Scans iOS projects for App Store compliance risks and exports a build-gating JSON report.
Runs the Appflight CLI against an iOS project and gates the build on App Store review risks.
The step installs a pinned version of the appflight npm package onto the
build machine, runs the deterministic check, and writes a machine-readable
JSON report to $BITRISE_DEPLOY_DIR so it is exported as a build artifact.
Privacy manifests (PrivacyInfo.xcprivacy), Required Reason APIs,
NSUsageDescription permission-string quality, ATT, App Transport Security,
background modes, third-party SDK risk, in-app purchase restore requirements,
hardcoded secrets, private API usage, and other App Store review rules.
The default (free) deterministic scan runs entirely on the build machine and
sends no source code or project data. Setting deep: true enables the
paid AI tier, which does send allowlisted findings, a facts digest, and
redacted code excerpts to the Appflight API, and requires an API token.
See the repository README for the full field list and the security review notes.
0 — no findings at or above the fail_on threshold; build passes.1 — findings at or above the threshold; build fails (the gate working).2 — tool or usage error; build fails with a distinct message so a
broken invocation is never silently read as "clean".Upload screenshots, metadata and binaries to App Store Connect (iTunes Connect) and submit your app for App Store review.
Uploads binaries (.ipa / .pkg files) to App Store Connect.