Delayed patches (they don't keep up with AOSP), missing secure element (makes disk encryption key cracking trivial in comparison).
Fairphone 6/6+ (the latest), is based on..... It's pretty hard to find the Android version it's based on... Got it. They ship phones based on Android 16 half of the year after the release of 17 (9 since public beta).
Many security patches are NOT backported to 16, which makes Fairphone insecure by design.
They allow relocking the bootloader, which is nice, If they also support custom AVB keys, I'd say this is a fine example of the example of the vendor that is not hostile, just not good enough.
I wouldn't say they're hostile - Samsung is hostile for example.
So, what's your angle here? Do you want me to go through every vendor you bring up or what?