Calyx is supposed to be close to being ready again, relatively speaking. I expect it to be available this year.
I’m on LineageOS with a relocked bootloader and a device maintainer that does weekly updates, which seems like a reasonably good solution to me. That’s also niche enough that I can see why it’s not recommended.
Signing the keys myself isn’t that complicated and now each update takes less than 10 minutes, though to learn it was very confusing and took more time. I can provide more information if anyone else is interested in doing this. I wouldn’t go with a fork of a fork when this is an option for me.
With my specific old phone, there are also still vulnerabilities related to wifi and bluetooth. That isn’t great given I have hearing aids that I keep paired with bluetooth in public spaces. I think this qualifies as “actually pretty bad,” even if it would technically difficult to exploit these vulnerabilities. Anything we are doing in this type of context is a temporary and partial mitigation suitable at best for low risk situations.
I hope the Motorola deal can bring GrapheneOS to more countries.