Releases: deegitech/asc-release-kit
Releases · deegitech/asc-release-kit
Release list
v0.1.0
First public release.
Added
doctor: read-only checks of the whole setup in order (settings, the key's
source, permissions, location and format, the token, Apple's answer, the clock,
the hourly rate limit, the app and its bundle ID, Sales and Trends with the vendor
number, the analytics request, Xcode forupload-build), each failure with the
exact fix.--offline,--strictand--json; exit 1 when a check fails.fix:lines: errors with a known fix end with one (in--jsonoutput asfix):
App Store Connect status codes and error codes (for example 401, 403
FORBIDDEN.REQUIRED_AGREEMENTS_MISSING_OR_EXPIRED, 409
ENTITY_ERROR.ATTRIBUTE.INVALID.DUPLICATE,STATE_ERROR, 5xx on writes), network
errors, the exit codes ofsecurityandaws, config mistakes, Apple's upload
codes ITMS-90189, ITMS-90186 and ITMS-90062, and the upload messages "Cloud signing
permission error", "No signing certificate" and "No suitable application records
were found". Any other API error points todocs/troubleshooting.md.- A Keychain item cut off by macOS's interactive password prompt (128 characters,
observed October 2026) is recognised and explained. docs/setup.md(setup from zero, every console step) and
docs/troubleshooting.md(every error message and API code with its fix).auth check: load the API key from exactly one source (key file with owner-only
permissions,ASC_PRIVATE_KEY, macOS Keychain or AWS SSM), sign an ES256 token
withcryptographyor theopensslcommand, and optionally call the API.apps list.release: create or reuse a version, attach a VALID build, set What's New per
locale, copy App Review details and the Game Center link from the live version,
verify by reading back, and submit with an assertion that the version is in the
review submission.release --whats-new-textand a"*"entry in the What's New file: one text for
every locale the file doesn't list. With--submit, an empty What's New or an
open review submission stops the run before anything is written.aso validate,aso applyandaso storefronts: multi-locale metadata from one
JSON file with Apple's limits, keyword checks, a Guideline 2.3.7 denylist, handling
of auto-created localizations (409), and Apple's storefront/locale table.aso pull: write that JSON file from what App Store Connect holds now.analytics request | list | downloadfor the Analytics Reports API with MD5 and
size verification.sales downloadfor Sales and Trends reports, including daily ranges, checked
against Apple's table of valid report combinations, with--allow-missingfor
scheduled jobs.reviews exportto CSV, JSON Lines or JSON with CSV-injection protection.upload-buildwrappingxcodebuild -exportArchive,altool --upload-packageand
notarytool submitwith the API key.- Plan-by-default writes (enforced in the API client), a redacted JSON Lines
journal,--jsonoutput that keeps the events of a failed run, and an offline
test suite against a mock App Store Connect server.
Security
ASC_API_BASE_URL,ASC_SIGNERandASC_OPENSSLare environment-only and
refused in config files; loopback API hosts needASC_ALLOW_INSECURE_LOOPBACK=1.- Helper programs run without
ASC_PRIVATE_KEYin their environment; SIGTERM and
SIGHUP run the normal cleanup, so temporary key copies don't outlive the command. - Key files are checked and read through one file descriptor; local files the kit
writes (journal, reports, exports, pulled metadata) are private (0600/0700).