Conversation

Replying to and
GrapheneOS is a partner in the security program so it receives security patches in advance. It doesn't help with much, since it only really takes a day to integrate the patches, build, test and ship a release. Major version upgrades are also a different story as you can see here.
2
Replying to and
It's at a major disadvantage for these major version upgrades though, at least for the time being. It appears much harder to work out an arrangement to get early access for those especially since GrapheneOS doesn't follow their rules. They're friendlier with security updates.
1
The major version upgrades bring a lot of important privacy and security improvements every year. When the device support code receives an upgrade to the new major release (which is optional, due to Treble), that tends to prevent simply staying on the previous branch for a while.
1