AndroidX Security State libraries launch for component-level patching
Google has released version 1.1.0 of the AndroidX Security State library and version 1.0.0 of the Security State Provider library, introducing a centralized mechanism for developers and enterprises to verify security patch status at the individual component level rather than depending on a single device-wide date.
Granular patch tracking across system components
The traditional Security Patch Level (SPL) offers a single calendar date for the entire software stack, which fails to capture rapid updates delivered through modular systems like Google Play. The new AndroidX libraries split this tracking into three distinct metrics for specific components: Device SPL (DSPL) for currently installed patches, Published SPL (PSPL) for official bulletins, and Available SPL (ASPL) for pending downloads waiting via inter-process communication.
These metrics monitor three foundational layers of the OS:

- System: The core Android operating system updated via standard or OEM system over-the-air packages.
- System modules: Modular subsystems updated in the background through Google Play system updates under Project Mainline.
- Kernel: The bridge between hardware and software, evaluated using Long-Term Support release versions like 5.15.159 or 6.1.91 rather than monthly calendar dates.
Contextual security checks for banking and enterprise apps
Security-critical applications in sectors like banking, fintech, and healthcare can now programmatically evaluate device protection before executing sensitive workflows. Instead of rejecting a device outright for missing a monolithic patch date, developer.android.com noted that applications can compare DSPL against ASPL to require specific component updates. Engineers can also use functions like `areCvesPatched()` to verify whether high-risk vulnerabilities affecting components like NFC or Bluetooth are fixed prior to authorizing tap-to-pay transactions.
For original equipment manufacturers, the companion `androidx.security.state.provider` library standardizes how update clients communicate available packages to applications. This abstraction layer ensures that apps do not need to track whether an update originates from Google Play, an OTA client, or a proprietary manufacturer service.
Frequently asked questions about AndroidX Security State
How do applications query the currently installed security patch level?
Apps query the Device SPL directly from running system properties and configurations synchronously without requiring network access.
What is the difference between Published SPL and Available SPL?
Published SPL represents the latest patch level officially released by Google in the Android Security Bulletin, while Available SPL identifies the specific updates ready to be downloaded on that particular device.
Which kernel versions are tracked by the new libraries?
The libraries evaluate kernel security using Long-Term Support release versions, such as 5.15.159 or 6.1.91, instead of traditional calendar-based dates.