Initial implementation of secure time updates for GrapheneOS from Renlord:
github.com/GrapheneOS/pla
To avoid regressions, it won't be validating certificate issuance / expiry times, so it can still fix significant time issues. Could add validation based on OS build date later.
