> GrapheneOS does everything and more for key attestation
Right, that's the problem, in my opinion. I'm not referring to the apps that require Google's keys only, I'm referring to the ones that allow GrapheneOS keys too. If you use one of these apps, you can use vanilla GrapheneOS builds, but you cannot run your own self-signed builds.
You are gaining freedom relative to running Google's OS, but you are still not free to further modify the software running on your own device.
Apps that require "integrity" should monitor their own integrity only, they should not attempt to infer the integrity of their environment.