Auditor and AttestationServer now have support for the verifiedBootHash feature added in key attestation v3:
github.com/GrapheneOS/Aud
github.com/GrapheneOS/Att
The hash uniquely identifies the release, unlike the patch level fields, which can be the same across multiple releases.
Conversation
On devices with Android Verified Boot 2.0 (AVB), the value of verifiedBootHash is the VBMeta Digest (android.googlesource.com/platform/exter). It's available as the ro.boot.vbmeta.digest property so Auditor could have included it with the OS enforced info but hardware attestation is much better.
