icon

Check App Store Compliance with Appflight

Scans iOS projects for App Store compliance risks and exports a build-gating JSON report.

Runs the Appflight CLI against an iOS project and gates the build on App Store review risks.

The step installs a pinned version of the appflight npm package onto the build machine, runs the deterministic check, and writes a machine-readable JSON report to $BITRISE_DEPLOY_DIR so it is exported as a build artifact.

What the checks cover

Privacy manifests (PrivacyInfo.xcprivacy), Required Reason APIs, NSUsageDescription permission-string quality, ATT, App Transport Security, background modes, third-party SDK risk, in-app purchase restore requirements, hardcoded secrets, private API usage, and other App Store review rules.

Data boundary

The default (free) deterministic scan runs entirely on the build machine and sends no source code or project data. Setting deep: true enables the paid AI tier, which does send allowlisted findings, a facts digest, and redacted code excerpts to the Appflight API, and requires an API token.

See the repository README for the full field list and the security review notes.

Exit behaviour

  • 0 — no findings at or above the fail_on threshold; build passes.
  • 1 — findings at or above the threshold; build fails (the gate working).
  • 2 — tool or usage error; build fails with a distinct message so a broken invocation is never silently read as "clean".

Similar steps

Upload screenshots, metadata and binaries to App Store Connect (iTunes Connect) and submit your app for App Store review.

Run App Center launch test for android

Upload an app to Qyrus and run tests.