Google has stopped automatically pushing Git tags for certain portions of Android source code, requiring developers to request access manually [1].

This shift changes how independent developers and privacy-focused projects interact with the Android Open Source Project (AOSP). By removing automated access, Google introduces a layer of manual approval for code that was previously available through standard distribution channels [1].

According to reports, developers must now submit requests through Google Forms and receive the source code via Google Drive [1]. This replaces the previous system of automatic Git-tag pushes, which allowed developers to track and integrate specific versions of the code seamlessly [1].

The GrapheneOS project, which maintains a privacy and security-hardened version of Android, has raised objections to the new process. The project said the move undermines the transparency and accessibility of the platform [2].

"We are concerned that this change violates the open-source license obligations that underpin Android’s source distribution," a GrapheneOS project lead said [1].

The dispute centers on the legal requirements of open-source licensing. GrapheneOS said that these obligations require free and automated access to the source code to ensure the software remains truly open [1, 2]. By shifting to a request-based system, Google has moved from a public distribution model to one based on individual permission [1].

Google has not provided a public explanation for the change in its distribution infrastructure. The modification affects how developers synchronize their builds with official Android releases, a critical step for maintaining security patches and system stability in custom ROMs [1].

Google has stopped automatically pushing Git tags for certain portions of Android source code

This move signals a potential tightening of Google's control over the Android ecosystem. While Android remains open-source, moving from automated Git distribution to manual requests creates a bottleneck that can hinder third-party developers and security auditors. If the GrapheneOS project's claims are correct, this may represent a shift in how Google interprets its licensing commitments to the open-source community.