Well, they're not above forking their own project to patch security holes and never upstreaming the fixes.
https://grapheneos.social/@GrapheneOS/117282080803799576
> Google should not be gatekeeping security patches to the standard Android platform code from Android OEMs but that's what they've started doing.