Over November 2025, I've been able to contribute to @gnome, and it was a pleasure!

I focused on GNOME Clocks, with the goal of making it as good as possible for GNOME 50. I focused on #accessibility, #linuxmobile and all sorts of bug fixes and features, as well as issue and MR triaging.

I also fixed some tiny issues in #GTK and #libadwaita, and helped make gettext-pseudolocale as good as possible.

I hope to find more free time to make GNOME Clocks 50 dependable as a mobile clocks app.

This entry was edited (3 weeks ago)

reshared this

Edit: Got it, thanks BlueLegend and Bri.
Mentioning people I know have been contributing to this. In 2024, I made a project in NVGt called FlashFiles, which was quite interesting for my skills at that time. Sadly due to my weird nature back then I deleted it, and only have a few outdated sounds, binarys or a weird old source from april with the most major changes missing. Does anyone still have an old backup/repo clone of this somewhere and would be willing to send it over in DM? I wanna look back on it. And also sorry for deleting it with no comment back then, I don't understand myself from back then. I appreciate your time. And bevore you ask, yup the repo is sadly also long gone and I can't seem to recover it.

@Bri @threlm4280 @garo

This entry was edited (3 weeks ago)

RE: mastodon.social/@Tutanota/1156…

We have to apologize as the statement that "Meta AI will read your private messages" is wrong.

Meta will use your conversation with its AI to show you personalized ads. Here's the Meta announcement: about.fb.com/news/2025/10/impr…


🚨Starting Dec 16th, Meta AI will read your private messages - unless you opt out now! 🚨

Opting out is hilariously complex, but we've got you covered:

1. Go to Meta Privacy Center on DESKTOP
2. Privacy Policy
3. Other Policies and articles
4. How Meta uses information for generative AI model and features
5. Your right to object
6. Learn more and submit requests here
7. Tick: I want to object to or restrict...

Oh, and @noybeu is already on it: tuta.com/blog/noyb-meta-ai-is-… 🍿


Archos reshared this.

Právě jsem zjistil, že až se dostaví tramvaj do Malešic, bude mi jezdit přímej autobus od domu až před kancl. Teď to mám s jedním přestupem z busu na bus.
Pořád budu jezdit do práce na kole. Ale už to asi nebude nejrychlejší volba. Nejzábavnější a nejekologičtější volbou zůstane dál. A až nasněží, bude se to hodit.
pid.cz/wp-content/uploads/syst…
This entry was edited (3 weeks ago)

We’re launching an end-of-year fundraising campaign with a simple goal: to reach 1,500 Friends of GNOME. And we need your help!

blogs.gnome.org/foundation/202…

This week we’ll also be sharing and celebrating accomplishments of GNOME over the past year here on the fediverse; be sure to follow #FriendsOfGNOME!

Finally, if you’re already a Friend of GNOME or join this month, please join us in posting with #FriendsOfGNOME as well so that we can thank you. 😊

#GNOME #OpenSource #FOSS #Linux #GivingTuesday

This entry was edited (3 weeks ago)

reshared this

Im Großen und Ganzen sind die Mitarbeitenden der Mobilitätszentrale der #Bahn echt in Ordnung und geben sich Mühe. Aber es nervt schon, dass a) man das immer noch nicht mit einem ordentlichen Ticket-/Onlineprozess eingeben kann oder es zumindest per Mail lösen kann, b) es jedes Mal anders läuft und jede:r das mit dem Merkzeichen und #Rollstuhl anders abfragt/einordnet und c) ich allein für den #39C3 schon wieder 2 h Telefonzeit in die Hin- und Rückfahrtsplanung/Buchung investiert habe, um doch nur die Hälfte erledigt zu bekommen, weil die Platzreservierung für die #Begleitperson vergessen wurde. Jene würde ich ja gerne bezahlen, aber ich kann sie nicht #online neben meinem Rolliplatz buchen. #wheelscientistontour #Bahnefreibarrierefrei
in reply to Liam Erven

I'm afraid not currently. You keep your followers and follows, bookmarks, lists, and blocks, but you start with fresh history.

As usual, @FediTips has excellent information on transferring to another instance. Basically, everything on their site (and in the masto feed) is gold.

fedi.tips/transferring-your-ma…

Public announcement from Code Factory:
"Starting today, December 2, 2025, we are launching the public beta of Eloquence for Android. To ensure a smooth experience and gather valuable feedback, we’re releasing the beta in stages. This means we’ll be gradually inviting more users over time, starting with a limited group and expanding step by step.
Join the beta from the following link: play.google.com/store/apps/det…

reshared this

in reply to Accessible Android

@Lprazdnik well, we're getting somewhere with this link! "App not available
A testing version of this app hasn't been published yet or isn't available for this account.
If you've been invited to become a tester, make sure you're signed in to the account that was invited to the testing program. If you've been invited to a Google Group as part of the program, make sure you've joined the Group."
@Leo

The Call for Papers for #bsdcan is open, see bsdcan.org/2026/papers.html and nxdomain.no/~peter/what_is_bsd… for some background (f you want to explain to less BSD-savvy friends) #bsdcan #bsd #freebsd #netbsd #openbsd #freesoftware #libresoftware #development #sysadmin #devops #conference

Když mi bylo osm let, přečetla jsem svoji první sci-fi knížku - Setkání s Rámou od A. C. Clarkea. Ta kniha předurčila moje směřování na léta dopředu. Neustále jsem se hrabala v počítačích a vystudovala jsem telekomunikace, radioelektroniku a navigační systémy. Vždycky jsem snila o vesmíru. Sice se mi nikdy nepovedlo Clarkovi poděkovat (nebo mu nadávat, občas si nejsem jistá 😆 ), ale aspoň jsem včera viděla úžasného astronauta, spisovatele a hudebníka, který Clarkea potkal 🥰

There's a first time for everything. Just had to deny a registration request on the official OctoPrint plugin repository as the plugin the author tried to register turned out to be pretty much completely vibe coded. And in the end, even their communication seemed to be the output of an LLM.

Unbelievably bad quality: tons of bugs, dead code, (future) vulnerabilities, ... I honestly haven't yet seen this amount of shittiness from a human developer, no matter how clueless.

I hate this future.

I'm a Google Workspace admin, and a team member sent me a screenshot showing that a message they wanted to send was being blocked because it violated an organizational policy-- which was news to me-- I hadn't put in place to block messages based on their content.

Turns out Google Workspace now warns by default when the message content mentions gender identity.

#google #privacy #politics

Poll: We got curious, so we wondered where you do the majority of your podcast listening if at all?
multiple choice.

  • At home (56%, 38 votes)
  • Out walking (17%, 12 votes)
  • Whendriving (20%, 14 votes)
  • With family/friends (listen together) (4%, 3 votes)
  • Any time I have a spare moment (19%, 13 votes)
  • I can never find the right time (4%, 3 votes)
  • Never really thought about it (1%, 1 vote)
  • I haven't found a podcast I'm interested in (11%, 8 votes)
  • I don't have time for podcasts (11%, 8 votes)
  • What's a podcast? (4%, 3 votes)
67 voters. Poll end: 2 weeks ago

reshared this

I received this new wireless mechanical keyboard that works great. However, in order to get home, end, page up, and page down to work you have to use the function key in conjunction with one, seven, three, and nine on the number pad on the keyboard. My problem is, NVDA interprets these keys as numbers on the keypad rather than home and page up and page down. Does anyone know of a way to stop NVDA from interpreting these keys or possibly using something like sharp keys to reap the keys with other modifier keys to perform the same function? Hope this all makes sense. I like the keyboard other than this. My problem is, I'm not sure that sharp keys would take a key in conjunction with a modifier layer two interpret the key differently. I think the flaw is within NVDA itself, and not so much the keyboard. The keyboard only has a 90% key layout so I'm limited and cannot reap other keys to perform these functions. I guess I really need to figure out how to bypass NVDA to perform these functions on a keyboard by keyboard basis, which makes the whole process much more complicated overall. Am I through breaking your brain yet?

Erinnert Ihr Euch noch an die zeiten, da man eigentlich immer extrem nach Rauch stank, wenn man irgendwo essen war? Was gab es für Proteste, als das Rauchen in Restaurants verboten wurde! Es würden keine Leute mehr kommen, Einschränkung der persönlichen Freiheit... Und heute? Kaum einer kann sich mehr vorstellen, im Restaurant rauchvernebelt zu werden und die Gaststätten sind immer noch voll. Ich Wünschte mir, mehr Politiker hätten den Mut, vielleicht unpoppuläre Massnahmen einfach mal auszuprobieren, angefangen von höheren Strafen gegen Arbeitgebende, die keinen Schwerbehinderten einstellen, über Grundsätzliche Parkgebühren im öffentlichen Raum, über Begrenzung von Geschwindigkeiten auf Autobahnen... Ich wette, man wäre schneller dran gewöhnt, als gedacht...Aber irgendwie traut man sich zu oft nur Massnahmen zum Nachteil derer, die sich am wenigsten wehren können...

reshared this

Petey the Penguin (A Quirky AI Song about a Penguin trying to find a new home) youtube.com/watch?v=difmOiVDqj…

reshared this

Reposting. Slots available.

After a short break, I’m returning to accessibility training services.

I provide one-on-one training for blind and visually impaired users across multiple platforms. My teaching is practical and goal-driven: not just commands, but confidence, independence, and efficient workflows that carry into daily life, study, and work.

I cover:
iOS: VoiceOver gestures, rotor navigation, Braille displays, Safari, text editing, Mail and Calendars, Shortcuts, and making the most of iOS apps for productivity, communication, and entertainment.
macOS: VoiceOver from basics to advanced, Trackpad Commander, Safari and Mail, iWork and Microsoft Office, file management, Terminal, audio tools, and system upkeep.
Windows: NVDA and JAWS from beginner to advanced. Training includes Microsoft Office, Outlook, Teams, Zoom, web browsing, customizing screen readers, handling less accessible apps, and scripting basics.
Android: TalkBack gestures, the built-in Braille keyboard and Braille display support, text editing, app accessibility, privacy and security settings, and everyday phone and tablet use.
Linux: Orca and Speakup, console navigation, package management, distro setup, customizing desktops, and accessibility under Wayland.

Concrete goals I can help you achieve:
Set up a new phone, tablet, or computer
Send and manage email independently
Browse the web safely and efficiently
Work with documents, spreadsheets, and presentations
Manage files and cloud storage
Use social media accessibly
Work with Braille displays and keyboards
Install and configure accessible software across platforms
Troubleshoot accessibility issues and build reliable workflows
Make the most of AI in a useful, productive way
Grow from beginner skills to advanced, efficient daily use

I bring years of lived experience as a blind user of these systems. I teach not only what manuals say, but the real-world shortcuts, workarounds, and problem-solving skills that make technology practical and enjoyable.

Remote training is available worldwide.

Pricing: fair and flexible — contact me for a quote. Discounts available for multi-session packages and ongoing weekly training.

Contact:
UK: 07447 931232
US: 772-766-7331
If these don’t work for you, email me at aaron.graham.hewitt@gmail.com

If you, or someone you know, could benefit from personalized accessibility training, I’d be glad to help.

#Accessibility #Blind #VisuallyImpaired #ScreenReaders #JAWS #NVDA #VoiceOver #TalkBack #Braille #AssistiveTechnology #DigitalInclusion #InclusiveTech #LinuxAccessibility #WindowsAccessibility #iOSAccessibility #AndroidAccessibility #MacAccessibility #Orca #ATTraining #TechTraining #AccessibleTech

Matt Campbell reshared this.

Weck den Tiger in dir mit dem No Spoons-Tiger! Rawr! 🐯 ihr könnt ihn auf T-Shirt, Hoodie, Sweatshirt, Tasse oder als Artprint bekommen 😊.

supergeek.de/de/designer/fuchs…