GrapheneOS doesn't use microG at all. It runs sandboxed Google Play. microG is the Calyx/Lineage world, different topic.
And it's not about the apps target SDK, its about which play integrity level the app demands: basic runs almost everywhere, device GrapheneOS passes via real hardware attestation, only strong /google-certified can hardblock. An old app can still demand strong, so there's no rule that older sdk works.
Your source only has a point in the microG world.. theres a legacy SafetyNet path microG can spoof. But that's faking it, not real security and Google's closing that path anyway. I deliberately don't keep a fixed app list, it changes with every update. Best bet: check the PrivSec directory + GrapheneOS forum, and just test your own bank with sandboxed Play installed.