Skip to content

listing-kit v0.4.0

Latest

Choose a tag to compare

@bilal- bilal- released this 04 Oct 11:07
· 5 commits to main since this release

⚠️ Behavior changes

  • normalize-screenshot.sh --play now crops to 9:16, not 2:1. A 1080×2400 capture becomes 1080×1920. That's still within Play's 2:1 limit, and it also meets Play's promotion bar: 4 screenshots at 1080 px or more, in 9:16 or 16:9. The validator now checks that ratio too, so 1080×2160 shots no longer count toward promotion eligibility.
  • Stricter validation:
    • App Store screenshots in sizes Apple doesn't recognize fail.
    • The App Store name needs at least 2 characters.
    • A Play tree with no locale folders fails, and so does a JPEG saved as icon.png.
    • Truncated PNGs are rejected.
    • Apple release notes (4000 characters) and Play changelogs/ (500 characters) are now checked.

Secret scan

  • Now caught:
    • OpenAI sk-proj- and Anthropic sk-ant- keys.
    • Stripe secret, restricted and webhook keys.
    • JWTs, including ones whose JSON contains whitespace.
    • Google service-account JSON.
    • GitHub ghs_/gho_/ghu_/ghr_ tokens, including app tokens.
    • GitLab glpat- tokens.
    • Slack xapp-/xoxe-/xwfp- tokens.
    • AWS ASIA session keys.
    • Authorization: Bearer headers.
  • No longer flagged:
    • Ordinary copy such as "Password synchronization across devices".
    • Hyphenated phrases like "task-management-…".
    • URLs that happen to contain "asia".

Fixes

  • sanitize-status-bar.sh no longer aborts on an Android emulator with no notifications posted.
  • visual-diff.sh now compares JPEGs as well as PNGs.
  • ImageMagick: tools are checked per operation. Generating images needs convert; diffing needs compare and identify.
  • grant-permissions.sh stops the iOS app before granting.

Refactors

  • lib/listing.py: one locale and image inventory, shared by the validator and the review page.
  • lib/imagemagick.sh: one ImageMagick 6/7 resolver.
  • tests/helpers.sh: shared fake PNG/JPEG fixtures.

Docs

  • .listing-kit/flows/ is committed. Only .listing-kit/secrets.local is git-ignored.
  • --non-interactive is a mode the agent adopts, not a CLI flag.
  • Run order is build → install → sanitize → grant → launch.
  • Drive by accessibility labels: iOS deep links raise an alert that Maestro can't dismiss.
  • python3 is listed as a requirement.
  • SKILL.md's validate step states what the validator guarantees instead of repeating every store rule.

Validation

  • bash tests/run.sh: 348 passed, 0 failed across 13 test files (also under macOS bash 3.2). CI is green on Ubuntu and macOS.