The GrapheneOS factory images flash a non-stock Android Verified Boot key which needs to be erased to fully revert back to a stock device state. Before flashing the stock factory images and before locking the bootloader, you should erase the custom Android Verified Boot key to untrust it
Would love if someone could fully confirm, though.
I think it does not apply since the verified boot key is replaced.
This thread seems to back this theory up: https://discuss.grapheneos.org/d/444-how-do-i-unlock-the-bootloader-in-grapheneos/3
Would love if someone could fully confirm, though.
Thanks for sleuthing. Appreciated.