Changelog

October 2026 · September 2026 · August 2026 · July 2026 · June 2026 · May 2026 · April 2026 · March 2026 · February 2026 · January 2026

October 2026

5.14.0 (2026-10-08)

Breaking changes

  • Release binaries are built with Go 1.27.1 and require macOS 13 Ventura or later. The installer stops with an error on older macOS; keep an older compatible release or upgrade macOS before updating asc.
  • With ASC_BYPASS_KEYCHAIN set, web sessions are cached only in the file backend and never read from or deleted in the system keychain. If you relied on keychain-stored web sessions with the bypass set, sign in again.
  • With ASC_BYPASS_KEYCHAIN set, an explicit ASC_WEB_SESSION_CACHE_BACKEND=keychain now fails with exit code 2 before any Apple sign-in or 2FA, and names both variables. Unset the backend variable or set it to file.

New features

iOS builds on Linux
  • asc builds compile compiles a prepared xtool Swift package into one thin arm64 iOS app with --package-path, --product, and --app-path. Use --platform device or --platform simulator and --configuration debug or --configuration release.
  • asc builds package signs a freshly built device app with rcodesign and writes an IPA with --app-path and --ipa-path. Real signing takes --identity, --identity-password-file, --provisioning-profile, and optional --entitlements, and checks profile trust, expiry, the exact bundle ID, the certificate binding, and requested entitlements before signing.
  • asc builds package --ad-hoc produces a local test IPA without an Apple identity. Apple does not accept it, and it cannot be installed on an ordinary iPhone.
  • Both commands use the xtool and rcodesign you install. ASC does not bundle, download, or redistribute Xcode, Apple SDKs, or Swift toolchains, and you are responsible for complying with the Apple agreements that apply to your build environment. Apple's SDK terms restrict use on non-Apple hardware; read the Linux iOS guide before using this workflow.
  • Neither command discovers credentials, creates certificates or profiles, or uploads. Upload a genuinely signed IPA with asc builds upload --wait as a separate step.
  • Outputs are create-only, the identity and password reach rcodesign through pipes and are never written to disk, and child tools receive an allowlisted environment without ASC_*, cloud, or GitHub credentials.
  • Nested executable code, extensions, embedded frameworks, watch apps, App Clips, and app symlinks are rejected. A simulator build still needs a Mac to install and run.

Improvements and fixes

Performance
  • Every command starts faster, including asc version, because snitch redaction patterns are compiled only when asc snitch runs.
  • macOS keychain lookups skip the legacy asc keychain after one empty probe.
  • --paginate without --limit now requests 200 items per page on 17 list and links commands that previously used Apple's small default page size, including subscription, in-app purchase, Game Center, Asset Library, and creative placement lists.
  • asc screenshots list, asc screenshots download --version-localization, asc video-previews list, asc video-previews download, asc validate, and custom page and experiment screenshot-sets list --include-screenshots fetch media together with their sets instead of making one request per set.
  • asc screenshots download --version-localization downloads up to four images at once.
  • Asset uploads send file chunks up to four at a time, and screenshot and preview uploads reuse connections across files.
  • asc migrate import uploads the screenshots in each set up to four at a time and keeps the planned order.
  • asc metadata push and asc metadata apply send per-locale localization writes up to four at a time. Receipts and JSON actions keep locale order; --if-exists conflict lines on stderr can print in any order.
  • asc testflight config export and asc testflight testers export --include-groups read groups, builds, and testers in parallel.
  • asc insights weekly, asc insights daily, and asc analytics compare overlap their report reads.
  • Current manual and automatic prices are fetched together, and sales reports for a known SKU are streamed instead of buffered.
  • asc builds upload --wait and --checksum avoid repeated version lookups and hashing the same file twice.
  • asc xcode signing plan is much faster on projects with large xcconfig graphs. A config directory swapped while the plan builds now fails instead of being read.
Metadata and media
  • asc metadata push and asc metadata apply no longer fail with a duplicate conflict when a locale is new in both app info and the version. App Store Connect auto-creates the version localization, so the planned create is applied as an update. Dry runs still show create.
  • asc video-previews download --version-localization saves previews as .m3u8 files, because App Store Connect exposes processed previews only as HLS streaming playlists, not the original video.
  • asc video-previews download --id still writes to the --output path you give and prints a warning when that path does not end in .m3u8.
  • asc video-previews download numbers files in App Store order instead of by file name.
  • asc video-previews list and asc video-previews download read every page of preview sets instead of only the first.
  • asc screenshots list, asc video-previews list, and screenshot-sets list --include-screenshots keep App Store order when Apple returns incomplete set media.
  • asc metadata pull --include previews and asc migrate export save preview playlists as .m3u8 with a .preview.json sidecar instead of .mp4 files.
  • Import keeps a remote preview that matches the exported reference. When none matches, asc migrate import and asc metadata push fail before any change, name the file, and ask for the original video or to skip previews (asc migrate import --skip-previews, or leave previews out of asc metadata push --include).
  • Older exports whose .mp4 files contain a playlist are still recognized as references and are never uploaded as videos.
Signing
  • Profiles with a date-only expiration stay valid through the end of that UTC day. asc signing fetch no longer skips them, asc signing sync push no longer renews them early, and stale-profile checks no longer flag them a day early.
  • asc xcode signing plan and asc xcode signing apply accept profiles whose creation date is up to 5 minutes ahead of the local clock, such as a profile just created with asc signing fetch --create-missing on a lagging CI runner. Profiles dated further in the future are still rejected.
Development
  • Faster CI and release pipelines, fewer redundant tests, and deterministic timing tests.

Release · Compare changes

5.13.0 (2026-10-07)

New features

Asset Library
  • asc asset-library videos upload --library-id ID --file video.mp4 uploads an .mp4, .m4v, or .mov video, checks it against Apple's media specifications with ffprobe before reserving the upload, and waits until it is ready. If a later step fails, the receipt keeps the reserved video ID.
  • Image and video uploads accept --category CREATIVE_ASSETS (default) or --category APP_SCREENSHOTS_AND_PREVIEWS, so screenshots and previews can be uploaded once and reused.
  • asc asset-library images and asc asset-library videos add rename, archive, unarchive, and delete. archive and delete require --confirm, and Apple decides which assets are eligible.
  • asc asset-library videos view, asc asset-library videos placements, and asc asset-library videos set-poster-frame --id ID --time-code TIMECODE read a video, list where it is used, and change its poster frame. A new poster frame applies to every placement that uses the video.
  • asc asset-library images list and videos list filter by --category, --state, --spec-id, --reference-name, and --id, and sort with --sort by referenceName, createdDate, or lastModifiedDate (prefix - for descending).
Placements
  • Placement commands are available on version, custom product page, product page optimization treatment, and in-app event localizations. placements create takes --image-id or --video-id. Screenshots and previews need an explicit --placement-group, such as IPHONE_DUO_PROFILE.
  • placements swap --placement-id ID --confirm replaces a placement in one request and keeps the existing placement if Apple rejects the replacement.
  • placements delete --placement-ids ID1,ID2 --confirm removes several placements in order. It stops at the first failure, reports the deleted IDs and the failed one, and keeps library media.
  • placements reorder orders placements on version, custom product page, and treatment localizations. In-app events do not support ordering.

Improvements and fixes

  • On Windows and Linux, credential lookup no longer deletes a stored profile as a supposed legacy duplicate, and named logout works when no legacy store exists. Legacy keychain migration now runs only on macOS.
  • asc metadata push and asc migrate accept iPhone Duo App Previews at 886×1920 in portrait and landscape.
  • Screenshot and Asset Library image uploads reject PNGs with an alpha channel or transparency before reserving the upload, and the error asks for an RGB PNG or JPEG.
  • The bundled App Store Connect OpenAPI snapshot and the asc schema index are updated to Apple's 4.5.1 release, which documents the Asset Library and placement APIs.

Release · Compare changes

5.12.1 (2026-10-06)

New features

  • asc review items add accepts --item-type appAssetLibraryImages and --item-type appAssetLibraryVideos, so an uploaded Asset Library image or video can be added to a standalone review submission. Review item lists and submission history show the asset. Submit with asc review submissions-submit --id ID --confirm; Apple requires an approved app version for standalone review.

Improvements and fixes

  • asc asset-library images upload stops as soon as Apple reports an image as FAILED instead of polling until the upload timeout. The command fails with a receipt that keeps the image ID and state.

Release · Compare changes

5.12.0 (2026-10-06)

New features

Asset Library and creative placements
  • asc asset-library reads an app's Asset Library and its images, videos, image placements, and asset specifications: asc asset-library view --app, asc asset-library images list, images view, images placements, asc asset-library videos list, and asc asset-library specs. JSON keeps Apple's response envelopes, and list commands support --limit, --next, and --paginate.
  • asc asset-library images upload --library-id ID --file image.png uploads a PNG or JPEG creative image and waits for processing. If a later step fails, the receipt keeps the reserved image ID.
  • asc localizations placements list and asc product-pages custom-pages localizations placements list read product page header, App Store search, screenshot, and preview placements, with --placement-type, --include image,video, and --sort filters.
  • asc localizations placements create --localization-id ID --image-id ID --placement-type TYPE assigns an Asset Library image as a PRODUCT_PAGE_HEADER_ASSET or APP_STORE_SEARCH_RESULTS_ASSET on a version localization. Existing placements are left in place.
  • asc localizations placements delete --id ID --confirm removes a placement and keeps its media in the library.
iPhone Duo
  • Screenshots accept the APP_IPHONE_DUO display type in outer (1398×2034 and 2034×1398) and inner (2007×2853 and 2853×2007) sizes, in asc screenshots sizes, asc screenshots upload, and migration size inference.
  • asc video-previews upload accepts --device-type IPHONE_DUO.
Product page optimization
  • asc product-pages experiments treatments create --v2 creates a treatment for a v2 experiment. Without --v2, the command keeps creating v1 treatments.

Release · Compare changes

5.11.0 (2026-10-05)

New features

  • asc migrate import --dry-run --check-remote compares local App Clip and App Preview assets with App Store Connect and prints the planned changes. It requires authentication and may download delivered media for comparison, but does not change remote assets. Without --check-remote, dry runs keep their existing local planning behavior.

Improvements and fixes

Authentication and web sessions
  • asc auth logout --all respects ASC_BYPASS_KEYCHAIN: it removes credentials from config files and leaves system keychain entries untouched.
  • Missing credentials, unknown profiles, invalid config, and denied keychain access produce authentication errors with setup commands or available profile names. These failures exit 3.
  • asc auth login --fix-permissions gives the same missing-private-key guidance as login without the flag.
  • Noninteractive web sign-in fails before sending a password when no two-factor code source is available. Expired-session reauthentication also stops before requesting an unavailable code; use --two-factor-code-command or ASC_WEB_2FA_CODE_COMMAND. Missing code input exits 1, while rejected codes exit 3.
  • asc web apps create runs its field wizard only when both stdin and stdout are terminals. Piped or captured invocations list the missing flags instead of opening the wizard.
  • Rejected Apple Ads OAuth credentials exit 3. Apple Ads and Apple web HTTP failures use the CLI's documented status-based exit codes.
Signing and Xcode
  • Signing, capability, and web app-creation lookups select an exact bundle identifier across all result pages instead of accepting a prefix match.
  • asc xcode validate passes resolved ASC credentials and private-key material to altool, so stored profiles no longer depend on altool finding the key in a private_keys directory. Explicit --api-key and --api-issuer retain altool's key lookup behavior.
  • Signing plans and export options reconcile provisioning-profile, bundle-ID, and team overrides before accepting a profile. Conflicting mappings and profiles that do not match the effective target fail validation.
  • Provisioning profiles with missing or malformed expiration dates, invalid creation dates, or future creation dates fail validation.
  • Read-only mode blocks signing-sync Git pushes and xcodebuild direct uploads before the remote write starts.
Command output and scripting
  • Failed commands that print structured results also print an error summary on stderr. A command that already reported its error on stderr does not print it twice.
  • App Store Connect errors include additional distinct error entries instead of showing only the first one.
  • Table and Markdown output now work for commands that fell back to JSON, including subscription offers and pricing, upload resources, Game Center assets, release and review results, web authentication and app creation, Xcode version changes, and TestFlight metrics. Explicit JSON output keeps the existing response envelopes.
  • asc testflight groups delete and remove-testers print structured stdout receipts.
  • Group flags placed before a subcommand now produce a usage error instead of being silently ignored. Put the flags after the subcommand.
  • Commands following a --next URL reject filters, sorting, and other query flags that would be ignored; put those options on the initial request.
  • --help works after supported positional arguments without reading indirect flag values.
Builds and uploads
  • Transport failures retain their network classification instead of appearing as local-file errors. Wait timeouts keep their original causes and retry guidance.
  • Rejected presigned uploads include the HTTP status, and an HTTP 403 suggests retrying an expired upload URL. Rejected uploads and terminal build-processing failures are classified as expected negative outcomes in upload, wait, and publish workflows.
  • Build-processing diagnostics do not select an arbitrary upload when several retries share the same artifact identity.
  • Version and review workflows using --build-number or --latest select builds eligible for the App Store. Waiting for a build rejects an internal-only build instead of trying to attach it.
  • asc builds dsyms --version live uses the build attached to the live App Store version. Build enumeration stops with an error when Apple repeats a pagination link.
Screenshots, review, and validation
  • Partial screenshot-upload failures report uploaded and pending counts, the underlying error, and a resumable failure artifact. Uploads also warn when names already in the target set would create duplicates.
  • Custom product page preview uploads retain successful uploads and per-file failure receipts when a later upload fails.
  • Failed in-app purchase and subscription review-screenshot delivery explains the failure and prints a cleanup-and-retry command.
  • A failed final review-submit request retains the created submission ID and recovery guidance.
  • asc release stage prints readiness blockers and a validation command on stderr while preserving completed steps and checkpoint recovery.
  • App/platform, age-rating App Info, and validation-selector errors point to the relevant selector or editable App Info. Ambiguous matches produce usage errors instead of choosing a resource.
Pricing, localization, and batch operations
  • Batch imports and mutations preserve exit 6 for read-only refusals while retaining per-item results, including asc apps info edit --locales. Ordinary partial failures still exit 1.
  • Subscription setup verification, price imports, and price equalization report failures on stderr. Pricing failures retain partial results, and missing price matches are classified with guidance for listing valid prices.
  • Subscription pricing reads, localization downloads, and asc migrate export version and App Info exports read every page before reporting success. asc localizations download always fetches all pages; --paginate remains accepted.
  • Unknown tester emails include an invite command. Ambiguous tester matches list candidates instead of choosing one.
  • An unknown web subscription attachment state prints an explanation on stderr instead of returning an unexplained nonzero exit.
  • Provider, file, and profile diagnostics sanitize terminal-unsafe text. Copyable API and screenshot retry commands quote their arguments while failure artifacts retain the original paths.
Documentation
  • README, help, and workflow examples use the current command names, required flags, canonical metadata roots, and two-factor sign-in behavior.

Release · Compare changes

5.10.0 (2026-10-04)

New features

  • asc status --until CONDITION polls like --watch and exits when the condition is reached: review-done, ready-for-sale, processed, testflight-ready, or change. It exits 0 on success and 1 on rejection or failure. --timeout limits the wait, and a wait that ends without an outcome reports pending and exits 7.
  • The asc status summary adds a nextCommands field with runnable asc commands for common states.
  • asc versions attach-build and asc review submit select a build with --build-number or --latest instead of only --build-id, and --wait waits for that build to finish processing. asc versions attach-build also resolves the version from --app, --version, and --platform (default IOS). Builds are matched only within the version's app, version string, and platform.
  • asc iap versions localizations import, asc subscriptions versions localizations import, and asc subscriptions groups versions localizations import create or update version localizations from a JSON file of locales with --file. Unchanged locales are skipped, fields are never cleared, and writes require --confirm unless --dry-run is set. If any locale fails, the rest still run and the command exits 1.
  • asc storekit reads the App Store Server API: transactions view and history, subscriptions status, refunds history, orders lookup, notifications history, notifications test, and notifications test-status, and the sandbox-only groups list and groups members. notifications test requires --confirm.

Improvements and fixes

  • asc status --include testflight reports real internal and external TestFlight build states and latestDistributedBuildId instead of PROCESSING for every build, and makes one fewer API request.
  • asc age-rating view --app and asc age-rating edit --app select the editable App Info when a new version is in preparation, instead of failing because two current App Infos exist. If no single App Info can be chosen, the error names --app-info-id.
  • A missing, unreadable, or invalid private key now fails as an authentication error with exit code 3 and a hint to run asc auth login or asc auth doctor, instead of exit code 1.
  • asc builds upload reports a missing --ipa or --pkg file as --ipa file not found or --pkg file not found instead of a raw stat error.
  • asc auth login without --key-id suggests the key ID when the --private-key file is named AuthKey_<KEYID>.p8. The value is not filled in automatically.
  • asc ipa-info --ipa and asc pkg-info --pkg suggest --path. asc builds view suggests asc builds info, and asc auth list suggests asc auth status and asc auth switch.

Release · Compare changes

5.9.2 (2026-10-03)

Improvements and fixes

  • asc web app-groups assign, unassign, and set no longer fail with Bundle ID capability graph returned 2 of 0 resources for Bundle IDs that have capabilities. They accept Apple's zero-total placeholder on the Bundle ID capability relationships, and still stop before any write when a relationship is actually incomplete.

Release · Compare changes

5.9.1 (2026-10-01)

New features

  • asc auth logout --include-global also removes matching credentials from ~/.asc/config.json when ASC_CONFIG_PATH points to another file.

Improvements and fixes

  • With ASC_CONFIG_PATH set, a keychain-bypassing asc auth login (--bypass-keychain or a truthy ASC_BYPASS_KEYCHAIN) and asc auth init write that file instead of ~/.asc/config.json, so later commands find the new profile. Omitting --name checks for existing profiles in the same file. --local still writes ./.asc/config.json and now warns that other commands read the ASC_CONFIG_PATH file. A relative ASC_CONFIG_PATH fails the login with the same error that reads return.
  • With ASC_CONFIG_PATH set, asc auth logout and the cleanup after a keychain login replaces a profile change only that file and the keychain. An isolated CI job, sandbox, or agent run no longer deletes credentials in ~/.asc/config.json. When that file still holds matching credentials, logout prints a warning on stderr; to remove them, run logout with ASC_CONFIG_PATH unset or pass --include-global. Behavior without ASC_CONFIG_PATH is unchanged.
  • A named asc auth logout that removes nothing exits 1 with a not-found error instead of reporting success. This includes a profile that exists only in ~/.asc/config.json while ASC_CONFIG_PATH is set, and a missing config file.

Release · Compare changes

5.9.0 (2026-10-01)

New features

  • asc validate --ipa PATH reads UIDeviceFamily from the IPA's Info.plist and blocks submission with screenshots.required.ipad when the build runs on iPad but the primary locale has no APP_IPAD_PRO_3GEN_129 screenshot set. The IPA must match the app's bundle ID, the version string, and the attached build number. Without --ipa, a version with iPhone screenshots but no iPad set gets the non-blocking screenshots.required.ipad_unverified info check.
  • asc pricing availability create --all-territories makes the app available in every territory in Apple's current catalog. It cannot be combined with --territory.
  • asc builds wait --report-pending prints the pending state and a resume command to stdout when --timeout expires first, and exits with the new exit code 7. Without the flag, a timeout still exits 1, and the error now adds the last known state and the resume command.

Improvements and fixes

Validation and pricing
  • asc validate blocks submission when the app has no price; Free counts as a price. A never-configured schedule reports pricing.schedule.missing, and a schedule without a current or upcoming base-territory price reports pricing.base_price.missing. Pricing reads that fail still produce the non-blocking pricing.schedule.unverified warning.
  • App, in-app purchase, and subscription pricing use the US Pacific date as "today", matching App Store Connect, and treat a price's end date as exclusive. Results change only on a price's end date or between 00:00 UTC and Pacific midnight. This covers asc pricing current, resolved schedule prices, asc iap pricing summary, asc subscriptions pricing summary, price and introductory offer imports, asc subscriptions pricing equalize and derive, and asc validate. --auto-start-date schedules for the next Pacific day.
  • asc pricing current reports a schedule with no current base-territory price as a configured: false receipt with reason: "no_current_base_price", plus nextStartDate when a later price is scheduled, and prints a pricing schedule create hint. The exit code stays 1.
App Review
  • asc review details-create and details-update check input before sending. Notes over 4,000 characters fail with the number of characters to remove, and +1 phone numbers need 10 digits after the country code. New review details require --contact-first-name and --contact-phone unless --if-exists skip|update is set. These checks exit 2 before any request.
  • When App Store Connect refuses to cancel a review submission, asc review submissions-cancel, asc review submissions-update --canceled=true, and asc submit cancel explain the submission's state and the next step. The exit code stays 5.
  • asc iap review-screenshots create|update, asc subscriptions review screenshots create, asc subscriptions setup --review-screenshot, and asc iap import check review screenshots before uploading. Files that are not PNG or JPEG, have the wrong extension, or have a corrupt header fail with a one-line error and exit 2 before any request. An undocumented size, an alpha channel, or an image that does not fully decode prints a warning, and the upload continues.
Versions
  • When a version string is not found, the error lists the app's existing versions, newest first, and suggests renaming an editable version or creating one. A rejected asc versions create names the version that already uses the string, or the versions still in progress, with the command to resolve it. Diagnostics go to stderr; stdout and exit codes are unchanged.
  • Live versions that Apple reports only as appVersionState=READY_FOR_DISTRIBUTION are recognized by asc builds dsyms --version live, by the whatsNew check in asc review submit and asc publish appstore --submit, and by default version resolution. When both state attributes are present, appVersionState wins.
  • asc versions list --help explains how to find the live version across both state attributes.
  • asc builds dsyms errors no longer repeat the builds dsyms: prefix.
Web
  • asc web commands without a usable web session print a one-line error and a Hint: explaining how to sign in or import a session, instead of the full usage page. The exit code stays 2. asc web review list, show, and threads also name the public API command that answers the same question.
  • Every app-scoped asc web review command resolves --app from ASC_APP_ID or the configured app ID.
CLI and configuration
  • Unknown-command errors suggest the current command for common legacy and sibling guesses, such as asc subscriptions localizations, asc app-info, asc pricing set, and asc review submissions create.
  • asc warns once on stderr when it uses the account home's .asc/config.json as a local config while HOME points elsewhere. Overriding HOME does not isolate that file; set ASC_CONFIG_PATH instead. A future release will stop using that file in this case.
  • Timing-sensitive tests are deterministic, and make test runs isolate inherited ASC_* variables and stored config.

Release · Compare changes

September 2026

5.8.1 (2026-09-30)

Improvements and fixes

  • asc status, asc review status, and asc review doctor recognize a live version that Apple reports as appVersionState READY_FOR_DISTRIBUTION and answer "No action needed." instead of asking you to review the release or submit the version.
  • asc review doctor no longer reports a live version's non-editable state as a blocker. Its other readiness findings still appear.
  • asc builds expire-all --older-than rejects a duration too large to represent, such as 110000d, before any request. Previously the value overflowed and matched every non-expired build.

Release · Compare changes

5.8.0 (2026-09-29)

New features

  • asc ipa-info --verify-signature and asc pkg-info --verify-signature verify signatures and certificate chains offline, anchored at Apple's roots. They check the code directory page hashes and sealed resources for IPAs, the table-of-contents signature and every file checksum for packages, and the leaf certificate type for each artifact. The result is valid, invalid, untrusted-chain, expired, or unsupported, and anything other than valid exits 1.
  • asc ipa-info lists every slice of a universal executable in architectures, each with its own code signature and signer. signerConsistent is false, with a warning, when the slices were signed differently.
  • asc pkg-info reads Distribution product archives, such as those from productbuild or a Mac App Store export, and reports the product identifier, version, minimum macOS version, host architectures, and every embedded component package.
  • asc devices register --via-url --max-devices N ends the registration session after N new devices.
  • asc screenshots frame adds --text-box to draw a filled box behind titles and subtitles, styled with --text-box-color, --text-box-padding, and --text-box-radius or an overlay textBox entry. --font also accepts a .ttf, .otf, or .ttc file, so the font does not need to be installed on the rendering host.
  • asc screenshots frame --input-dir accepts --parallel-workers N to render up to N screenshots at once. Receipts stay in input order.
  • asc web icloud-containers create creates an iCloud container. Containers can never be deleted, so it requires --confirm, refuses an identifier that already exists, and prints a receipt only after reading the new container back.
  • asc web apps create --if-exists skip skips an app that already exists instead of failing.

Improvements and fixes

  • asc web auth login no longer replays expired Apple sign-in cookies or sends each cookie twice. Cached domain-scoped cookies now keep their expiry, which fixes repeated HTTP 503 responses from Apple's sign-in service after a session goes stale.
  • asc web service-ids rename writes only after proving the Services ID's capability list is complete, so a rename cannot drop Sign in with Apple configuration.
  • Full-territory asc pricing availability edit uses a bulk write limit of 16, roughly halving its runtime again.
  • Apple Watch and Apple TV frames were verified against real simulator captures, and the screenshots guide documents native watch and TV framing.
  • Telemetry for an unknown subcommand records the attempted name only when it is one of 25 common verbs, such as list or create. Any other value, including IDs, paths, and flags, is recorded as other.

Release · Compare changes

5.7.0 (2026-09-27)

New features

  • App Store Connect API 4.5 support:
    • asc age-rating edit sets Korea age rating overrides with --korea-age-rating-override (NONE, ALL, TWELVE_PLUS, FIFTEEN_PLUS, NINETEEN_PLUS) and GRAC numbers with --grac-rating-classification-number, or clears them with --clear-grac-rating-classification-number.
    • asc performance overview --app APP_ID reads the app's Xcode performance overview. JSON keeps Apple's complete response; --device-type narrows it to one device.
    • asc subscriptions update sets --market-settings (APP_STORE, APPLE_SCHOOL, APPLE_BUSINESS) and --multi-seat-status.
    • asc game-center leaderboards v2 score-moderations list|update lists submitted scores and blocks or unblocks them. asc game-center details blocked-players list|update manages blocked players. Changes require --confirm.
  • --read-only, or ASC_READ_ONLY=1, refuses every POST, PATCH, PUT, and DELETE before it is sent.
  • asc api <METHOD> <PATH> sends an authenticated raw request to the App Store Connect API, with --query and --paginate.
  • Any flag that takes a value accepts @env:NAME or @file:PATH to read it from the environment or a file.
  • Resource ID flags accept App Store Connect self-links such as https://api.appstoreconnect.apple.com/v1/builds/BUILD_ID. A link of the wrong resource type fails with exit code 2 before any request.
  • asc ipa-info and asc pkg-info inspect local IPAs and flat packages offline, including the signer's common name, team ID, issuer, validity, and fingerprints. Unsigned and ad-hoc artifacts report a null signer; signatures are read, not verified.
  • asc devices register --via-url serves a registration URL and QR code that collects remote testers' UDIDs. Each downloaded profile gets a single-use callback token, and --stream prints one JSON receipt per device as it arrives.
  • asc builds dsyms downloads dSYM files by build ID or by app with --latest, --version, --build-number, or --all, and --wait waits for processing.
  • asc signing sync --storage object --object-bucket NAME keeps encrypted signing artifacts in S3 or an S3-compatible store (--object-endpoint), with credentials from the standard AWS chain. Pushes use conditional writes, and rotate-password stages, verifies, and swaps objects with rollback. Sync receipts add a storage object.
  • asc signing sync nuke --profile-type TYPE revokes certificates and deletes profiles of one type; it requires --confirm, and --dry-run makes no changes. sync push adds --renew-expired, --force-for-new-devices, and --include-mac-in-profiles.
  • asc screenshots frame adds iPad, Apple Watch, and Apple TV frames, --frame-color, titles and subtitles on every device, --font, --text-position, and --input-dir batches with --resume. Output is written only inside --output-dir.
  • asc web service-ids domains set replaces a Services ID's Sign in with Apple domains and return URLs. It refuses to write unless Apple's response proves the capability list is complete.

Improvements and fixes

  • asc pricing schedule create and asc app-setup pricing set default --start-date to today in US Pacific time. The previous UTC default was rejected with a 409 between UTC midnight and Pacific midnight. Explicit dates are sent unchanged.
  • Pricing schedule 409s name the cause: a start date in the past or future, a price point outside the base territory, or an unknown price point. Other 409s print as before.
  • asc analytics view and full-territory asc pricing availability edit send up to 8 requests at once, roughly halving their runtime.
  • asc migrate keeps App Clip and preview files in the canonical layout.
  • Streamed downloads are bounded by the upload timeout.
  • Warnings for the AppInfo kids age band selectors removed in API 4.5 and for deprecated app tag territory lookups.

Breaking changes

  • asc screenshots frame requires Koubou 0.20.0. Upgrade with pip install -U koubou==0.20.0 or brew upgrade bitomule/tap/koubou.
  • A flag value that starts with @ is read as @env: or @file: indirection. Write a literal leading @ as @@.

Release · Compare changes

5.6.0 (2026-09-25)

New features

  • Upload screenshots for a single locale without looking up its localization ID: asc screenshots upload --app APP_ID --version 1.2.3 --locale en-US --path ./screenshots/en-US --device-type IPHONE_65. With --locale, --path points at that locale's files, and --replace --confirm only clears that locale's screenshot set.
  • asc localizations list accepts a version string such as --version 1.0 together with --app, and its table and markdown output now include an ID column.
  • asc pricing availability create, asc metadata push, asc bundle-ids capabilities add, and asc review items-add accept --if-exists fail|skip|update (fail|skip for review items-add). The default remains fail; skip and update apply only when Apple's conflict is confirmed by a read-back.
  • Clear optional listing text with asc localizations update --clear-subtitle, --clear-privacy-policy-url, or --clear-promotional-text, or with null in metadata files. Clearing requires --confirm; required fields cannot be cleared.
  • asc signing fetch --match-extensions also fetches profiles for registered extension bundle IDs under the parent identifier, such as widgets and App Clips. Exact matching stays the default, and --strict-match-identifier makes it explicit.
  • asc signing fetch skips expired profiles. --delete-stale-profiles --confirm deletes expired or invalid profiles for the bundle ID and profile type before fetching, and --dry-run prints the plan without changing anything. asc profiles list adds --stale-only and --include-stale.
  • asc signing keychain adds list, unlock, lock, set-timeout, set-partition-list, and delete for dedicated signing keychains. Passwords are read from files and sent on stdin; delete requires --confirm and refuses the login, System, and current default keychains.
  • asc xcode signing plan --profile PATH infers per-target manual signing settings from provisioning profiles, including wildcard, macOS, and extension profiles, and can write matching export options.
  • asc builds upload reports the resolved buildId with --wait and --verify-timeout. When the build is not found in time, it prints the upload ID and the command to look the build up later.

Improvements and fixes

  • Manual-signing asc xcode export and asc xcode export-options generate now match App Store profiles installed by asc profiles local install. When no signing group matches, the error includes the generator's reason.
  • What to Test notes keep Hindi, Thai, Hebrew, Arabic, and other script marks. Characters App Store Connect rejects in What to Test, including emoji and many symbols, now fail locally with exit code 2 before any request, naming each rejected character.
  • Writing What to Test notes creates a missing TestFlight app localization for that locale and reports it on stderr. A conflict is treated as success only when the locale exists on a fresh lookup.
  • Build processing waits include Apple's processing errors when a build fails, across asc builds wait, asc builds upload --wait, asc publish testflight, asc publish appstore, and asc xcode export --wait. The original failure is kept if the details lookup fails.
  • asc metadata push, apply, and plan leave a scope unmanaged when its app-info/ or version/<version>/ directory is absent, instead of planning every remote locale in that scope as a delete. An existing empty directory still plans deletes and requires --allow-deletes --confirm.
  • asc signing fetch validates the bundle ID only against an explicit --app. The default app from ASC_APP_ID or the config file no longer rejects an explicit --bundle-id.
  • Signing lookups select the exact bundle ID across all pages instead of the first partial match.
  • Updated AWS SDK, golang.org/x/crypto, and tablewriter dependencies.

Release · Compare changes

5.5.0 (2026-09-24)

New features

  • Create App Store versions, review details, and localizations with --if-exists fail|skip|update. The default remains fail; skip preserves existing records, and update applies supported fields.
  • Import in-app purchases from JSON, including localizations and optional review screenshots. Preview with --dry-run, use --skip-existing for existing products, and require --confirm to create products. Failures report partial progress; accepted creates are not rolled back.
  • Reconcile Bundle ID capabilities against entitlements with asc bundle-ids capabilities reconcile plan|apply. Applying requires --confirm; removing mapped capabilities also requires --allow-remove.
  • asc signing fetch --create-missing-certificate can create a missing signing certificate and export a password-protected .p12 for local signing.
  • Create Apple Pay merchant certificates through asc certificates create or asc merchant-ids certificates create.
  • Convert an existing Xcode result bundle to JUnit with asc xcode test junit, and list simulator and Mac test destinations with asc xcode test-destinations. Mac destination queries require macOS.

Improvements and fixes

  • App Group unassign stops if an unproven identifier cannot be checked before reporting a no-op. set requires a successful lookup before an unproven identifier can replace existing assignments; known resource IDs remain supported.
  • Custom product page preview sync validates replacement files before deleting the current set.
  • asc builds expire-all --version limits expiration to one marketing version before applying age and keep-latest rules.
  • asc screenshots list without a locale includes every version localization.
  • Screenshot uploads support bounded concurrency from 1 to 8 while preserving order and cleanup behavior. Analytics report fetching also uses bounded concurrency.
  • Weekly insights paginate analytics metadata and report instances for complete results.
  • Pricing schedule creation defaults an omitted start date to the current UTC date.
  • In-app purchase base-territory input accepts country names and alpha-2 or alpha-3 codes.
  • Developer Portal capability updates verify the returned Bundle ID before writing.
  • Signing profile names are capped at 64 characters. Profile and certificate listing avoids unsupported platform filters.
  • Xcode Cloud product listing obtains app and bundle ID data without a per-product lookup when included resources are available.
  • dSYM downloads receive an independent timeout for each file. Streaming response bodies follow the caller context instead of the HTTP client's body-wide timeout; a caller deadline can still limit the transfer.
  • TestFlight group additions treat conflicts as skipped only after verifying that all requested memberships exist.
  • Background asset submission gives requests independent deadlines and uses a bounded cleanup context for eligible rollback. An ambiguous final-submit timeout still requires checking the returned submission ID before retrying.
  • One-time API key downloads no longer retry ambiguous transport or body-read failures.
  • Workflow error hooks receive a bounded cleanup window after cancellation.
  • Metadata migration removes stale known output files only when their identity can be verified. Windows retains the safe-deletion limitation.
  • Leaderboard-set updates stop on repeated pagination links before making mutations. Included-resource pagination merging scales linearly.
  • Completing a phased release and changing subscription monthly-commitment billing require --confirm.
  • Root --profile works after the command name. Invalid flags and stray operands receive command-specific guidance, with unsafe-to-copy argument text omitted.

Release · Compare changes

5.4.0 (2026-09-19)

New features

  • asc web sign-in-keys list|view|create|download manages Sign in with Apple private keys. Creation and download require --confirm, save the one-time P8 content with private permissions, and never overwrite an existing file.
  • asc apps update can configure production and sandbox App Store Server Notification URLs with --subscription-status-url and --sandbox-subscription-status-url. Both flags require credential-free HTTPS URLs.
  • asc product-pages custom-pages create now creates the required initial version and primary-locale localization with the custom product page, so the new page is ready for content updates.
  • asc builds add-groups --dry-run resolves the build and beta groups, validates assignments, and prints the planned operations without changing App Store Connect.
  • Web commands can select an account from ASC_WEB_APPLE_ID, the last usable cached session, or the only cached session. An explicit --apple-id remains authoritative, and multiple matching accounts produce a disambiguation error.
  • asc validate, asc metadata pull, and version-scoped asc localizations list can select the newest editable App Store version when no version selector is provided, with removed-from-sale and live versions as fallbacks.
  • Ambiguous resource selectors now list bounded candidate names and IDs with the exact flag needed to choose one. Unknown subcommands also suggest close task, alias, and child-command matches.

Improvements and fixes

  • Review submission creation now fails closed when discovery, pagination, identity validation, or item inspection is incomplete. A successful create response that also contains top-level API errors retains the valid submission ID while preserving the command's failure policy.
  • Web session handling rejects symlinked or non-regular cache files, falls back from stale or unusable sessions, writes replacements through private exclusive staging files, and preserves cookie expiry, path, and domain scope.
  • Attachment downloads no longer forward session credentials across unsafe redirects. Web notices and authentication diagnostics also bound and sanitize account, provider, purchase, beta-group, and in-app purchase identifiers.
  • In-app purchase review screenshot replacement binds checksums to the uploaded bytes, avoids unsafe delete-first updates, and produces shell-safe recovery commands.
  • Authentication and signing file operations reject symlinks and non-regular files, preserve staged replacements, verify provisioning profiles before cleanup, repair macOS temporary-key permissions safely, and enforce profile cleanup size limits.
  • Pagination rejects unsafe or repeated next links, bounds App Store review and build --since traversal, surfaces late page failures, and stops sandbox loops and duplicate tester matches instead of returning partial or ambiguous results.
  • Build upload lookup no longer replays exhausted requests or retries permanent app-scoped HTTP 404 responses. Beta group assignment also completes its preflight before mutation.
  • Rating downloads preserve retryable storefront failures through their deadline and stop when the next retry delay would exceed it.
  • Migration export verifies explicit version ownership and preserves privacy URLs. App Group mutations and capability discovery also preserve actionable API failures instead of continuing with incomplete state.
  • Xcode configuration traversal compares normalized include paths and indexes authorized signing paths to reduce repeated allocation and lookup work.
  • Updated AWS SDK, golang.org/x/term, and golang.org/x/text dependencies.

Release · Compare changes

5.3.4 (2026-09-16)

New features

  • asc auth login --fix-permissions repairs an over-permissive private key before login continues. asc auth doctor --fix uses the same repair path, while login without the flag keeps the existing fail-closed behavior.

Improvements and fixes

  • Private-key permission repair is bound to the opened file, rejects symlinks and non-regular files, verifies file identity before changing its mode, and omits executable-looking guidance for terminal-unsafe paths.
  • asc versions links lists every accepted --type value in validation errors, describes --version-id accurately, and distinguishes a missing version, relationship, or pagination page in HTTP 404 errors.
  • asc auth token explains why --confirm is required and prints the exact safe command to run again, including root authentication flags and command options.
  • asc testflight groups add-testers treats an HTTP 409 as a successful skip only when a paginated read-back confirms that every requested tester already belongs to the group. Added and skipped operations now print structured receipts.
  • asc builds add-groups reports Apple's top-level and associated HTTP 422 details, then performs bounded build-state reads for specific recovery commands. Successful assignments and non-422 failures make no diagnostic reads, and the original HTTP status and exit code remain intact.

Release · Compare changes

5.3.3 (2026-09-15)

Improvements and fixes

  • Web authentication discovers Apple's current login service key instead of relying on a stale value.
  • Xcode configuration parsing avoids copying the full traversal stack for each nested xcconfig include.
  • Pricing and availability commands report an unconfigured resource as an expected negative result instead of exposing a raw HTTP 404.

Release · Compare changes

5.3.2 (2026-09-14)

Improvements and fixes

  • Build lookups reject empty selectors and explain ambiguous matches. Upload polling also retries the intermittent HTTP 404 returned before a new build becomes visible.
  • Removed flags now name their replacements, and a first asc auth login without --name uses the default profile name.
  • Web commands distinguish capability-discovery failures, absent availability data, and invalid review-attachment selectors instead of returning misleading generic errors.
  • In-app purchase review screenshot updates use the API's supported request shape.
  • Signing commands preserve keychain utility diagnostics and complete asc signing run when the supplied profiles are valid.

Release · Compare changes

5.3.1 (2026-09-14)

Improvements and fixes

  • Build-localization errors explain when the selected build is not attached to an App Store version.
  • macOS authentication avoids repeated keychain prompts when a usable stored profile already exists.

Release · Compare changes

5.3.0 (2026-09-13)

New features

  • macOS publishing now has a native PKG path: asc xcode export --pkg-path, asc xcode validate --pkg, and asc publish testflight|appstore --pkg work with installer packages. Local builds can also export and upload a PKG with --platform MAC_OS --pkg-path, and direct Xcode uploads no longer need an IPA placeholder.
  • Generated manual signing options support App Store macOS archives. The resolver matches application and installer identities, maps profiles across executable nested bundles, permits profile-free scripting targets, and handles the CloudKit entitlement shapes used by Mac profiles. Other macOS export methods still require an explicit ExportOptions plist.

Improvements and fixes

  • Native macOS provisioning profiles use .provisionprofile, while iOS and tvOS profiles continue to use .mobileprovision. Profile installation, listing, cleanup, and signing sync recognize both extensions and preserve existing legacy repository paths.
  • asc release stage verifies a build's app and platform before changing version metadata. asc validate --version-id also verifies that the selected version belongs to the requested app and platform before running readiness checks.
  • Notarization snapshots the exact private bytes that are hashed and uploaded, detects source changes, and validates SHA-256 hashes, submission UUIDs, and returned S3 credentials.
  • Xcode validation rejects symlinks, empty files, special files, and concurrent rewrites. Archive metadata reads are bounded, and Xcode tools are resolved through the selected trusted toolchain instead of executable names from PATH.
  • --ipa --platform MAC_OS remains available with a deprecation warning. Use --pkg with --version and --build-number for prebuilt Mac uploads.
  • Updated Go cryptography, module, system, and AWS dependencies.

Release · Compare changes

5.2.1 (2026-09-11)

Improvements and fixes

  • asc web auth login recovers when Apple's legacy login configuration endpoint returns HTTP 404, allowing password sign-in and two-factor authentication to continue.
  • Login configuration failures explain that password authentication has not started and point to --api-debug for request details, while preserving the original error.

Release · Compare changes

5.2.0 (2026-09-10)

New features

  • asc versions rating-reset view|create|delete manages scheduled overview-rating resets through an authenticated Apple web session. Creating or cancelling a reset requires --confirm, and the reset applies to every country or region for the selected platform.

Improvements and fixes

  • Initial app availability setup now works through the public API by including every current territory in the request. Selected territories use --available, and all other territories are initialized as unavailable.
  • Web-session availability bootstrap preserves the browser headers and matches the current browser v2 request format.
  • Review submission history ignores empty relationship entries so each item is reported with its actual resource type.

Release · Compare changes

5.1.0 (2026-09-08)

New features

  • asc web removed-apps list, asc web api-keys list, and asc web api-keys view accept --session-from-env for CI reads.
  • --session-from-env reads the versioned ASC_WEB_SESSION bundle in memory, validates the Apple Account identity, and leaves the session cache and keychain untouched.
  • Other commands reject --session-from-env; provider selectors and two-factor overrides are also rejected in this mode.

Improvements and fixes

  • Review-draft create treats a successful response with omitted data as an inconclusive preflight and stops before writing.
  • Review-draft delete reports an unverified result when the response omits data, while explicit data: null and relationship 404 responses still prove absence.
  • Individual API-key P8 files are staged through the private-file path before secret bytes are written, protecting them from inherited macOS ACLs.
  • Individual-key publication keeps atomic no-replace behavior and preserves recovery artifacts when the destination directory grants inherited access.
  • Interactive web login renews its request budget after credential retrieval, two-factor authentication, and keychain waits, so provider selection and session persistence do not inherit an expired deadline.
  • Caller cancellation and caller-owned deadlines remain effective when web login renews its internal request budget.
  • The installer refreshes the pinned ASC skills pack.
  • Help and documentation no longer show the command surface as experimental; operational limits, confirmations, and deprecation guidance remain.

Release · Compare changes

5.0.0 (2026-09-06)

New features

  • asc capabilities inventories supported web-session workflows alongside public API commands.
Local validation, Xcode, and screenshot workflows
  • asc validate warns about placeholder text, short app names, empty or non-canonical keyword segments, repeated phrases, and terms duplicated in an app name or subtitle.
  • --strict turns content-quality warnings into blockers.
  • asc validate --check-urls performs bounded, read-only checks for support, marketing, privacy-policy, and privacy-choices URLs.
  • URL checks reject private destinations, cap redirects, disable proxies, avoid response bodies, and redact URLs and network details from findings.
  • asc xcode doctor reports the selected developer directory, Xcode and SDK availability, xcodebuild, xcrun, beta status, and overall result.
  • asc xcode doctor supports JSON, table, and Markdown output.
  • asc xcode doctor does not switch xcode-select, install software, invoke sudo, or contact App Store Connect.
  • asc xcode test supports test, build-for-testing, and test-without-building with explicit destinations, result-bundle paths, and bounded cancellation.
  • Local Xcode tests safely discover .xctestrun artifacts, preserve ordinary Xcode exit statuses, and keep diagnostics on stderr.
  • asc xcode test emits JSON, table, Markdown, or JUnit results with bounded test failures.
  • asc xcode install validates a signed IPA, its profile, and one exact connected physical device before invoking Xcode devicectl.
  • The install workflow materializes one Payload/*.app bundle in a private bounded directory and verifies its bundle identifier, version, and build afterward.
  • Install diagnostics redact paths, identifiers, tool output, and internal causes; the source IPA is never overwritten.
  • asc screenshots matrix expands a JSON plan across devices, locales, appearances, and content variants with bounded concurrency and retries.
  • Screenshot matrices publish raw captures, optional framed artifacts, and offline HTML/JSON review reports through rooted, no-follow, atomic file handling.
  • Screenshot matrix execution is local and does not upload artifacts to App Store Connect.
Signing, certificates, and notarization
  • asc signing sync push --targets-file synchronizes an app and embedded targets from a strict manifest with per-target and aggregate results.
  • asc signing sync pull selects one bundle ID or a targets manifest, requires complete resolution before writing, and keeps full-repository pulls when no selector is supplied.
  • asc signing sync rotate-password validates every encrypted artifact, rewraps identities and metadata, verifies the replacement password, and publishes one commit without rewriting Git history.
  • Password rotation stops before publication when the current password is wrong or an encrypted artifact is corrupt.
  • Signing sync accepts protected PKCS#12 or PEM identities for MAC_APP_DIRECT and MAC_CATALYST_APP_DIRECT.
  • Direct-distribution signing checks signed macOS and all-device claims and the associated Developer ID Application certificate before Git publication.
  • asc signing keychain install places one verified identity in a new dedicated macOS keychain, optionally adds it to the search list, and leaves the default keychain unchanged.
  • Dedicated-keychain installation validates permissions, certificate binding, team, and optional fingerprint, then rolls back the keychain and search-list change after a failed verification.
  • asc certificates export validates an Apple push certificate, matching unencrypted RSA or EC private key, and optional CSR before writing a password-protected PKCS#12 identity.
  • asc xcode signing plan resolves direct, inherited, and xcconfig settings into a source-bound plan; apply requires its hash and commits staged edits transactionally.
  • asc signing resign validates profiles, teams, certificates, entitlements, nested code, and archive metadata before producing a new IPA through create-only atomic output.
  • Re-signing signs leaf code before containers, avoids codesign --deep, verifies the repacked archive, and never overwrites the input or an existing output.
  • --rebase-team-claims optionally rewrites allowlisted keychain access-group and ubiquitous KVS namespaces, rejecting ambiguous mappings and recording deterministic entitlement changes.
  • asc notarization staple --file PATH --confirm staples a macOS artifact and validates its ticket; asc notarization validate --file PATH performs the read-only check.
  • Notarization commands use bounded diagnostics and rooted no-follow paths, and reject direct ZIP inputs.
Web authentication, API keys, and Developer Portal coverage
  • asc web auth export writes a versioned asc-web-session bundle; asc web auth import loads it from a file or --from-env and can validate it with --validate.
  • Web-session import checks cookie origins and expiration before atomically updating the selected cache; secret values stay out of output.
  • Concurrent web-session writes use serialized cache generations, preventing cleanup from deleting a newer or unrelated session.
  • Bundle IDs, App Groups, and agreements share Developer Portal CSRF refresh, same-origin, cookie-persistence, and team-selection behavior.
  • --developer-team accepts a team ID or exact name; ambiguous multi-team accounts fail closed instead of selecting a team silently.
  • asc web api-keys list and view expose team and individual key metadata without printing private key material.
  • Team API-key creation validates PKCS#8 P8 input and accepts case-insensitive --role values.
  • asc web api-keys create-individual generates a P-256 private key locally, registers only its public key, and saves a recoverable ApiKey_<KEY_ID>.p8 file.
  • Individual-key creation preserves existing destination files and retains the local artifact after an uncertain remote result.
  • API-key revocation handles team and individual keys with a type-specific preflight and post-state verification.
  • Developer Portal commands read iOS and macOS Bundle IDs and support disabling private-cloud-compute capabilities.
  • Developer Portal commands manage Services IDs.
  • Developer Portal commands list visible and hidden iCloud containers.
  • Website Push IDs support verified view, create, and delete operations.
  • asc web app-groups gains exact-set, unassign, and delete operations; deletes stop while references remain, and changed App IDs warn that profiles need regeneration.
  • asc web agreements accept accepts several named agreements in one confirmed request and verifies every requested status afterward.
  • asc web agreements download saves one agreement with HTTPS same-host checks, atomic publication, a size limit, and no signed URL in output.
  • asc web apps create --access full|limited configures full or selected limited app visibility after creation; limited access requires at least one user.
  • Omitting --access from app creation preserves the historical request body.
App, review, privacy, tax, and subscription workflows
  • asc web apps delete preflights observable eligibility and verifies server state after deletion before reporting success.
  • App distribution commands read distribution method and set public or private distribution with readback verification.
  • App commands read status history and app transfer status.
  • Custom-distribution commands list Apple Account recipients.
  • Removed apps can be restored with explicit full or limited access.
  • asc versions update --version-id VERSION_ID --downloadable true|false manages version availability through the public API; setting false requires --confirm.
  • Application and IAP tax-category commands validate catalog choices and resource identity before setting or clearing explicit categories.
  • Tax workflows generate and download one eligible Transaction Tax report.
  • Medical-device declarations support affirmative EEA, GBR, and USA declarations and a detailed regional JSON form.
  • asc web review reads app-scoped Resolution Center threads and unsent drafts.
  • App Review replies send one verified text message; attachment uploads remain unsupported.
  • asc web review drafts create|update|delete manages unsent drafts without sending messages or uploading attachments.
  • asc subscriptions pricing plan-availability show|set reads and updates complete territory sets, including the territories needed by monthly-commitment setup.
  • asc web xcode-cloud workflows list reads workflows for a product through a web session; asc xcode-cloud workflows duplicate copies an existing workflow through the public API.
  • Web Xcode Cloud commands manage the persistent next build number and custom version-alias lifecycle.
  • Web Xcode Cloud commands inspect private SCM provider connection status.
  • asc web sandbox delete protects family members and incomplete snapshots, rejects missing or duplicate IDs, and verifies every requested tester's absence after deletion.

Improvements and fixes

  • Uncertain timeout or server-error responses for Xcode Cloud aliases, Services IDs, and app distribution use readback where available; the CLI never retries these mutations automatically.
  • Invalid flag values now consistently return usage exit code 2 across analytics, Game Center, encryption, IAP, subscriptions, pricing, TestFlight, webhooks, apps, builds, reviews, and Xcode Cloud.
  • asc search prioritizes release-dashboard status intent and routes remaining release follow-ups to the relevant command family.
  • Web login retries a fresh login after a post-two-factor 401, and request deadlines begin after interactive authentication.
  • Web-session compare-and-delete is atomic and backend-scoped; cache generations prevent stale cleanup from deleting newer sessions.
  • Signing writes protect inherited entitlement inputs, preserve special permission bits, detect ACL and extended-attribute drift, and preflight IPA central directories.
  • Xcode signing bounds source graphs, blocks changed shared fallbacks, and preserves xcconfig inheritance and comment state across edits.
  • Re-signing preserves container entitlements and traverses preserved trees through rooted handles, including nested App Clip relationship claims.
  • TestFlight readers decode object-form app-tester dimensions, paginate review readers, retain included rejection context, and document app-endpoint field conflicts.
  • Privacy workflows fail closed on unknown publication state or unrepresentable remote usage values and preserve DATA_NOT_COLLECTED during pull and plan round trips.
  • Privacy planning handles stale catalog tokens and failures partway through a sequence.
  • Monthly-commitment price writes read back the resulting prices so a partial or stale response cannot be reported as success.
  • App Clip capability sync requires --confirm, compares the current graph, skips no-op writes, and preserves unrelated relationships.
  • Certificate listing validates --certificate-type and drops invalid types; app tax-category reads reject mismatched resource IDs.

Breaking changes

  • 5.0 removes the 4.x CLI-side deprecation windows; former warning paths now fail with usage errors.
  • The new web, Xcode, and signing command families ship with experimental labels; 5.1 removes those labels without changing their behavior.
  • asc auth logout requires --confirm before credential access; missing confirmation returns usage exit code 2.
  • asc game-center groups achievements set and asc game-center groups leaderboards set require --confirm before network access.
  • asc game-center leaderboard-sets members set and asc game-center leaderboard-sets v2 members set also require --confirm; missing confirmation returns usage exit code 2.
  • --device on asc signing fetch and asc signing sync push requires --create-missing.
  • asc signing sync push|pull no longer accepts inline --password or ASC_MATCH_PASSWORD; use --password-file or ASC_SIGNING_SYNC_PASSWORD.
  • Product-scoped asc iap localizations, asc iap images, and asc iap submit are removed; use the corresponding version-scoped commands.
  • Product-scoped asc subscriptions localizations, asc subscriptions images, and asc subscriptions groups localizations are removed; use the corresponding ... versions ... commands.
  • Product-scoped subscription review submitters are removed; select IAP or subscription version resources with asc review items add.
  • Deprecated build --id selectors and --build aliases are removed where --build-id is canonical.
  • --newest, --app-id, and deprecated app, version, info, bundle, localization, screenshot, and subscription aliases are removed. Consult the 5.0 command-specific --help for replacements.
  • Replace --two-factor-code with --two-factor-code-command or ASC_WEB_2FA_CODE_COMMAND; negative-keyword views no longer accept --keyword.
  • The undocumented --name and --ref-name spellings retained by iap setup and subscriptions setup remain available.
  • The challenge relationship setter, advanced-experience image delete shim, and Game Center detail pagination flags are removed.
  • --available-in-new-territories, --external-testing, and --challenge-enabled no longer work.
  • --territory ALL is rejected; use --all-territories.
  • ASC_IRIS_SESSION_CACHE and ASC_IRIS_SESSION_CACHE_DIR are no longer read; use ASC_WEB_SESSION_CACHE and ASC_WEB_SESSION_CACHE_DIR. The old IRIS cache is not imported.
  • App-scoped --build-number queries require an explicit --platform, for example asc builds info --app APP_ID --build-number 42 --platform IOS.
  • Read version availability with asc versions view --version-id VERSION_ID; set it with asc versions update --version-id VERSION_ID --downloadable true|false, adding --confirm for false.
  • The Migrate to 5.0 guide includes the complete command table and upgrade checklist.

Release · Compare changes

August 2026

4.11.0 (2026-08-29)

New features

  • asc validate --deep checks App Privacy publication, pending agreements, and first subscription attachment through an existing cached Apple web session.
  • Deep validation remains read-only; it never starts login, opens Keychain, accepts agreements, publishes privacy answers, or attaches subscriptions.
  • --apple-id selects the cached Apple Account, while --strict turns missing-session and other warning findings into blocking failures.
  • Deep results preserve successful public checks when one private endpoint fails, and classify each result as passed, blocked, unverified, or notApplicable.
  • The subscription check distinguishes an approved first subscription from a ready but unattached one, and leaves terminal versions as notApplicable.
  • Incomplete pricing evidence remains unverified, so validation does not infer that an app is free or invent a Paid Apps Agreement blocker.

Improvements and fixes

  • Slack validation notifications keep diagnostics concise while retaining the finding that explains why validation failed.
  • Snitch telemetry classifies descriptions as leaf calls, keeping emitted call shapes consistent for telemetry consumers.
  • Command documentation generation preserves help output when the Go build cache starts cold.

Community and maintenance

  • AWS SDK, Smithy, AWS credentials, AWS S3, and Bitrise utility dependencies received routine updates.

Release · Compare changes

4.10.0 (2026-08-27)

New features

  • asc versions list --latest reduces results to the newest version for each platform.
  • Product-page listings expose documented query controls for filtering, sorting, fields, includes, and pagination.
  • App-event listings expose documented query controls, allowing callers to select the event data they need.
  • IAP v2 listings expose documented list filters, fields, includes, sorting, and pagination controls.
  • Bundle ID listings expose documented filters, fields, includes, sorting, and pagination controls.
  • Certificate listings expose documented filters, fields, includes, sorting, and pagination controls.
  • Provisioning-profile listings expose documented filters, fields, includes, sorting, and pagination controls.
  • Subscription price listings expose documented filters, fields, includes, sorting, and pagination controls.
  • TestFlight beta-group listings expose documented query controls for group discovery and filtering.
  • TestFlight tester listings expose sort, include, and invite-type controls.
  • User listings expose documented query controls for filtering, fields, includes, sorting, and pagination.
  • Xcode Cloud product listings expose documented CI product query controls.
  • TestFlight group creation exposes controls for creating internal and external groups.
  • Shell completion now includes nested commands and their flags.
  • Metadata validation can fetch each unique URL with --check-urls, using bounded concurrency and reporting URL findings as warnings.
  • Metadata validation flags placeholder copy in names, subtitles, descriptions, keywords, promotional text, and release notes.
  • Validation reports screenshot sets that exceed Apple's ten-screenshot cap.
  • Analytics accepts missing sales reports as an explicit condition instead of failing an otherwise usable report set.

Improvements and fixes

  • JSON decoding preserves whether sparse resource attributes were absent or explicitly present as null.
  • Screenshot collection reads paginate complete collections instead of stopping at the first page.
  • Analytics report reads follow continuation URLs, preserving multi-page report output.
  • Signing fetch detects pagination cycles and stops instead of looping indefinitely.
  • Upload rejects zero-length asset operations before starting an upload.
  • Terminal usage diagnostics are sanitized, list validation failures use usage classification, and known flag parse errors stay concise.
  • Metadata pagination deadline coverage and Windows telemetry timing tests are more stable.

Community and maintenance

  • Routine dependency, test, and release maintenance changes are recorded in the release comparison.

Release · Compare changes

4.9.4 (2026-08-26)

Improvements and fixes

  • Xcode commands accept project paths with trailing separators.
  • App Clip mutations reject repeated comma-separated flags instead of accepting ambiguous input.
  • Published-app audits preserve results collected before a later app fails.
  • Replacing a user's visible app list requires confirmation.
  • Stored profile names are normalized consistently during authentication lookup.

Release · Compare changes

4.9.3 (2026-08-26)

Improvements and fixes

  • Subscription price-point streaming validates output flags before starting work.
  • Ratings histogram requests honor cancellation promptly.
  • Report output rejects symlinked parent paths before writing files.
  • Game Center relationship replacement requires confirmation.
  • TestFlight tester metric payloads survive the command's processing path.
  • Encryption commands reject repeated build IDs.

Release · Compare changes

4.9.2 (2026-08-25)

Improvements and fixes

  • Public App Store reads cap oversized Retry-After values, preventing one response from delaying a command without bound.
  • Sandbox list filters survive page traversal.
  • Subscription setup price mutations reconcile their result with the selected price.
  • Build listings reject filters combined with --next, because the continuation URL already contains the original query.
  • Known flag parse errors stay short and actionable.
  • Web app creation explains the missing-company-name case.

Documentation and maintainer workflows

  • Documentation records that the app-scoped builds endpoint can hide the latest build.
  • Maintainer guidance personalizes Wall approvals and records the protected-merge cycle.

Release · Compare changes

4.9.1 (2026-08-24)

Improvements and fixes

  • Build upload failures include actionable context for diagnosing the rejected artifact.
  • Post-upload TestFlight notes failures are recoverable after a successful build upload.
  • Pre-release version matching treats X.Y and X.Y.0 as equivalent.
  • The most frequently missed required flags receive clearer guidance.
  • Remaining high-frequency parameter failures use the correct usage-error classification.
  • Agreement-blocked HTTP 403 responses explain the agreement state that requires action.
  • Preview uploads keep a stable order and report partial results when one item fails.
  • Public App Store reads retry rate-limited responses.

Documentation and tests

  • Root help teaches the discovery loop for finding commands, flags, and examples.
  • Concurrency-sensitive tests share an off-test-goroutine assertion helper.
  • Pricing tests use fixtures that match merged availability behavior.

Release · Compare changes

4.9.0 (2026-08-23)

New features

  • asc optimize keywords rank evaluates keyword rank evidence for a selected app, platform, country, and keyword set.
  • asc optimize search plan combines official Apple Ads evidence with App Store metadata into a read-only review plan.
  • Search planning keeps popularity, impression share, paid conversions, and metadata coverage as separate evidence sources.
  • Search planning writes review-only metadata, exact-keyword, and negative-keyword files when --out-dir is provided.
  • Search planning suppresses absence-based recommendations when required evidence is unavailable.
  • asc pricing availability platforms reports platform availability before an app-wide availability mutation.
  • App-wide remove-from-sale checks whether another platform would remain exposed before changing availability.
  • App version view can resolve a version using app and version selectors.
  • TestFlight tester removal can wait for completion, and tester exports can filter names.
  • Game Center relationship removal requires --confirm.
  • The age-rating audit covers the September 2026 social-media response changes.
  • Web commands report agreement status and provide an agreement-acceptance operation.
  • Subscription setup can derive localized prices from another subscription.

Improvements and fixes

  • Metadata validation catches push-time metadata rejections offline, before the network request.

Release · Compare changes

4.8.0 (2026-08-22)

New features

  • asc builds list exposes the documented /v1/builds query surface.
  • Device registration accepts validated TSV files.
  • Localizations can update directly by resource ID.
  • Categories support --next and --paginate for controlled traversal.
  • App listings can sort by SKU and filter by version or review-submission state.
  • Xcode Cloud artifact listings include artifacts from every run action.
  • asc xcode-cloud doctor diagnoses a build run and can save its logs.
  • asc xcode-cloud run --doctor --wait diagnoses a waited build run.
  • Unknown subcommands suggest common tasks that may match the requested path.
  • Auth logout stages confirmation before deleting credentials.

Improvements and fixes

  • Snitch redacts credentials before reporting diagnostics.
  • System status accepts completed incidents.
  • Analytics warns when report output is truncated.
  • Auth doctor validates private keys supplied through the environment.
  • Auth status reports credential environment precedence.
  • Authentication documentation explains the same credential precedence.
  • Metadata errors provide targeted flag recovery guidance.
  • Metadata required-input errors remain concise.
  • Xcode Cloud status accepts deprecated --id during its compatibility window; new scripts should use --run-id.

Community and maintenance

  • AWS configuration, Go crypto, and Bitrise utility dependencies received routine updates.
  • Maintainer documentation received proportional validation and faster skill workflows.

Release · Compare changes

4.7.1 (2026-08-21)

Improvements and fixes

  • Video-preview uploads preflight set capacity before reserving upload work.
  • Continuation requests reject query flags that their URLs would discard.
  • Unsupported output formats report valid enum values.
  • Bundle ID patch attributes are sanitized before the Web mutation.
  • Single-territory introductory offers honor --dry-run.
  • Search prioritizes precise command paths when suggesting recovery.
  • Misplaced global flags receive a targeted diagnostic.
  • Help examples use first-party command paths.
  • Versions group help includes worked examples.
  • Subscription localization selectors use clearer flag ergonomics.

Tests and compatibility

  • The tvOS ranking test forbids score ordering where the platform does not support it.

Release · Compare changes

4.7.0 (2026-08-21)

New features

  • Screenshots can be listed by version and locale.
  • Localizations and versions expose --include for related resources.
  • Reviews accept multiple --stars values and version-scoped filters.
  • Status exposes the latest build's internal state and expiry.
  • Authentication detects swapped key and issuer IDs before the API returns a 401.

Improvements and fixes

  • Asset upload parts retry transient failures.
  • Long build waits survive transient errors without abandoning the wait immediately.
  • Mutating requests retry rate limits while honoring a bounded Retry-After.
  • Images are rejected when detected format contradicts the file extension.
  • Screenshot downloads preserve unchanged files.
  • Screenshot workflows wait for checksum settlement before proceeding.
  • Screenshot capacity failures explain the recovery action.
  • App-scoped TestFlight group filters use the documented /v1/betaGroups endpoint.
  • Explicitly requested help prints to stdout.
  • --build-id is the canonical build selector.

Release · Compare changes

4.6.1 (2026-08-20)

Improvements and fixes

  • JWT and Apple Ads client secrets backdate issued-at times to absorb small client clock differences.
  • Build release notes are validated before the API request.
  • Positional bundle-ID mutation arguments are rejected before side effects.
  • Repeated comma-separated flags are rejected on nominations, profiles, and win-back offers.
  • Version creation rejects repeated copy-field flags.
  • Apple Ads optimization pagination remains bounded.
  • Query handling follows the documented schema contract.
  • The obsolete Migrate to 1.0 guide was retired.

Release · Compare changes

4.6.0 (2026-08-19)

New features

  • asc system-status reports Apple Developer incidents and their current state.
  • TestFlight notes can be set as soon as builds appear.
  • IPA uploads detect the platform declared by the artifact.

Improvements and fixes

  • Unsafe build artifacts are rejected before an upload reservation is created.

Release · Compare changes

4.5.0 (2026-08-18)

New features

  • asc apps published audits account apps for published territory coverage and reports each published app's territory count.
  • asc apps public rank reports platform-aware public App Store search rank.
  • asc pricing availability remove-from-sale performs a verified app-wide remove-from-sale operation.
  • TestFlight tester lookup reports truncation and keeps a stable output contract for scripts and agents.

Documentation and community

  • The README star-history chart was removed.

Release · Compare changes

4.4.4 (2026-08-18)

New features

  • asc optimize search plan combines official Apple Ads Platform evidence with App Store metadata into a read-only review plan.
  • Search plans preserve popularity, impression share, paid outcomes, and metadata coverage as separate evidence sources.
  • Search plans write review-only metadata, exact-keyword, and negative-keyword files under --out-dir.
  • TestFlight beta testers can be added to multiple groups in one operation.
  • TestFlight beta tester removal requires --confirm.

Improvements and fixes

  • Repeated comma-separated flags on mutating commands are rejected.
  • Availability bulk edits preserve completed work when one operation fails.
  • The golangci-lint cache stays inside the checkout for repeatable builds.

Release · Compare changes

4.4.3 (2026-08-16)

New features

  • Diagnostics carry structured metadata and codes across high-impact CLI failures.
  • Review findings, screenshot validation, TestFlight validation, and submit preflight use structured diagnostic output.
  • Raw TestFlight validation diagnostics remain available for callers that need provider detail.
  • Apple Ads help includes first-run remediation, stdin payload guidance, and starter examples.

Improvements and fixes

  • Search Term Popularity sorting follows the Apple Ads Platform API order.
  • TestFlight notifications are idempotent.
  • TestFlight period-validation diagnostics are preserved through failure reporting.
  • Review submission requests include the appStoreVersion relationship.

Release · Compare changes

4.4.2 (2026-08-15)

Improvements and fixes

  • Xcode export preflight tests no longer depend on the host Xcode installation.
  • Review submission item requests include the appStoreVersion relationship.
  • Root filesystem handling supports restricted working directories.

Release · Compare changes

4.4.1 (2026-08-15)

Improvements and fixes

  • Apple Ads keyword query selectors are checked against Platform API filters.
  • Legacy fields are rejected across Platform API v1 queries instead of being sent silently.

Release · Compare changes

4.4.0 (2026-08-15)

New features

  • Apple Ads Platform API v1 foundation adds the transport, account context, authentication, and base resource commands.
  • Platform v1 campaign resources are available under direct asc ads command paths.
  • Platform v1 Maps and asset resources are available under direct asc ads command paths.
  • Platform v1 reports and optimization resources are available under direct asc ads command paths.

Breaking changes and migration

  • Campaign Management API v5 is deprecated; direct asc ads uses Platform v1, while legacy commands move under asc ads v5.

Release · Compare changes

4.3.0 (2026-08-14)

New features

  • Xcode export supports release-testing builds for distribution workflows.
  • Developer Portal App Groups can be managed through Web commands.
  • App Group mutations include safety checks before changing shared identifiers.
  • Signing can reconcile ad hoc profiles and run commands in isolated signing environments.
  • Signing sync can normalize and store private identities for later pulls and CI workers.
  • asc distribute inspect validates an IPA without wholesale extraction and reports app, profile, certificate, and device facts.
  • asc distribute prepare writes a deterministic verified bundle with bundle.json and payload/app.ipa.
  • asc distribute publish publishes verified install links through a caller-owned S3-compatible endpoint.
  • asc distribute plan, apply, resume, status, and verify compose resumable ad hoc installation stages.
  • Distribution supports separate artifact roots for the bundle, manifest, generated page, and receipt.

Improvements and fixes

  • Analytics download units exclude redownloads and updates.
  • Builds reject unexpected add-groups arguments.
  • Dependency updates cover Go modules used by text processing, PKCS#12 handling, and workflow tooling.

Release · Compare changes

4.2.0 (2026-08-13)

New features

  • asc builds groups lists the TestFlight groups containing a selected build.
  • asc apps rename provides a direct command for changing an app's name.
  • Review submissions can be listed through the nested review submissions list command.

Improvements and fixes

  • Direct Claude child sessions are distinguished in session telemetry.
  • Public storefront failures retain their HTTP status context.
  • Unknown commands stay concise and common command-path mistakes receive recovery guidance.
  • Introductory-offer creation requires a territory; the ALL alias is deprecated.

Release · Compare changes

4.1.0 (2026-08-12)

Improvements and fixes

  • Migrate to 4.0 import-path guidance now matches the command's checked behavior.
  • Screenshot upload help explains selector requirements before an upload is attempted.
  • Key-type failures retain their parameter, and missing versions classify as not found.
  • Metadata apply failures preserve their original failure classification.
  • Subscription availability resolves territories from the subscription itself.
  • Documentation explains how to discover required resource IDs.
  • Removed Review item detail commands guide users to the list command.
  • Managed Xcode export passthrough arguments are rejected instead of accepted and ignored.

Release · Compare changes

4.0.0 (2026-08-11)

New features

  • asc xcode build provides a first-class command for building an Xcode project or workspace.
  • Xcode export and publish expose signing style, team, and related export options.
  • Workflows accept bounded per-step retry and timeout settings and terminate timed-out process trees.
  • Workflow validation accepts explicit JSON output from a validation step.
  • TestFlight publish supports upload-only mode for pipelines that distribute or add notes later.
  • TestFlight can list beta groups containing a selected build.
  • Release staging reconciles routing coverage and includes verified coverage upload stages.

Improvements and fixes

Build, publishing, and signing
  • Next-build-number selection uses the highest usable processed build number across paginated history and in-flight uploads.
  • Restricted accounts retain next-number safety checks, while unusable processed numbers are skipped with a warning.
  • Publish retries post-upload TestFlight propagation and correlates TestFlight reviews with their builds.
  • Synchronized signing assets stay profile-scoped, and unusable profile certificates are skipped.
  • Signing fetch preflights every output path and signing repository Git operations run non-interactively.
  • Auth normalizes key and issuer identifiers before token signing.
  • macOS local profile commands resolve the active Xcode provisioning-profile directory and fall back when Xcode cannot be queried.
  • Unified certificates are recognized for Mac signing.
  • User role and visible-app updates are sent together.
Assets, screenshots, previews, and notarization
  • Interrupted screenshot uploads reconcile reservations before retrying and use canonical reviewed upload targets.
  • Screenshot planning fixes iPad slot selection.
  • App Preview files are validated before upload.
  • Video-preview detail lookup errors are preserved.
  • Notarization preserves archive identity and reports failed multipart completions.
  • Xcode failures preserve early diagnostics and honor reported validation failures.
  • Shared output writes publish new files only after successful writes, and Xcode Cloud artifact writes are atomic.
Validation, pagination, and diagnostics
  • Accessibility and category commands reject conflicting pagination options, while webhooks resume from continuation URLs.
  • Analytics, assets, builds, ratings, and TestFlight requests renew deadlines during long operations.
  • Localization plans, migration payloads, App Clip selectors, version includes, app setup, Slack blocks, and Xcode combinations are checked before side effects.
  • App-info version resolution traverses all pages.
  • Certificate request output paths are preflighted, and pass-type queries require certificate includes before certificate fields or limits.
  • HTTP conflicts and 422 failures use the intended exit classifications.
  • Analytics accepts valid instance and segment resource IDs, and Game Center metrics return authentication errors.
  • Matchmaking weights reject NaN and infinity.
  • Copyright validation warns when text does not start with the four-digit acquisition year.
  • Win-back FREE_TRIAL creation uses --territory, omits a subscription price point, and rejects an incompatible price.
  • Background-asset file updates require --checksum, pricing tier cache writes are atomic, and generated app names preserve Unicode.
  • Structured output write failures propagate, and Slack validation rejects null block payloads.

Breaking changes and migration from 3.7

  • Read the checked Migrate to 4.0 guide and run asc --help plus relevant command help against the 4.0 binary.
  • asc review items view ... and asc review items-get ... were removed; use asc review items list --submission "SUBMISSION_ID".
  • Replace analytics --state with --access-type, replace analytics --date with --processing-date, and replace Review item --state with --resolved or --removed.
  • The singular appStoreVersionExperimentV2 item-type alias was removed; use appStoreVersionExperimentsV2.
  • screenshots upload --replace and video-previews upload --replace require --confirm; --replace --dry-run remains available without it.
  • 4.x temporarily accepts signing --device without --create-missing, but warns and ignores those IDs; 5.0 rejects that combination.
  • Signing fetch and signing sync push refuse existing output files, so clean output directories before rerunning them.
  • Previously accepted ignored flags now fail before authentication or API requests, including conflicting pagination, invalid Xcode values, missing includes, and delete-bearing metadata without --allow-deletes.
  • asc migrate import honors Deliverfile metadata_path and screenshots_path, resolves them relative to the Deliverfile, and requires --allow-external-metadata or --allow-external-screenshots for external paths.
  • asc migrate import recognizes platform "osx" and platform "xros", screenshot uploads use the upload timeout, and invalid locale directories fail before confirmed import.
  • Build numbers use the highest positive processed or in-flight value; local profiles follow active Xcode; asc release stage adds validate_build at steps[0].
  • Workflow numeric outputs retain JSON numbers, while partial migration output reports status: "partial" with a non-zero exit.
  • Screenshot classification covers Apple Watch, Mac, and 13-inch iPad; retired APP_IPAD_PRO_129 is no longer created by planning or applying.
  • Ambiguous 3840x2160 screenshots need an Apple TV or Vision Pro filename hint.
  • asc profiles local clean --confirm operates in the active-Xcode-resolved directory; inspect it or pass --install-dir before destructive use.

Audit, tests, CI, and community

  • The 4.0 audit corrected Review, release staging, workflow output, help, migration, and TTY-aware signing behavior.
  • Review regression coverage and web-only doctor coverage were expanded or disclosed where the command could not verify a state.
  • WinGet release CI avoids requesting workflow scope.
  • Atomic output, notifier validation, request deadlines, certificate paths, app setup, pricing, webhooks, and user-access safety received fixes.

Release · Compare changes

3.7.0 (2026-08-09)

New features

  • The new asc web bundle-ids capabilities enable workflow authenticates against the Developer Portal, checks that the capability is available and editable for the account, performs an exact Bundle ID update, and returns enabled/changed/status output.

Release · Compare changes

3.6.1 (2026-08-08)

Improvements and fixes

  • macOS release artifacts now receive Developer ID signature and notarization verification.
  • Interrupted release workflow steps can be retried with guarded publication and recovery behavior.

Release · Compare changes

3.6.0 (2026-08-08)

New features

  • The Asset Library capability has a discoverable command skeleton while the API surface is being exposed.

API and resource compatibility

  • Video-preview validation accepts Apple’s iPhone 6.9 device alias, and app-event and nomination validation match the current contracts.
  • Xcode Cloud and OpenAPI response decoding preserves typed and currently returned fields instead of silently dropping them.
  • App Store version validation, Bundle ID capability settings, pass-type pagination, and user-role validation now follow Apple’s contracts.
  • Version-localized search keywords are updated through the correct resource.
  • Introductory-offer reads, promotional-offer inline prices, and review/pre-order requests use the corrected response and request shapes.
  • Signing requests use BundleIdPlatform, and unsupported TestFlight external-state editing is deprecated.
  • App Clip advanced experiences, webhooks, and Game Center v2 requests and output now match Apple’s contracts.
  • Analytics and sales-report API contracts are corrected; App Clip inline-localization failures now return the correct exit status.
  • Capability matching recognizes all supported Asset Library spellings.

Reliability and maintenance

  • PTY-dependent web-auth tests are isolated, TestFlight feedback fields remain available when screenshots are included, and build-upload timeout coverage is stable.
  • Crypto, text, and Bitrise utility dependencies are updated.

Release · Compare changes

3.5.1 (2026-08-05)

New features

  • The new asc web api-keys create workflow creates an all-apps team key, downloads and verifies the one-time P8, saves the key and issuer metadata, and reports partial outcomes when a later step fails.

Improvements and fixes

  • Pricing availability bootstrap now fails closed when Apple rejects it, and permanently rejected telemetry events are dropped instead of retried forever.

Release · Compare changes

3.5.0 (2026-08-03)

New features

  • Certificate workflows support pass-type ID certificates, and analytics queries can filter view instances server-side.

Improvements and fixes

  • IPA uploads now validate app identity before starting, ambiguous upload-finalization responses are reconciled, and inherited Xcode output waits are bounded.
  • Xcode build-settings fallback is explicit, and gosec failures reach the security check’s exit status.
  • A non-publishing release rehearsal validates artifact and workflow behavior.
  • Vulnerable dependencies are updated, Dependabot is enabled, and CI uses centralized Go toolchain versions.

Release · Compare changes

3.4.1 (2026-08-01)

Improvements and fixes

  • Analytics decoding and validation accept the current sales-report versions returned by App Store Connect.

Release · Compare changes

3.4.0 (2026-08-01)

New features

  • Web auth can store Apple Account passwords in the native credential store keyed by Apple ID, report whether one exists, remove one, or clear all; storage is bypassed when keychain access is disabled.

Release · Compare changes

July 2026

3.3.0 (2026-07-30)

Improvements and fixes

  • IPA Info.plist expansion and review-response batch fan-out are bounded to limit untrusted workload size.
  • Credentials are redacted at output and error boundaries, and helper environments are isolated.
  • Repository-controlled file I/O is rooted and rejects path traversal and symlink escapes.
  • Workflow examples, interpreted output, and install-skills dependencies are hardened.
  • Post-merge release blockers and regression gaps are closed.

Breaking changes

  • File-driven batch mutations now require explicit --confirm, and privileged mutations bind to their exact captured target. Scripts that previously supplied a file and mutated immediately must add --confirm and should review the target-binding behavior.

Release · Compare changes

3.2.0 (2026-07-29)

New features

  • The asc app-clips default-experiences create workflow accepts --template-id and asks Apple to copy the template experience’s header image and localizations onto the new experience.

Improvements and fixes

  • Apple Ads campaign updates require a campaign envelope, for example {"campaign":{"status":"PAUSED"}}.

Release · Compare changes

3.1.3 (2026-07-28)

New features

  • Screenshot validation detects duplicate pixels and reports the conflicting files before upload.

Release · Compare changes

3.1.2 (2026-07-26)

New features

  • In-app purchase workflows support free offer codes.

Improvements and fixes

  • Search results prioritize canonical workflows, and free offer-code prices render correctly rather than appearing missing or non-zero.

Release · Compare changes

3.1.1 (2026-07-20)

Improvements and fixes

  • API debug output exposes rate-limit fields to make throttling easier to diagnose.

Release · Compare changes

3.1.0 (2026-07-17)

New features

  • Version-scoped API 4.4.1 resources cover in-app-purchase versions, subscription metadata and group versions, and review items.
  • API 4.4.1 age-rating, pricing, and sparse app fields are exposed.
  • Schema output exposes request relationships, making the required linkage shape inspectable before a request is sent.
  • Structured Xcode project version editing and export-options generation from an archive carry project and archive metadata into build/export workflows.

Improvements and fixes

  • The OpenAPI snapshot, coverage plan, and command documentation are synchronized with API 4.4.1.
  • Invalid age-rating combinations, adjusted-equalization requests, and other API 4.4.1 inputs are rejected before mutation.
  • Relationship-limit flags use the corrected plural form, and legacy API 4.4.1 resource spellings are deprecated in favor of version-scoped resources.
  • Deprecated in-app-purchase submit discovery is restored, and subscription localization deletion has explicit confirmation coverage.
  • Nullable request fields and related sparse fields are preserved for versioned in-app-purchase and subscription resources.
  • Absolute xcconfig groups resolve correctly when editing Xcode projects.

Release · Compare changes

3.0.0 (2026-07-16)

New features

  • Pricing workflows can create missing app-availability records.
  • Canonical view and edit command forms are defined for consistent command discovery.

Improvements and fixes

  • Focused invocations build only the selected command tree, and output-renderer registration is deferred until first lookup.
  • Uploads use four default chunk workers and a tuned transport.
  • Complete environment credentials skip keychain lookup, and failed pagination or key-file writes are guarded and cleaned up.
  • Unknown flags and help text are clearer, and analytics-ranked flag aliases are accepted.
  • Web HTTP status is preserved in exit codes for ordinary, retried, and authentication failures.
  • Invalid private keys are usage errors and invalid web credentials are authentication errors.
  • Missing app availability and missing availability edits are classified as not-found outcomes.
  • Metadata, subscription-setup, subscription-screenshot, and authentication validation findings are classified in telemetry.
  • Subscription-availability remediation points to the correct repair path.
  • Installation checksum verification fails closed and release binaries are stripped.

Release · Compare changes

2.8.2 (2026-07-13)

Improvements and fixes

  • asc subscriptions validate checks UPFRONT and MONTHLY commitment plan availability and reports actionable territory and pricing remediation, including review-screenshot delivery state.
  • Subscription pricing now materializes the complete price matrix so paginated or sparse price-point data does not produce an incomplete result.

Release · Compare changes

2.8.1 (2026-07-11)

Improvements and fixes

  • Compliance-form requests now send the X-Csrf-Itc header required by the web endpoint.

Release · Compare changes

2.8.0 (2026-07-11)

Improvements and fixes

  • macOS release binaries are signature-verified after signing.
  • Repeated local builds avoid unnecessary tooling work and complete faster.
  • Metadata keyword workflows are split into command-owned files, Xcode Cloud operations into resource files, and submission and screenshot workflows into focused files.
  • ASC client queries are grouped by resource to make endpoint behavior easier to maintain.
  • CI runs checks on native runners and selects checks from the changed scope.
  • Obsolete low-signal coverage is removed and the 2.8.0 release readiness checks are hardened.

Breaking changes

  • The ASC Studio application, its frontend, and its dedicated release/check workflows were removed. Users of that separate application must continue with the asc CLI workflows.

Release · Compare changes

2.7.0 (2026-07-10)

Improvements and fixes

  • Xcode Cloud workflow responses retain typed fields returned by Apple.
  • Skills availability checks run off the command path, so normal invocations do not pay that check’s latency.
  • Telemetry is stored and forwarded asynchronously, with bounded v4 outcomes and collector latency tolerated in production.
  • Readiness validation collapses independent checks and runs them in parallel.

Release · Compare changes

2.6.1 (2026-07-08)

New features

  • asc metadata plan writes a review artifact from canonical metadata; asc metadata approve approves all, selected keys, or scopes; and asc metadata status reports the local approval state. The apply path verifies the approved plan before writing.

Improvements and fixes

  • Failure telemetry now emits sanitized failure parameters.
  • The Go toolchain is updated to 1.26.5.

Release · Compare changes

2.6.0 (2026-07-06)

New features

  • asc web apps delete --app APP_ID_OR_BUNDLE_ID --confirm resolves the selected app, verifies the target, and deletes it through Apple’s web API.
  • asc web removed-apps list lists apps visible in the Removed Apps status view.

Release · Compare changes

2.5.1 (2026-07-05)

Improvements and fixes

  • Web-session workflows that had completed their stability period are promoted into the supported command surface.
  • Integration key files use restricted permissions.
  • The scheduled weekly integration test job is removed.

Release · Compare changes

June 2026

2.5.0 (2026-06-28)

New features

  • asc review items now provides nested list, get, add, update, and remove commands for review-submission items.
  • asc subscriptions list --app APP_ID resolves an app scope across its subscription groups.

Improvements and fixes

  • Subscription setup reuses matching groups, subscriptions, localizations, prices, and availability records, verifies the resulting state, and reports a clear conflict when an existing resource does not match the requested configuration.
  • Subscription price set converges on an existing matching price instead of creating a duplicate.
  • Subscription localization create and IAP localization create are idempotent when the requested localization already exists.
  • Build-test-note localization creation reuses an existing matching localization.
  • Validation failures are classified in telemetry, and review-rating lookups resolve the app identifier before requesting ratings.
  • App-info edit converges after localization conflicts instead of leaving an ambiguous partial result.

Release · Compare changes

2.4.1 (2026-06-28)

Improvements and fixes

  • Resolved price listing now selects the newest matching relationship record and preserves the associated territory and plan type.
  • CI runs independent GitHub Actions steps in parallel and shards Go tests across runners.

Release · Compare changes

2.4.0 (2026-06-26)

Improvements and fixes

  • Anonymous telemetry events now carry bounded command, invocation, error-kind, and failure-stage context, while keeping the event payload sanitized.
  • Maintainer workflows are migrated into the repository’s agent-skill packages, making audit, release, issue, community-app review, and related procedures discoverable and reusable.

Release · Compare changes

2.3.0 (2026-06-24)

New features

  • Failed screenshot uploads write a failure artifact that can be resumed with asc screenshots upload --resume PATH; resume continues pending files and ordering work without recreating completed uploads.
  • High-level workflow runs can resume from a saved run ID with asc workflow run --file FILE release --resume RUN_ID, reporting resumed step state.
  • TestFlight crash and feedback list commands accept --include to request related resources from Apple.

Improvements and fixes

  • Introductory-offer operations now enforce their timeout contract instead of waiting without a bounded deadline.
  • Webhook shutdown no longer races on its shutdown channel.
  • App-info batch test counters are race-safe.
  • Missing subscription App Review screenshots are reported explicitly so validation can name the required upload.

Release · Compare changes

2.2.0 (2026-06-20)

New features

  • The new asc storekit retention-messaging command group covers image and message list/upload/delete operations, default-message view/set/delete, endpoint view/set/delete, and performance start/view/wait operations.
  • StoreKit retention messaging requests support the sandbox and production environments, validate UUIDs and message payloads, and use the retention-messaging API’s image, message, default, and performance resources.

Release · Compare changes

2.1.2 (2026-06-19)

Improvements and fixes

  • Telemetry status, enable, disable, and reset-ID operations are documented alongside ASC_TELEMETRY_DISABLED, ASC_TELEMETRY_ENDPOINT, and ASC_TELEMETRY_EPHEMERAL.
  • The README and generated command documentation disclose anonymous telemetry.

Release · Compare changes

2.1.1 (2026-06-18)

New features

  • asc telemetry status, asc telemetry enable, asc telemetry disable, and asc telemetry reset-id let operators inspect and control anonymous CLI telemetry.

Improvements and fixes

  • Adds an iOS release guide for agents covering the build, signing, upload, and App Store Connect handoff.

Release · Compare changes

2.1.0 (2026-06-16)

New features

  • asc subscriptions pricing monthly-commitment supports listing, enabling, disabling, and bootstrapping paired UPFRONT and MONTHLY prices for supported territories.
  • Monthly-commitment list and price list commands accept --plan-type, and enable can create MONTHLY prices.
  • asc builds next-build-number now resolves the next safe number from both the latest processed build and the latest in-flight upload, avoiding reuse after a zero-build upload.

Improvements and fixes

  • The OpenAPI snapshot is synchronized with Apple’s API 4.4 republish, and monthly-commitment and STORAGE metric documentation is updated.
  • The CLI warns when the deprecated ACCESS_TO_REPORTS user role is used.
  • Alternative-distribution help includes EU addendum guidance.
  • FREE_TRIAL offer-code prices are resolved with the correct territory price relationship.

Maintenance

  • The monthly-commitment plan-type filter is documented.

Release · Compare changes

2.0.0 (2026-06-10)

New features

  • asc xcode inject --manifest FILE generates plist, JSON, text, and copied-asset outputs from a deployment manifest. --set key=value overrides manifest values, --dry-run validates without writing, and --overwrite permits replacing existing outputs.
  • Individual App Store Connect API keys are supported in configuration and JWT signing. Individual credentials use the sub user subject and do not require an issuer ID.
  • Subscription plan availability, app-availability content statuses, and API 4.4 schema/index coverage are added.
  • Background-asset list commands can filter by locale, and performance metrics recognize STORAGE.

Improvements and fixes

  • Win-back offer creation inlines price relationships and validates or clarifies price-point inputs before sending the request.
  • asc install-skills applies a timeout and installs skills globally as intended.
  • API notes record the monthly-commitment behavior and the ACCESS_TO_REPORTS role deprecation.
  • The Makefile adds a parallel test target for multi-core local execution.

Breaking changes

  • Deprecated command implementations are removed from the current command tree.
  • The beta build-localizations group and legacy asc builds find and asc builds latest paths are gone; use asc builds info and asc build-localizations as shown by help.

Release · Compare changes

1.9.2 (2026-06-06)

New features

  • Keychain credentials can now move to config.json with asc auth export-to-config --confirm; the command exports embedded private-key material to a restricted .p8 file when the original path is unavailable, preserves the selected default profile, and reports per-profile warnings when cleanup cannot finish.

Improvements and fixes

  • The Go toolchain and module dependencies are updated.

Release · Compare changes

1.9.1 (2026-06-02)

Improvements and fixes

  • asc profiles list now includes ACTIVE and INVALID profiles by default and accepts --profile-state for narrower results; pagination keeps the filter on subsequent pages.

Release · Compare changes

1.9.0 (2026-06-01)

New features

  • asc ads now covers Apple Ads Campaign Management API v5 resources, including campaigns, ad groups, ads, keywords, negative keywords, targeting, reports, and account context. It uses separate Apple Ads OAuth credentials and supports named profiles or ASC_ADS_* environment variables.
  • Apple Ads operators get setup, org-discovery, read-only smoke-test, reporting, raw-request, and guarded-cleanup playbooks.
  • Campaigns can be paused or resumed with asc ads campaigns pause --campaign ID --org ORG_ID --confirm and the matching resume command.
  • Report presets cover campaign, ad-group, keyword, search-term, ad, and nested ad-group levels. They build requests from flags such as --from, --to, --last-days, --granularity, --fields, --sort, --limit, and --time-zone; custom selectors remain available through JSON payloads.
  • Endpoint and auth behavior has regression coverage, including the no-org me and acls paths. Report presets validate selectors, integer IDs, UTC rolling ranges, ORTZ rules, required ordering, and report-level restrictions.

Improvements and fixes

  • Ads authentication now supports discovery, profile validation, doctor diagnostics, and direct short-lived token output behind --confirm, with clearer separation between Ads and App Store Connect credentials.

Release · Compare changes

May 2026

1.8.0 (2026-05-31)

Improvements and fixes

  • Screenshot fan-out rejects duplicate names before upload, preserving unambiguous local artifacts and relationship updates. Downloaded screenshots retain their server order, and resumable or skipped uploads synchronize relationship order for locales with no new files.
  • Build lists can exclude expired builds, and latest-build selectors expose --exclude-expired with its --not-expired alias; these selector flags require --latest where the selector is ambiguous.
  • Release and submission selection accepts READY_FOR_DISTRIBUTION, allowing a processed version to continue through the expected flow.
  • Web authentication can select a provider and carry it through cached and prompted sessions; phone-based two-factor behavior has regression coverage.
  • The web session can sync an App Clip's parent-bundle capability with app-scoped lookup, update, validation, and output.
  • Device registration reuses an already registered UDID instead of treating an idempotent Apple response as a hard failure. Long bundle-identifier filters split into API-safe requests while retaining the complete result set.
  • Review demo password length is checked before a web-session request, and certificate tests cover Unicode CSR subjects. Internal TestFlight group payloads also receive regression coverage.

Release · Compare changes

1.7.0 (2026-05-30)

New features

  • Release automation now generates WinGet manifests, uploads them as release artifacts, and submits the Rorkai.ASC package manifest to microsoft/winget-pkgs.
  • asc screenshots upload enforces the App Store screenshot-set cap and lets operators select the first N sorted files with --max-screenshots; asc xcode export --timeout DURATION bounds the local xcodebuild -exportArchive process and reports a timeout with command context.

Improvements and fixes

  • The release follow-up fixes retry handling when WinGet publication has to be repeated.

Release · Compare changes

1.6.1 (2026-05-29)

New features

  • Web sessions now expose App Store compatibility opt-ins through asc web apps compatibility view --app APP_ID and asc web apps compatibility edit --app APP_ID --ios-app-on-mac=BOOL --ios-app-on-vision-pro=BOOL; the update targets the selected settings.

Improvements and fixes

  • asc signing fetch now scopes profile retrieval to the resolved bundle ID resource, preventing a matching profile from another bundle from being selected.
  • The maintainer workflow now documents how release announcements are recorded, and helper scripts ignore generated Python bytecode.

Release · Compare changes

1.6.0 (2026-05-28)

New features

  • asc profiles inspect --path ./profile.mobileprovision parses a local provisioning profile without an App Store Connect request and supports JSON, table, markdown, and optional --entitlements output.

Improvements and fixes

  • The Iris attach flow skips its POST when an IAP already reports an operation in flight, reducing duplicate web-session writes during retries.
  • Community-app fork submissions now validate that the parent entry exists and belongs to the requested fork.
  • Localization update diagnostics preserve attempted field context when Apple's error response is generic.
  • The hand-maintained website changelog and release-doc validation were removed in favor of GitHub-generated release notes.

Release · Compare changes

1.5.4 (2026-05-26)

Improvements and fixes

  • Iris IAP listing fields are corrected, and --iap-id accepts either the Iris resource ID or the bundle-style productId; the command resolves the input to the Iris ID before posting and narrows already-attached handling to true idempotent conflicts.

Release · Compare changes

1.5.3 (2026-05-26)

New features

  • asc web review iaps attach now handles non-renewing in-app purchases with app-scoped lookup, a review-submission target, confirmation for the write, idempotent already-attached handling, and resolved-resource output.

Improvements and fixes

  • The README now shows macOS TestFlight distribution end to end, including .pkg upload and adding the build to a macOS tester group.

Release · Compare changes

1.5.2 (2026-05-25)

New features

  • asc status --platform can scope universal-app dashboards to iOS, macOS, tvOS, or visionOS when resolving builds, App Store versions, and review submissions.
  • Certificate creation can generate the CSR inline from supplied subject values and continue through the signing flow.

Improvements and fixes

  • Offer-code commands now print follow-up hints for the next list, value-export, or status command.

Release · Compare changes

1.5.1 (2026-05-22)

New features

  • Equalized subscription pricing can be scheduled with an explicit or derived start date; --dry-run previews the plan, the result reports schedule state, and invalid boolean values fail before an update.

Improvements and fixes

  • Subscription offer-code list and value exports now sanitize names, keep table and markdown columns consistent, report CSV write failures, and cover one-time-code values.

Release · Compare changes

1.5.0 (2026-05-18)

New features

  • asc search builds a deterministic local index over command paths, summaries, usage text, examples, and flag names. It supports command-oriented aliases, typo-tolerant fallback matching, --limit, and JSON, table, or markdown output.
  • asc reviews respond-batch groups customer review replies, supports --dry-run, skips reviews that already have a response, and filters by response state before writing. Review lookup exposes responded and unresponded filters plus the response fields needed to plan batches.

Release · Compare changes

1.4.2 (2026-05-16)

New features

  • asc background-assets submit plans the selected version, supports --dry-run, reuses an existing review submission when possible, and rolls back an attachment if submission fails.

Improvements and fixes

  • asc apps wall submit --country can resolve a non-US storefront such as Japan. Metadata validation preserves blank-template behavior while tightening app-info and version-localization checks.

Release · Compare changes

1.4.1 (2026-05-11)

New features

  • asc metadata init creates locale-aware app-info and version-localization templates with validation-friendly defaults.
  • An experimental, guarded monthly-with-12-month-commitment subscription surface covers Apple's April 2026 announcement. It validates ONE_YEAR subscriptions, excludes the USA and Singapore territories, and enforces the 1.5x upfront-price rule while the public App Store Connect API lacks billing-mode fields.

Improvements and fixes

  • Xcode Cloud secret environment-variable creation now fetches its encryption key from the CI auth endpoint outside the /ci/api base path. The metadata docs explain when version-localization IDs become available to asc metadata validate.

Release · Compare changes

1.4.0 (2026-05-08)

New features

  • asc capabilities reports coverage for CLI, public-API, web-only, and API-limited workflows, with JSON, table, and markdown output plus --status and --area filters.
  • asc publish appstore --metadata-dir validates and plans a prepared metadata directory, applies version metadata, then continues through App Store submission.
  • Subscription review notes can be updated, and an experimental web-session command removes a subscription from sale with confirmation and post-write verification.

Improvements and fixes

  • FREE_TRIAL subscription offer-code creation no longer requires --prices and rejects price input that does not apply to that mode.
  • Analytics report relationship lookup accepts Apple-prefixed report IDs, and metadata workflows recognize the current Bangla locale alias, bn-BD.
  • Repository formatting and Go tooling are refreshed, and govulncheck runs with a patched Go toolchain.

Release · Compare changes

1.3.0 (2026-05-04)

New features

  • asc analytics request --reuse-existing returns an active matching request before creating another one and falls back to that request on an App Store Connect duplicate-request conflict.
  • asc apps registry pull maintains .asc/app-registry.json by refreshing App Store Connect identity data, preserving local-only fields, supporting dry-run planning, rejecting duplicate keys, writing through symlink-safe paths, and requiring --confirm with --prune-missing.

Improvements and fixes

  • The release includes documentation and command-level regression coverage for reusable analytics requests and app-registry pulls.

Release · Compare changes

April 2026

1.2.7 (2026-04-27)

New features

  • asc subscriptions offers introductory create accepts --all-territories and --territory ALL; it reads current availability, supports --dry-run, skips existing introductory offers, reports created/skipped/failed counts, and rejects a price-point override that cannot be applied consistently across territories.

Improvements and fixes

  • The macOS CI regression check for web-auth Ctrl+C is stable while retaining assertions for a non-usage exit and no password-required fallback.

Release · Compare changes

1.2.6 (2026-04-24)

Improvements and fixes

  • asc subscriptions setup auto-enables --price-territory when --territories is omitted, while preserving territory overrides, preserveCurrentPrice, and start-date fields in the pricing request.

Release · Compare changes

1.2.5 (2026-04-23)

Improvements and fixes

  • Workflow validation permits duplicate output-producing step names in independent workflows, still rejects a collision when both producers can run in the same graph, avoids partial reachability-cache results across cycles, and documents output scope.

Release · Compare changes

1.2.4 (2026-04-22)

New features

  • asc publish testflight --submit --confirm can submit external groups for beta review, reusing the builds add-groups submission helper, waiting for a processing build where required, and reporting beta review state in publish output.

Improvements and fixes

  • The README shows a complete single-locale screenshot upload, and the docs clarify the app-info localization variant and refresh related workflow examples.

Release · Compare changes

1.2.3 (2026-04-17)

Improvements and fixes

  • Repository, documentation, and issue links now use rorkai. Homebrew releases publish to the rorkai tap, with a formula smoke test matched to the current help surface.
  • The web-auth interrupt PTY test is more stable, and the legacy installs-badge workflow is removed.
  • Release automation refreshed the estimated-downloads badge.
  • The root CLI tagline and branding are refreshed.

Release · Compare changes

1.2.2 (2026-04-14)

New features

  • asc app-clips invocations create accepts --locale and --title, validates the pair, and creates the required localization inline with the invocation.

Improvements and fixes

  • asc migrate import with a Deliverfile that sets skip_screenshots has regression coverage; submission lookup not-found and empty version-ID branches are also covered.
  • Release automation refreshed the estimated-downloads badge.

Release · Compare changes

1.2.1 (2026-04-11)

Improvements and fixes

  • asc migrate import skips unsupported screenshot files such as .DS_Store, tolerates empty locale directories, resolves metadata-only layouts without a screenshots/ directory, and exposes --skip-screenshots for an explicit metadata-only run. Submission regression coverage includes build attachment and existing-submission lookup.
  • Release automation refreshed the estimated-downloads badge.

Release · Compare changes

1.2.0 (2026-04-09)

New features

  • asc review submit is the canonical shortcut for attaching a build and sending a prepared App Store version through the modern review-submission flow; it reuses shared preflight and submission logic and emits caller-specific remediation.

Improvements and fixes

  • The shared review path now short-circuits an already submitted version before preflight or build attachment, and asc publish appstore --submit returns cleanly on a submitted version. Regression tests cover submitted-version reruns, price-territory parsing, and screenshot resume-mode conflicts.
  • The release fixes the auth-doctor migration guidance order for the review-submit flow and checks screenshot resume-mode conflicts and subscription price-territory parsing.
  • Release automation refreshed the estimated-downloads badge during this release.

Release · Compare changes

1.1.1 (2026-04-06)

Improvements and fixes

  • Keyword-limit validation now counts characters rather than UTF-8 bytes across shared metadata and localization flows, fixing incorrect rejection of Arabic, Japanese, and other multibyte scripts.
  • Focused screenshot-set upload regression coverage catches failures in the shared asset-upload helper.

Release · Compare changes

1.1.0 (2026-04-06)

New features

  • Screenshot upload can fan out one prepared set across selected localizations, resume from upload artifacts, retry failed work, and validate before a large run.
  • Metadata has a keyword-audit command and direct keyword push, with partial failures reported per locale.
  • Localization workflows discover supported locales, apply them in bulk, document locale forms, and warn when a new localization is incomplete for submission.
  • asc validate includes remediation guidance by default, while asc publish appstore can produce a dry-run plan without requiring the full auth preflight.

Improvements and fixes

  • Equalizations pagination now matches other collection commands and territory updates retry after rate limiting. Territory names containing commas parse correctly in CSV input.
  • Review status explains stale removed submissions and standardizes the not-configured state; new app events default to unscheduled. Auth-status help is easier to discover.
  • Localization keyword validation added byte-aware limits for the release's metadata path; the following 1.1.1 patch corrected this to character counting. Release automation also refreshed the estimated-downloads badge.

Release · Compare changes

1.0.1 (2026-04-04)

Improvements and fixes

  • Generic App Store Connect write failures now include attempted metadata field names, and localization diagnostics retain whitespace-only field context. Failed-delivery verification for IAP and subscription-group review screenshot creation has regression coverage.
  • The estimated-downloads badge is refreshed by the release automation.
  • The installs badge is refreshed.

Release · Compare changes

1.0.0 (2026-04-03)

Improvements and fixes

  • Deprecated commands, aliases, and compatibility wrappers are removed; canonical view and edit surfaces are standardized; and runtime migration messages point publishing, release, submit, age-rating, and build workflows to their replacements.
  • The release adds the dedicated Migrate to 1.0 guide and refreshes command pages and command-surface tests to match the new taxonomy.

Breaking changes

  • Deprecated command paths and aliases are no longer accepted. Follow the replacement shown by the 1.0 migration guide before upgrading automation; command names in this entry reflect the 1.0 release.

Release · Compare changes

0.49.1 (2026-04-02)

New features

  • Adds the app-tags command reference to the documentation.
  • Refreshes the documentation for screenshot plan/apply workflows and adds the release workflow pages.

Improvements and fixes

  • Fixes ASC Studio app-selection races so a stale asynchronous result cannot replace the user's current app selection.
  • Adds regression coverage for stale device-sheet completion and keeps the Mintlify documentation build green.

Breaking changes

  • Renames the project to App Store Connect CLI and the desktop app to ASC Studio; the executable remains asc.

Release · Compare changes

0.49.0 (2026-04-01)

New features

  • Adds ASC Studio, an agentic desktop app backed by the CLI.
  • ASC Studio covers app selection, metadata, pricing, screenshots, reviews, TestFlight, finance, and command tools; its 0.0.1 packaging workflow is prepared.
  • Adds local-build publishing through the App Store Connect API for prepared IPA or PKG artifacts.
  • Splits additive review metadata and screenshot commands into focused operations.
  • Adds stable subscription and IAP selectors based on product and reference values instead of list order.

Improvements and fixes

  • Consolidates App Store publishing guidance around one canonical flow and refreshes the setup guidance.
  • Adds regression coverage for IAP setup's localization context refresh between workflow steps.

Release · Compare changes

March 2026

0.48.1 (2026-03-31)

New features

  • Adds commands to upload and synchronize PPO treatment screenshots and their localizations.

Improvements and fixes

  • Corrects Windows auth-key permission checks so valid key files are accepted without weakening the protection against overly broad permissions.
  • Adds regression coverage for human-readable version/platform display mapping.

Release · Compare changes

0.48.0 (2026-03-30)

New features

  • Makes validate the canonical submission-readiness command for build, metadata, encryption, and review checks.
  • Adds asc pricing current and resolved current-price views for inspecting prices currently in effect.
  • Adds introductory-offer CSV import for repeatable territory pricing setup.
  • Adds experimental web-session medical-device commands and documents experimental web surfaces for agents.

Improvements and fixes

  • Displays readable platform names in table output.
  • Fixes TestFlight tester group filtering and avoids a crash when Game Center list details are empty.
  • Adds regression coverage for medical-device region parsing and review submission pagination/state edges.

Release · Compare changes

0.47.1 (2026-03-29)

New features

  • Shares review-submission lifecycle and reporting across release, publish, submit, and status workflows.
  • Separates help taxonomy from embedded workflows and hardens CI, hooks, and release automation.

Improvements and fixes

  • Restores Mintlify source, fixes root configuration, and removes inconsistent emoji glyphs from docs builds.
  • Adds regression coverage for the terminal FAILED build-wait state and test-notes selector conflicts.
  • Adds the Q2 incremental rewrite roadmap.

Release · Compare changes

0.47.0 (2026-03-27)

Improvements and fixes

  • Makes builds info the canonical build lookup and separates latest lookup from next-number allocation.
  • Standardizes build and TestFlight selectors across app, version, build number, platform, and build ID.
  • Adds --group-level support to subscription updates.
  • Restores deprecated build-selector compatibility while the canonical paths become the documented direction.
  • Corrects a workflow help example and adds regression coverage for the not-expired build-info path.
  • Refreshes the downloads badge.

Breaking changes

  • Migrate scripts to canonical info, next-number, build-scoped notes, and typed selector forms.
  • Deprecated build spellings remain compatible in this release but are no longer preferred.

Release · Compare changes

0.46.2 (2026-03-26)

New features

  • Adds --free to app pricing so a price schedule can explicitly set an app to $0.
  • Adds --all-territories to availability editing for applying the same availability state across every territory.

Improvements and fixes

  • Verifies review-screenshot delivery after upload and reports failed or incomplete review resources.
  • Refreshes the estimated-downloads badge.

Release · Compare changes

0.46.1 (2026-03-25)

New features

  • Adds experimental asc web sandbox create for authenticated creation of App Store sandbox testers.

Improvements and fixes

  • Raises the default web-session rate limit to one second and strengthens the command's experimental-use disclaimer.
  • Requests Apple phone 2FA codes before prompting during web authentication.

Release · Compare changes

0.46.0 (2026-03-25)

New features

  • Adds experimental analytics dashboard commands to the web-session surface.

Improvements and fixes

  • Refreshes the estimated-downloads badge.

Release · Compare changes

0.45.4 (2026-03-24)

New features

  • Adds asc analytics compare for comparing sales metrics across two periods.
  • Adds video-previews set-poster-frame for setting the poster frame of an uploaded preview.

Improvements and fixes

  • Pins Koubou 0.18.1 for reproducible screenshot framing and covers build-count validation edges.
  • Refreshes the release badge.

Release · Compare changes

0.45.3 (2026-03-23)

Improvements and fixes

  • Prefers view and edit verbs on canonical command surfaces, making help and automation vocabulary consistent.
  • Expands subscription metadata diagnostics for missing localization and pricing readiness gaps.
  • Isolates command-test frame and cache state to reduce test interference.
  • Refreshes the estimated-downloads badge in the release automation.
  • Refreshes the release badge.

Release · Compare changes

0.45.2 (2026-03-22)

Improvements and fixes

  • Hardens upload verification and submission hints when processing has not reached a usable state.
  • Adds a public-app privacy readiness advisory to validation.
  • Pins Koubou to 0.18.0 for stable screenshot framing.

Release · Compare changes

0.45.1 (2026-03-21)

Improvements and fixes

  • Adds lazy auto-reauthentication when an expired web session is encountered.
  • Replaces the unreliable web 2FA input with command-based code retrieval, reducing failures in web-session login.
  • Pins Koubou to 0.17.1 and preserves stable screenshot-frame slugs.

Release · Compare changes

0.45.0 (2026-03-21)

New features

  • Adds experimental web-session subscription attachment workflows.
  • Adds beta review submission support to builds add-groups for external TestFlight groups.
  • Uses Apple's modern reviewSubmissions API for submission cancellation.
  • Adds API-backed creation for localizations and pricing availability, plus encryption-exempt declarations.
  • Adds auth-free public App Store commands for inspecting public storefront app data.

Improvements and fixes

  • Adds regression coverage for web subscription refresh reporting.
  • Refreshes the download badge.

Release · Compare changes

0.44.2 (2026-03-20)

New features

  • Adds asc builds count for a concise count of matching builds.
  • Adds builds update support for encryption compliance and a corresponding encryption check to submission preflight.

Improvements and fixes

  • Adds build processing diagnostics to upload failures, distinguishing processing from terminal failure.
  • Fixes TestFlight notification flows, skips redundant internal-group adds, and clarifies partial-notification failures.
  • Preserves config-fallback credentials when switching the default auth profile.
  • Clarifies demo-account-required review guidance.
  • Adds signing git-store path and symlink regression coverage.
  • Adds regression coverage for mutating request-limiter defaults and refreshes release badges.

Release · Compare changes

0.44.1 (2026-03-17)

New features

  • Adds asc xcode validate for checking an IPA before upload.

Improvements and fixes

  • Aborts the web-auth password prompt cleanly on Ctrl+C.
  • Recovers availability boolean parsing and renames pricing verbs to match the canonical command vocabulary.
  • Hardens subscription availability and equalized-pricing flows.
  • Strengthens web-auth fallback and snapshot regression coverage.
  • Refreshes the downloads badge.

Release · Compare changes

0.44.0 (2026-03-16)

New features

  • Adds asc xcode version view, edit, and bump commands for project marketing and build versions.
  • Adds encrypted git-based signing sync for certificates and provisioning profiles.
  • Adds release pre-submit and submit preflight readiness stages before App Review submission.
  • Adds app content-rights view/edit commands and an age-rating --all-none safe-default option.
  • Adds exact-role web-auth capability lookup for accounts whose key role is needed by an operation.

Improvements and fixes

  • Paginates pricing and pre-order territory-availability listings so large territory sets are not truncated.
  • Warns when an App Store export uses a beta Xcode toolchain and waits for direct-upload exports to process.
  • Handles tvOS direct-upload exports that produce a package without an IPA.
  • Hardens review-submission status handling, quiets stale warnings, and adds actionable submission error hints.
  • Adds pagination edge-case coverage for capability lookups and hardens launch onboarding/support documentation.

Release · Compare changes

0.43.0 (2026-03-15)

New features

  • Adds asc auth issuer-id to print the configured App Store Connect issuer ID.
  • Adds a metadata-keywords workflow for inspecting and applying keyword data.
  • Adds asc builds dsyms to download dSYM artifacts for processed builds.

Improvements and fixes

  • Suppresses expected 409 Conflict warnings when cancelling an already-stale submission.
  • Avoids repeated keychain prompts during auth status and profile switching.
  • Adds regression coverage for submit update-state preflight detection.

Release · Compare changes

0.42.0 (2026-03-14)

New features

  • Adds sorting and app lookup support to Xcode Cloud build-runs.
  • Adds --run-id support for Xcode Cloud issues and artifacts tied to a specific build run.
  • Adds experimental private Xcode Cloud workflow-editor commands.
  • Adds custom labels to asc snitch reports.

Improvements and fixes

  • Returns usage errors for invalid Xcode Cloud build-run flags and displays bundle IDs in the products table.
  • Clarifies invalid web-auth credential errors and adds submit-create stale-detach regression coverage.

Release · Compare changes

0.41.4 (2026-03-14)

New features

  • Adds asc auth token to print the signed JWT for the selected auth profile, with the existing auth safeguards.
  • Recovers submit-create when a version is already attached to another submission.
  • Automatically selects the editable app-info resource when an app has more than one.

Improvements and fixes

  • Validates release tags before updating the Homebrew tap.
  • Removes stale subscription-v2 and unused documentation/benchmark artifacts.

Release · Compare changes

0.41.3 (2026-03-13)

New features

  • Adds a --platform filter to builds list and displays marketing version and platform in output.
  • Validates whatsNew during submit-create preflight.

Improvements and fixes

  • Adds regression coverage for app-version state resolution.

Release · Compare changes

0.41.2 (2026-03-13)

New features

  • Adds --app-info to metadata pull for apps with multiple app-info records.
  • Adds --skip-existing and --replace to screenshot uploads, allowing rerunnable synchronization without manual cleanup.

Improvements and fixes

  • Fixes pre-order enable, update, and disable flows.
  • Improves metadata version-state and terms validation.
  • Removes the benchmark comment flow.

Release · Compare changes

0.41.1 (2026-03-13)

Improvements and fixes

  • Simplifies community-app submission metadata so contributors provide the fields the submit command actually needs.

Release · Compare changes

0.41.0 (2026-03-12)

New features

  • Adds an app-availability bootstrap command for setting up storefront availability.

Improvements and fixes

  • Aligns review items add with Apple's documented submission item types, avoiding requests rejected by the submission schema.
  • Allows snitch issue filing when the token cannot manage labels.
  • Excludes territory resources from the availability create included array so the relationship payload matches Apple's schema.
  • Adds regression coverage for review-history pagination edge failures.

Release · Compare changes

0.40.1 (2026-03-12)

New features

  • Adds sandbox environment support to IAP offer-code generation.
  • Adds review submissions-history for inspecting App Review submission history.

Improvements and fixes

  • Validates copyright, URL format, and conditional privacy-policy metadata before submission.

Release · Compare changes

0.40.0 (2026-03-12)

New features

  • Adds local asc xcode archive and asc xcode export helpers with deterministic .xcarchive and .ipa paths.
  • Smooths upload-processing waits in the same workflow.
  • Adds workflow step outputs and resumable recovery so a failed workflow can continue from completed steps.
  • Canonicalizes the IAP pricing command tree.

Improvements and fixes

  • Renames raw linkage commands to links, clarifying their role in the resource relationship surface.
  • Adds pagination and retryable-pricing regression coverage.

Breaking changes

  • The raw linkage naming is replaced by the canonical links surface.
  • Scripts using the old linkage command names should migrate to links.

Release · Compare changes

0.39.1 (2026-03-11)

Improvements and fixes

  • Validates release type and scheduled date in release configuration.
  • Warns when subscription pricing does not cover every requested territory.
  • Moves pre-release versions and beta-app localizations under the canonical TestFlight command taxonomy.

Breaking changes

  • The preferred command home for pre-release versions and beta-app localizations is now testflight; automation should follow the new help taxonomy and its compatibility guidance.

Release · Compare changes

0.39.0 (2026-03-11)

New features

  • Includes IAP review-readiness checks in unified validation.

Improvements and fixes

  • Moves app-info workflows under apps info, completing the app metadata home.
  • Sanitizes BASH_ENV before workflow steps run, preventing inherited shell configuration from changing workflow behavior.
  • Finishes the canonical builds test-notes migration.
  • Synchronizes the OpenAPI snapshot with App Store Connect API 4.3.

Release · Compare changes

0.38.3 (2026-03-10)

New features

  • Adds asc subscriptions pricing equalize for applying a consistent pricing shape across subscription territories.
  • Adds deep MISSING_METADATA diagnostics for missing subscription localization, image, or pricing data.

Release · Compare changes

0.38.2 (2026-03-10)

New features

  • Allows internal groups in builds add-groups, removing an unnecessary TestFlight distribution restriction.

Improvements and fixes

  • Adds regression coverage for community-app submission validation.

Release · Compare changes

0.38.1 (2026-03-10)

New features

  • Replaces the Wall generator with the apps wall submit command.

Release · Compare changes

0.38.0 (2026-03-08)

New features

  • Redesigns TestFlight command discovery around canonical workflows.
  • Adds iap setup and subscriptions setup workflows that create required product, localization, and pricing resources in sequence.
  • Standardizes the [experimental] stability label across command surfaces.

Improvements and fixes

  • Preserves screenshot order after uploads.

Breaking changes

  • Replaces removed legacy subscription paths with V2 families under subscriptions groups, pricing, offers, and review.
  • V2 selectors include --group-id, --subscription-id, --price-point-id, and --availability-id; scripts using removed paths must migrate.

Release · Compare changes

0.37.3 (2026-03-07)

New features

  • Adds bundle-ID and app-name resolution to crashes and status commands.
  • Adds asc snitch for agent-driven friction reporting, with issue-triage guidance in the docs.

Improvements and fixes

  • Includes IDs and resource-type labels when a beta group name is ambiguous.
  • Guards remote webhook binds and symlinked asset paths.
  • Fixes code-scanning workflow permissions and dismisses false-positive crypto alerts.
  • Adds crash-lookup regression coverage and aligns release help, docs, and workflow examples.

Release · Compare changes

0.37.2 (2026-03-06)

New features

  • Adds govulncheck and CodeQL workflows, including expanded custom CodeQL language coverage.
  • Adds terminal progress spinners to web-session commands.
  • Adds phased-release progress output.

Improvements and fixes

  • Improves the expired web-auth session cache UX.
  • Adds validation coverage for retryable and transport-skip subscription-image paths.

Release · Compare changes

0.37.1 (2026-03-06)

Improvements and fixes

  • Warns during validation when subscription promotional images need attention.
  • Prunes repetitive low-signal tests.

Release · Compare changes

0.37.0 (2026-03-05)

New features

  • Adds asc schema for endpoint discovery by path, method/path, or dot notation.
  • JSON results include parameters, allowed values, request attributes, and response schema names; --list, --method, and --pretty support automation.
  • Adds asc release run for a deterministic version, metadata, build-attach, readiness, and review-submission pipeline.
  • Supports dry-run planning, structured step output, confirmation, strict validation, and checkpointed resume.
  • Adds app-scoped build waiting so builds wait can discover a build before polling processing.
  • Adds batch app-info locale updates through --locales or --from-dir.
  • Adds version metadata carry-forward for creating a new version from an existing version's metadata.
  • Adds latest-build processing-state filters and localization shortcuts for build workflows.
  • Adds an install-time notifier for stale cached ASC skills.
  • Extends Xcode Cloud run triggers and adds build-runs lookup.

Improvements and fixes

  • Rejects unsafe characters in API path segments before constructing requests.
  • Fixes stale CLI examples in agent-facing docs.

Release · Compare changes

0.36.3 (2026-03-03)

New features

  • TTY-aware output defaults: interactive terminals default to table, while piped or redirected output defaults to minified json; an explicit --output still wins.
  • Auth status renderers: asc auth status now supports table and JSON output, plus --verbose and --validate for inspecting and checking stored credentials.
  • Latest build selection: asc builds latest resolves the latest processed build and the next build number, with --version, --platform, --next, and --exclude-expired filters.
  • Category subcategories: category updates accept --primary-subcategory-one, --primary-subcategory-two, and matching secondary subcategory flags; asc categories subcategories --category-id ... lists valid IDs.

Improvements and fixes

  • Metadata push resolves ambiguous localization targets more safely and validates app-info locales before updating.
  • CLI usage errors and pagination loops were standardized.

Release · Compare changes

0.36.2 (2026-03-02)

Improvements and fixes

  • Initial subscription pricing now uses PATCH with inline prices, matching Apple's accepted request shape for first-time pricing.
  • App-event purchase requirements are normalized and known Apple 500 responses are guarded, producing a useful CLI result instead of an opaque failure.

Release · Compare changes

0.36.1 (2026-03-02)

New features

  • Xcode Cloud usage alerts and persistence: usage alerts can report quota conditions, and web-session refresh state persists across commands.
  • Xcode Cloud environment variables: asc web xcode-cloud env-vars shared list|set|delete manages shared variables for a product, using the web session.
  • Xcode Cloud workflows: asc web xcode-cloud workflows describe inspects a workflow and the workflow commands can toggle its state.

Improvements and fixes

  • Web auth resolves the cached session by default and removes --password-stdin; account-context errors are clearer, and pricing availability set now requires --available-in-new-territories.
  • Foundation Lab's TestFlight entry was updated.

Release · Compare changes

February 2026

0.36.0 (2026-02-28)

New features

  • Xcode Cloud usage reporting: asc web xcode-cloud usage summary|months|days|workflows reports plan quota and compute-minute usage, with monthly, daily, product, and workflow breakdowns. The commands use Apple's private CI API and a web session.

Improvements and fixes

  • Webhook execution bounds and process lifecycle waits were fixed so local receivers handle event scripts within explicit limits.

Notes

  • Xcode Cloud usage reporting is explicitly experimental, unofficial, and discouraged because it depends on Apple's private CI API.

Release · Compare changes

0.35.3 (2026-02-28)

Improvements and fixes

  • Game Center leaderboard-set members-set now works with empty sets and deduplicates member output across the v1 and v2 updater paths.

Release · Compare changes

0.35.2 (2026-02-27)

New features

  • Tier-based pricing resolution: price-point and schedule workflows accept --tier and --price, letting callers resolve Apple's tier or customer-price value before creating a schedule.

Improvements and fixes

  • The main branch release failure was fixed.

Release · Compare changes

0.35.1 (2026-02-26)

Improvements and fixes

  • Web follow-up requests deduplicate URL redaction and avoid a prompt-timeout regression.
  • Web app creation preflights bundle IDs and accepts UNIVERSAL, preventing a request that cannot succeed because its bundle ID doesn't exist.

Release · Compare changes

0.35.0 (2026-02-26)

New features

  • Price-point selection by customer price: schedule creation can select a price point by customer price instead of requiring a pre-resolved price-point ID.
  • Web App Privacy workflow: asc web privacy catalog|pull|plan|apply|publish provides an agent-oriented workflow for private App Store Connect privacy declarations, including a plan/apply boundary.
  • macOS screenshot capture and framing: screenshot automation can capture macOS app windows and frame them for Mac App Store canvas sizes.

Improvements and fixes

  • Web authentication falls back to an interactive password prompt, and 401 failures include debug diagnostics without exposing the password.

Notes

  • The web privacy and authentication command groups use Apple's private web surfaces and are experimental/unofficial; the public API doesn't expose App Privacy declarations.

Release · Compare changes

0.34.1 (2026-02-26)

Improvements and fixes

  • Keychain authentication still works when the original .p8 file has been removed, allowing stored key material to be used for review-detail and app-creation flows.

Release · Compare changes

0.34.0 (2026-02-25)

New features

  • Web review context: asc web review can list and show App Review submissions, resolution-center threads, messages, rejections, and attachments. show can download available screenshots and attachments to an output directory while redacting returned URLs.
  • Detached web auth and app creation: experimental Apple web-session authentication and app-creation commands moved under the detached web command group, separating private-web workflows from public API commands.

Improvements and fixes

  • Web review validates submission states, prevents attachment filename path traversal, and removes the dead allowLast parameter. Upload timeout hints and defaults were improved.
  • Generated Wall spacing and snippet maintenance were updated.

Release · Compare changes

0.33.2 (2026-02-25)

Improvements and fixes

  • The issue audit shipped the high-value CLI changes identified in that review.

Release · Compare changes

0.33.1 (2026-02-24)

New features

  • Family Sharing: IAP and subscription create/update commands now expose --family-sharable, wiring Apple's family-sharing field into the CLI.
  • TestFlight agent workflows were improved across builds, notes, groups, and sync, with clearer command paths for automated use.

Improvements and fixes

  • README guidance was reorganized around onboarding.

Release · Compare changes

0.33.0 (2026-02-23)

New features

  • Pre-submission checks: asc submit validate runs submission readiness checks before creating a review submission.
  • Direct localization updates: asc localizations update updates app-info or version localization fields by locale, without preparing a metadata directory.
  • Price-point filters: price-point list commands accept exact, minimum, and maximum customer-price filters.
  • Screenshot sizing now focuses default dimensions on iOS submission slots and includes newer iPhone 67/69 dimensions; asc screenshots exposes the expanded dimension data.

Improvements and fixes

  • Stale review submissions are cancelled before a new one is created, and app-privacy API errors now include a hint for the web workflow because those declarations aren't available through the public API.
  • Builds latest filtering, localization update formatting, and low-sample benchmark parsing were corrected.
  • The release workflow trigger and agent documentation were refreshed.

Release · Compare changes

0.32.0 (2026-02-22)

New features

  • Slack release payloads: notifications can include thread_ts and release-payload attachments, allowing release messages to remain in a Slack thread with structured metadata.
  • Custom product-page media: product-page workflows can upload and synchronize custom product-page media.
  • Performance tooling: hot paths and pagination were optimized, and benchmark CI was added to track changes in command performance.

Improvements and fixes

  • Asset helpers and localization ID handling were consolidated; Slack message text duplication and custom-page code issues were fixed. README onboarding now includes GitLab CI components and a clearer first-run structure.

Release · Compare changes

0.31.3 (2026-02-21)

New features

  • asc localizations screenshot-sets delete deletes a screenshot set by ID with the CLI's destructive-operation guard.
  • Added iPad Pro 13-inch (M5) screenshot dimensions to local validation. Release · Compare changes

0.31.2 (2026-02-21)

New features

  • Metadata workflows: asc metadata pull, asc metadata push, and the asc migrate metadata aliases use the same metadata directory layout as asc migrate, with consistent locale and file resolution.

Improvements and fixes

  • Metadata push now handles locale paths, default-locale casing, unused writers, file cleanup, validation, and app-info/version localization selection consistently.

Release · Compare changes

0.31.1 (2026-02-20)

New features

  • Screenshot and video-preview CDN downloads retry transient failures and send a curl-like user agent, improving reliability for automated asset pulls.

Improvements and fixes

  • Asset download errors now retain useful context.
  • The status dashboard labels a release “Needs Attention” only when a real blocker exists.

Release · Compare changes

0.31.0 (2026-02-20)

New features

  • Account status: asc account status reports account-level state, optionally scoped with --app, in JSON, table, or Markdown output.
  • Weekly insights: asc insights weekly --app "APP_ID" --source analytics|sales --week "YYYY-MM-DD" compares the selected week with the previous week; the sales source includes linked IAPs and subscriptions by matching the app SKU.
  • Subscription price import: asc subscriptions prices import --id "SUB_ID" --input "./prices.csv" imports territory prices, with --dry-run, --start-date, and preservation controls for scheduled pricing.

Improvements and fixes

  • Wall generation now sorts generated app entries alphabetically.

Release · Compare changes

0.30.0 (2026-02-20)

New features

  • Release status dashboard: asc status --app "APP_ID" aggregates builds, TestFlight, App Store, submission, review, phased-release, and link signals into one deterministic payload; --include selects sections and --output table renders it for review.
  • Local webhook receiver: asc webhooks serve --port 8787 --dir ./webhook-events accepts webhook events, persists payloads, and can execute a script for each event with --exec.
  • Localization diff: a deterministic diff command compares local metadata with App Store Connect data, making pending changes visible before a push.
  • Embedded list/show guides were added to asc documentation, and TestFlight beta-tester CSV compatibility was standardized.

Improvements and fixes

  • Webhook serving rejects positional arguments and removes dead body-size code.
  • Listener and process handling now wait for webhook processes correctly.
  • Status uses positional beta-build matching only when one build and one detail make that fallback unambiguous.
  • Date comparisons, diff UTF-8 truncation, and duplicate localization validation were corrected.

Release · Compare changes

0.29.3 (2026-02-19)

New features

  • TestFlight beta groups support internal groups on create and list. asc testflight beta-groups list --app "APP_ID" --internal filters app groups, and --global --internal queries internal groups across apps. create --internal creates an internal group.

Improvements and fixes

  • A bad Homebrew tap token no longer fails the rest of the release workflow.

Release · Compare changes

0.29.2 (2026-02-19)

Improvements and fixes

  • Install help now points users to the repository's skills.

Release · Compare changes

0.29.1 (2026-02-19)

Breaking changes

  • Startup update checks and self-update behavior were removed. Homebrew installations now follow Homebrew's update model, so users update with brew upgrade.

Improvements and fixes

  • Documentation now consistently calls the tool asc and explains its unofficial status.

Release · Compare changes

0.29.0 (2026-02-18)

New features

  • Relationship endpoints: added the missing relationship list, get, and mutation routes across apps, bundle IDs, Game Center, builds/TestFlight, metadata, subscriptions, IAP, pricing, and Xcode Cloud. This makes related resources reachable without raw API calls.
  • Workflow execution: the workflow command gained enterprise hardening for JSON runs, including safer handling of command output and process results.

Improvements and fixes

  • Relationship request validation now rejects empty mutation arrays and aligns bundle, app, and Game Center relationships with the production API contract.

Release · Compare changes

0.28.14 (2026-02-18)

Improvements and fixes

  • asc migrate import skips non-locale metadata directories such as review-information folders instead of treating them as localizations. macOS path comparison coverage was corrected around the fix.

Release · Compare changes

0.28.13 (2026-02-17)

New features

  • Added a setup GitHub Action for repository automation.
  • Added a daily analytics snapshot workflow.

Improvements and fixes

  • CI now enables misspell, unparam, and errorlint in phases so lint findings can be addressed incrementally.

Release · Compare changes

0.28.12 (2026-02-17)

New features

  • Generated release notes: release notes can be generated from git history, with output suitable for text and Markdown consumers.

Improvements and fixes

  • Release-note text and Markdown output no longer duplicate content, and --max-chars 0 is handled correctly. Error strings were normalized for staticcheck, and the lint issue limit was restored for CI.

Release · Compare changes

0.28.11 (2026-02-17)

New features

  • Paginated commands show a GitHub-style spinner on stderr while pages are fetched, keeping progress visible without contaminating stdout data. Release · Compare changes

0.28.10 (2026-02-16)

Improvements and fixes

  • Added Mixtape app details to wall-of-apps.json.
  • Removed stale ASC.md so generated agent guidance cannot use obsolete repository instructions.

Release · Compare changes

0.28.9 (2026-02-16)

New features

  • Local provisioning-profile management: asc profiles local adds local install, list, and clean workflows; profiles can also be downloaded from App Store Connect.
  • Certificate requests: asc certificates csr generate creates a certificate signing request from the CLI.
  • Screenshot plans accept JSONC comments, which keeps annotated automation plans valid.

Improvements and fixes

  • Profile and certificate file writes were hardened against path traversal, orphaned key files, unsafe permissions, and local edge cases. The local profile commands also fixed their reported edge cases, and force-overwrite paths apply an explicit restrictive umask.

Release · Compare changes

0.28.8 (2026-02-16)

New features

  • TestFlight CSV exchange: beta testers can be exported to and imported from CSV, with standardized validation and compatibility handling for automation.
  • Media downloads: screenshots and video previews can be downloaded from their CDN URLs, with shared asset download helpers and transient-failure handling.

Improvements and fixes

  • TestFlight summaries now report accurate values, and asset downloads handle context errors more cleanly.

Release · Compare changes

0.28.7 (2026-02-16)

Improvements and fixes

  • Submission readiness checks now cover empty build data, category values, and screenshot requirements.

Release · Compare changes

0.28.6 (2026-02-15)

Improvements and fixes

  • Corrected whatsNew validation for version 1.0 releases, where the initial release has different metadata requirements.

Release · Compare changes

0.28.4 (2026-02-15)

Improvements and fixes

  • Wall generation was repaired after the Dandelion entry exposed duplicate WallEntry definitions and a generation issue.

Release · Compare changes

0.28.3 (2026-02-14)

Improvements and fixes

  • Stale update checks run asynchronously, reducing startup work for commands that don't need update information.

Release · Compare changes

0.28.2 (2026-02-14)

Improvements and fixes

  • Koubou is pinned to v0.13.0 for repeatable local screenshot framing.
  • The CLI checks the installed version before asc screenshots frame and watch generation.
  • Missing or mismatched kou versions return a clear error.
  • Documentation includes pip install koubou==0.13.0.

Notes

  • Local screenshot automation remains experimental; callers should pin the tool version with the CLI.

Release · Compare changes

0.28.1 (2026-02-14)

Notes

  • Local screenshot commands are explicitly marked experimental: asc screenshots run, capture, frame, and list-frame-devices.
  • Review commands review-generate, review-open, and review-approve are also experimental and may change.

Release · Compare changes

0.28.0 (2026-02-14)

New features

  • Local screenshot workflow: asc screenshots adds capture, framing, device listing, review generation, review opening, and approval commands. Koubou provides deterministic framing for generated App Store screenshots; the local workflow remained experimental.
  • Top-level asc screenshots and asc video-previews commands are wired into the command tree, with media-asset wording and root help updated accordingly.

Improvements and fixes

  • Uploads now use the configured upload timeout, including asset file uploads.
  • Auth output redacts environment identifiers; ASC_STRICT_AUTH accepts explicit yes/no values and warns on unsupported values, while ASC_BYPASS_KEYCHAIN handles an empty setting consistently. Keychain migration cleanup and credential removal were tightened for test isolation.
  • IPA, profile, and other file paths reject symlink escapes across Unix and non-Unix platforms. Submit cancellation routes to the review-submission ID, and exit-code behavior is consistent across commands.
  • Release binaries are stripped with -s -w, dead command wrappers were removed, and async/await support was added to the internal App Store Connect client.

Release · Compare changes

0.27.0 (2026-02-11)

New features

  • Pre-submission validation: asc validate now checks the App Store version, app metadata, localizations, screenshots, and age-rating declaration, emits a structured report, and returns a reported error when blocking issues exist.
  • Metadata migration: asc migrate import handles the complete metadata layout, including app-info and version localizations, while asc init can refresh ASC.md guidance.
  • Screenshot and build checks: validation checks screenshot dimensions and presence; build latest/next-number selection was corrected for the current release state.

Improvements and fixes

  • Shared validation, metadata helpers, migration screenshot logic, and age-rating error messages were consolidated so the new checks report consistent failures.

Release · Compare changes

0.26.4 (2026-02-11)

Improvements and fixes

  • API errors now surface Apple's associatedErrors details alongside the primary error, making nested validation failures visible to callers.

Release · Compare changes

0.26.3 (2026-02-11)

New features

  • Added asc apps wall and generated community-app metadata, with contribution flow and platform handling for community app entries.
  • asc auth doctor reports migration hints, including array-shaped hints when more than one action is needed.
  • Subscription price-point equalizations accept --paginate for complete result sets.

Improvements and fixes

  • The project moved to Go 1.26.

Release · Compare changes

0.26.2 (2026-02-10)

New features

  • IAP offer-code generation: offer-code creation now has the pricing and eligibility inputs needed to generate codes for in-app purchases.
  • Game Center mutations: Game Center resource groups gained the mutating endpoints needed to create or update resources, and the enabled-version pointer is handled on GameCenterAppVersion.
  • Bundle ID capability updates: bundle ID capability records can be updated through the CLI.
  • List commands were brought to endpoint parity, including consistent app-ID flag validation.

Release · Compare changes

0.26.1 (2026-02-10)

New features

  • Age-rating declarations are fully handled by the metadata and submission paths, and initial releases can carry whatsNew correctly.
  • Added the repository Hall of Fame.

Improvements and fixes

  • Output cleanup was deferred through the command lifecycle, and update/reporting paths were hardened while zero-coverage packages were removed.

Release · Compare changes

0.26.0 (2026-02-09)

New features

  • CI and test reporting: commands can return meaningful CI exit codes and write JUnit reports with the new report flag, giving pipeline runners a machine-readable test result.

Improvements and fixes

  • The release history includes a revert and follow-up around the CI/report implementation; consult the release notes when pinning behavior for a pipeline.

Release · Compare changes

0.25.4 (2026-02-08)

Improvements and fixes

  • Markdown output now uses tablewriter's renderer, keeping table and Markdown formatting on the same output path.
  • PrintTable and PrintMarkdown type switches were replaced with an output registry, so renderers are registered by output type rather than maintained in a central switch.
  • The install script was aligned with versioned release asset names; table rows were also left-aligned for terminal readability. These maintenance changes are covered by this release.

Release · Compare changes

0.25.3 (2026-02-08)

New features

  • Notification payloads can now include Slack Block Kit content, allowing structured Slack messages from CLI workflows.
  • ASC_DEFAULT_OUTPUT sets the default renderer for scripts and shells that don't pass --output.

Improvements and fixes

  • Replaced the tabwriter table path with tablewriter so bordered table output is consistent across commands. Shared wrapper re-exports and pre-stat file checks were removed as part of the cleanup.

Release · Compare changes

0.25.1 (2026-02-07)

New features

  • Consolidated IAP pricing: asc iap prices --app "APP_ID" or --iap-id "IAP_ID" summarizes current price, proceeds, base territory, and scheduled changes; --territory narrows app-level results.
  • Subscription price-point queries and pricing support were expanded, including territory-aware lookup and pagination paths.

Improvements and fixes

  • asc migrate import now omits locale from metadata PATCH payloads and selects the draft or PREPARE_FOR_SUBMISSION App Info record instead of relying on an arbitrary record. Follow-up hardening keeps that selector consistent.
  • The release also cleared the lint backlog in batches and added the canonical repository URL to the README and agent guidance.

Release · Compare changes

0.25.0 (2026-02-06)

New features

  • macOS notarization adds asc notarization submit --file <path> for .zip, .dmg, and .pkg files.
  • Uploads use SHA-256 handling and Apple's Notary API v2.
  • --wait polls to completion; --poll-interval and --timeout control the wait.
  • status, log, and list inspect existing submissions.

Improvements and fixes

  • Notarization wait status reports progress, timeout, and failure guidance, including the command to retrieve the developer log.

Release · Compare changes

0.24.3 (2026-02-06)

Improvements and fixes

  • Release assets were renamed to follow GitHub CLI naming conventions, keeping downloaded artifact names consistent with the release tooling.

Release · Compare changes

0.24.2 (2026-02-05)

New features

  • asc publish can resolve a TestFlight beta group by its name or ID, so publishing workflows can accept the identifier operators already have.

Improvements and fixes

  • Corrected a false “ambiguous group” result and fixed a nil-pointer panic in pagination.

Release · Compare changes

0.24.1 (2026-02-03)

New features

  • TestFlight gained the missing command endpoints from the release audit, including the corresponding command wiring.
  • Certificate activation can be toggled from the CLI.
  • Analytics report requests can be deleted.

Improvements and fixes

  • Added CLI-level coverage for the TestFlight commands and corrected their help indentation.
  • The README now positions asc as a scriptable IDE/terminal CLI.

Release · Compare changes

0.24.0 (2026-02-02)

New features

  • Game Center enabled-version queries: asc game-center enabled-versions list --app "APP_ID" lists enabled versions, and compatible-versions --id "ENABLED_VERSION_ID" lists versions compatible with a multiplayer matchmaking configuration.
  • asc testflight metrics beta-tester-usages --app "APP_ID" fetches beta tester usage metrics.
  • --period selects a supported reporting window; --group-by betaTesters and --filter-tester "TESTER_ID" scope the result.
  • asc testflight beta-crash-logs get --id "CRASH_LOG_ID" fetches an individual crash log.
  • IAP and subscription pricing lookups: IAP offer-code prices and price-schedule base territories can be read directly, and one-time subscription offer-code access is split into explicit list and get commands.
  • ID-scoped pricing and media-set queries: pricing schedule and availability can be fetched by --id, and preview or screenshot sets can be fetched by set ID instead of first resolving the parent localization.

Improvements and fixes

  • Enabled-version commands no longer perform redundant output validation.

Release · Compare changes

0.23.5 (2026-02-02)

New features

  • Subscription grace-period support adds the subscription configuration data needed to represent Apple's grace-period settings.

Release · Compare changes

0.23.4 (2026-02-02)

New features

  • app-setup info set accepts a content-rights declaration, so setup can configure the same declaration exposed by apps update.

  • Startup update checks notify users when a newer CLI release is available.

Improvements and fixes

  • Destructive removal commands now require explicit confirmation before deleting resources.

  • Self-update downloads now identify the client with a User-Agent and close temporary files on error paths, improving compatibility and cleanup.

Release · Compare changes

0.23.3 (2026-02-01)

New features

  • builds upload accepts --pkg for macOS installer packages.

  • app-infos list discovers app-info IDs needed by metadata and declaration workflows.

  • review submissions-cancel cancels draft review submissions.

  • apps update accepts a content-rights declaration.

Improvements and fixes

  • builds list reports usesNonExemptEncryption as required, exempt, or not applicable, making encryption status visible without inspecting raw API data.

Release · Compare changes

0.23.2 (2026-02-01)

New features

  • App Clip image get commands retrieve metadata and URLs for existing App Clip image resources.

Release · Compare changes

0.23.1 (2026-02-01)

Improvements and fixes

  • Development tooling adds a safe format/lint fallback when optional tools are unavailable.

Release · Compare changes

January 2026

0.23.0 (2026-01-31)

New features

  • --debug and ASC_DEBUG enable HTTP tracing for diagnosing requests and responses.

  • TestFlight build relationships, beta feedback, and beta-recruitment criteria filters expose more of Apple's beta-testing data.

  • App-info category, encryption-declaration, and territory age-rating relationships are available for app metadata workflows.

  • Game Center parity expands app versions and details, v1 relationships/metrics/images, and v2 achievements, leaderboards, and leaderboard sets.

  • App Clips and App Store version relationships, plus customer reviews, are exposed through the CLI.

  • Relationships for IAPs, subscriptions, pricing, offer codes, bundle IDs, agreements, CI products, background assets, and visible apps cover common commerce and distribution lookups.

Improvements and fixes

  • Next-page parsing for bundle IDs and Game Center details now follows the API's pagination links reliably.

  • Pricing schedule and availability IDs receive stricter validation before requests are sent.

  • Background-asset output and debug logging were refactored for clearer, safer output; HTTP flags are split so tracing options do not accidentally alter request behavior.

Release · Compare changes

0.22.1 (2026-01-31)

New features

  • TestFlight beta-license agreement and notification resources can be managed from the CLI.

  • Game Center submission endpoints are available for submission-related workflows.

  • Customer-review summarizations can be retrieved.

Release · Compare changes

0.22.0 (2026-01-31)

New features

  • Subscription sub-resources and in-app-purchase sub-resources expand resource-level management beyond the parent records.

  • Offer-code commands and per-territory pricing commands support localized commerce configuration.

  • Build/TestFlight operations gain sandbox parity, covering the same build relationships in the sandbox API surface.

  • Screenshot validation recognizes Apple's 6.9-inch iPhone display type.

Improvements and fixes

  • Subscription offer-code price payloads are sent using the corrected relationship shape.

  • Game Center activity handling tolerates a missing activity version instead of failing while decoding the response.

Release · Compare changes

0.21.0 (2026-01-30)

New features

  • App metadata keyword relationships can be listed and managed.

  • Analytics resources can be fetched directly by ID as well as through relationship listings.

  • Xcode Cloud SCM endpoints expose source-control connections and related resources.

  • Game Center coverage adds challenges, activities, groups, and matchmaking resources.

Improvements and fixes

  • Analytics relationship IDs are validated as UUIDs before API calls.

Release · Compare changes

0.20.2 (2026-01-30)

New features

  • Webhook delivery relationships and pagination are available for inspecting delivery records.

  • notify slack sends CLI notifications through a Slack webhook.

  • Review submission and review-item resources can be queried.

  • In-app event localizations and media relationships are exposed.

  • Account signing relationships and user-visible-app relationships are supported.

  • Product-page localization keywords and media sets can be listed with pagination.

  • App Clip domain status relationships are available.

Improvements and fixes

  • Slack webhook handling is hardened, relationships pagination is validated, and next-page links now extract IDs correctly for user-visible apps.

  • App Clip domain support received follow-up cleanup alongside the relationship addition.

Release · Compare changes

0.20.1 (2026-01-30)

Improvements and fixes

  • The release improves command-line usability; the release record does not describe the individual interaction changes further.

Release · Compare changes

0.20.0 (2026-01-30)

New features

  • Webhook commands manage webhook configurations.

  • App Clip commands cover App Clip resources and their API relationships.

  • Product-page commands manage product-page resources.

  • In-app-event commands manage in-app-event resources.

Improvements and fixes

  • Client pagination handles additional typeOf cases, JSON output preserves intentional zero values, and client experiments validate IDs before use.

Release · Compare changes

0.19.3 (2026-01-29)

New features

  • Marketplace search detail requests can select supported fields, reducing responses to the data callers need.

Release · Compare changes

0.19.2 (2026-01-29)

New features

  • Alternative-distribution package resources can be inspected and managed through the CLI.

Improvements and fixes

  • Alternative-distribution output and client code were cleaned up for the new surface.

Release · Compare changes

0.19.1 (2026-01-29)

New features

  • Background-asset commands list and manage paginated background-asset resources.

Release · Compare changes

0.19.0 (2026-01-29)

New features

  • Android-to-iOS mapping commands expose mappings used to connect Android and iOS apps.

  • Win-back offer commands support subscription win-back configuration.

  • reviews ratings reports App Store rating statistics.

  • Marketplace, merchant-ID, promoted-purchase, and pass-type-ID resources are available through dedicated CLI commands.

Improvements and fixes

  • Sandbox tester create/delete commands were removed because they are not supported by the current API surface.

  • Review output handles formatting more consistently, finance output preserves zero paid-month values, and pagination handles additional typeOf casing.

  • Authentication/configuration and dependencies were refreshed and hardened.

Breaking changes

  • Scripts that call the removed sandbox tester create/delete commands must migrate to the operations still supported by App Store Connect.

Release · Compare changes

0.18.2 (2026-01-29)

New features

  • install skills installs the ASC workflow skills pack used for release, TestFlight, metadata, and related workflows.

Improvements and fixes

  • Keychain defaults and config defaults are reconciled consistently, including when keychain credentials are present.

  • Keychain bypass validation is consistent, tests isolate authentication config, and unused type definitions are removed.

Release · Compare changes

0.18.1 (2026-01-29)

Improvements and fixes

  • auth status merges keychain and configuration values before reporting credential status.

Release · Compare changes

0.18.0 (2026-01-29)

New features

  • Game Center commands cover achievements, leaderboards, leaderboard sets, and their supported localizations.

  • auth status --validate validates stored credentials over the network and reports failures.

Improvements and fixes

  • Commands were reorganized by domain, making related command groups easier to discover and maintain.

  • Pagination, error handling, and temporary key cleanup were hardened; authentication values are handled strictly.

  • Game Center request and response types were aligned with the OpenAPI contract, and leaderboard-set localization names are validated.

  • Repository-local agent skills were removed as the project moved workflow skills to the maintained external pack.

Release · Compare changes

0.17.0 (2026-01-28)

New features

  • Build-bundle commands expose the bundles associated with uploaded builds.

  • Pre-order commands manage pre-order availability and pricing.

  • Nominations commands expose nomination resources and their paginated collections.

  • App encryption declaration commands manage export-compliance declarations.

  • App asset commands manage App Store assets, and app-setup can run post-create automation.

  • Xcode Cloud artifacts, test results, issues, expanded workflow coverage, and routing coverage can be queried.

  • Performance metrics and diagnostics, actors list/get commands, and apps get/update commands are available.

Improvements and fixes

  • Pre-order availability and Xcode Cloud list logic were corrected, duplicate list flags were consolidated, and performance output/download handling was improved.

  • Command logic and pagination types were consolidated for more consistent behavior.

  • App-setup command issues were corrected as the setup workflow expanded.

Release · Compare changes

0.16.0 (2026-01-27)

New features

  • EULA commands manage app-level end-user license agreements.

  • Accessibility declaration commands manage accessibility information for app versions.

  • App tags, App Store version promotions, and version release requests are supported.

  • Review-submission commands cover App Store review submission operations, using one unified review command surface.

Improvements and fixes

  • EULA app-ID resolution and accessibility helper reuse were corrected, and tests use stable typed assertions rather than matching error strings.

Release · Compare changes

0.15.0 (2026-01-27)

New features

  • IAP and subscription commands cover the core product, group, and pricing operations.

  • The repository includes an offline OpenAPI snapshot and endpoint-index tooling, allowing endpoint and schema work without relying on a live documentation page.

Improvements and fixes

  • Subscription creation uses the API's group relationship name, and unused IAP/client code was removed or validated.

Release · Compare changes

0.14.0 (2026-01-26)

New features

  • Bundle ID capabilities can be listed and configured.

  • Signing files can be fetched for local signing workflows.

Improvements and fixes

  • Signing profile and certificate handling, filename sanitization fallbacks, and tvOS in-house distribution inference were corrected.

  • Agents.md references the maintained workflow skills and their progressive-disclosure guidance.

Release · Compare changes

0.13.0 (2026-01-26)

New features

  • Auth profiles can be switched explicitly, allowing separate App Store Connect credentials to be selected for different projects or teams.

  • Offer-code resources are available through dedicated CLI commands.

  • Age-rating declarations can be configured from the CLI.

Improvements and fixes

  • Credential names are normalized, resolution errors are clearer, profile mismatches are detected, and listing/default selection agree across flags and storage.

Release · Compare changes

0.12.4 (2026-01-26)

New features

  • Authentication can read a private key from environment variables for headless CI use.

  • App-info metadata commands manage metadata fields through the app-info resource.

Improvements and fixes

  • App Store version output includes the version date.

Release · Compare changes

0.12.3 (2026-01-26)

New features

  • auth init --open opens the authentication setup flow for interactive setup.

Improvements and fixes

  • The README gains a table of contents for faster navigation.

Release · Compare changes

0.12.2 (2026-01-26)

New features

  • builds expire-all expires multiple builds in one operation.

  • Device management commands cover registered App Store Connect devices.

Improvements and fixes

  • Upload-client transport assertions and audit fixes improve request safety and make regressions easier to catch.

Release · Compare changes

0.12.1 (2026-01-25)

New features

  • TestFlight beta-build localizations support “What to Test” notes.

Improvements and fixes

  • Build uploads wait longer for processing, reducing premature timeout failures.

  • Pagination handles the API's additional typeOf values.

Release · Compare changes

0.12.0 (2026-01-25)

New features

  • Categories can be listed and set.

  • App Store versions can be created, updated, and deleted.

  • Xcode Cloud action commands expose workflow actions.

  • Users and invitations can be managed from the CLI.

  • TestFlight beta distribution commands support tester and build rollout operations.

Improvements and fixes

  • App Store submission now uses the reviewSubmissions API correctly.

Release · Compare changes

0.11.0 (2026-01-25)

New features

  • The publish workflow connects build, upload, version, and submission stages into one end-to-end command flow.

  • Auth config initialization supports selecting credential storage.

  • The repository provides the ASC workflow skills pack for release and operational tasks.

Improvements and fixes

  • Empty config values no longer become phantom credentials during authentication.

Release · Compare changes

0.10.2 (2026-01-24)

New features

  • App pricing and availability commands configure price schedules and territory availability.

Improvements and fixes

  • Pricing schedule output formatters and client cleanup make the new pricing surface consistent with other commands.

Release · Compare changes

0.10.1 (2026-01-24)

Improvements and fixes

  • Maintenance release updates the README footer attribution; the release metadata lists no behavior change.

Release · Compare changes

0.10.0 (2026-01-24)

New features

  • builds latest finds the latest build with platform filtering; version filters enforce the platform limit.

  • Build upload supports the full upload flow, including processing and checksum handling.

  • Customer reviews can receive responses.

  • App Store version phased-release management is available, with dedicated output formatting.

Improvements and fixes

  • Upload channel deadlocks and unused retry options were removed, and build upload handles empty checksums safely.

  • Finance report type mappings are documented and validated, beta-group boolean updates are handled correctly, and review star ratings are validated.

  • Large command files were split and localization downloads were improved for maintainability and more reliable retrieval.

  • Contributor guidance was reorganized around progressive disclosure for agent-assisted repository work.

Release · Compare changes

0.9.0 (2026-01-24)

New features

  • Finance report commands retrieve App Store Connect financial reports, with JSON fields matching the API response.

Improvements and fixes

  • Credentials use the default keychain and legacy entries are migrated, reducing setup differences between existing and new installations.

Release · Compare changes

0.8.1 (2026-01-24)

Improvements and fixes

  • Improves IPA plist parsing and makes upload retry behavior more observable.

Release · Compare changes

0.8.0 (2026-01-23)

New features

  • Beta groups and testers can be managed, including tester details, group relationships, and build-to-group relationships.

  • TestFlight apps and pre-release versions can be listed and inspected.

  • Build localizations and TestFlight YAML configuration support distribution workflows.

Improvements and fixes

  • TestFlight command registration and generated documentation were refreshed to match the expanded command surface.

Release · Compare changes

0.7.0 (2026-01-23)

Improvements and fixes

  • Security and beta-group handling were hardened.

  • Delete command output includes the message ID returned by the operation.

Release · Compare changes

0.6.0 (2026-01-23)

New features

  • Xcode Cloud commands trigger workflows and monitor their processing status from the CLI.

Release · Compare changes

0.5.0 (2026-01-21)

New features

  • --paginate follows collection next links and aggregates every supported page into one result.

Release · Compare changes

0.3.1 (2026-01-21)

Improvements and fixes

  • Sandbox tester password validation trims accidental leading and trailing whitespace before checking the value.

Release · Compare changes

0.3.0 (2026-01-21)

New features

  • Sandbox tester commands create, list, inspect, update, and delete supported App Store Connect sandbox accounts.

Release · Compare changes

0.2.0 (2026-01-21)

New features

  • Beta groups and testers can be created, listed, updated, and removed, with dedicated output handlers.

  • Localization commands manage localized App Store content.

  • Submission workflows and version commands provide the initial release-preparation path.

  • Analytics and sales-reporting commands retrieve App Store Connect business data.

Improvements and fixes

  • Missing submission lookups are handled explicitly instead of producing an unusable result.

  • Homebrew tap automation and installation instructions were updated.

Release · Compare changes

0.1.6 (2026-01-20)

New features

  • Feedback commands retrieve screenshots attached to App Store Connect feedback submissions.

Release · Compare changes

0.1.5 (2026-01-20)

Improvements and fixes

  • Maintenance release that updates release automation to commit Homebrew tap changes using the personal Git identity. The release metadata lists no user-facing CLI behavior change.

Release · Compare changes

0.1.4 (2026-01-20)

Improvements and fixes

  • Credential resolution checks the system keychain before environment variables when both provide values.

Breaking changes

  • Environments that intentionally relied on an environment variable overriding an existing keychain value must remove or update the keychain entry.

Release · Compare changes

0.1.3 (2026-01-20)

Improvements and fixes

  • Improves help output styling and removes duplicate usage text.

Release · Compare changes

0.1.2 (2026-01-20)

New features

  • macOS release binaries are code-signed, and the release workflow imports the Apple Developer ID certificate needed for signing.

Release · Compare changes

0.1.0 (2026-01-20)

New features

  • The core CLI foundation provides App Store Connect API access with keychain authentication.

  • Output supports minified JSON for automation alongside human-readable formats.

  • Pagination and filters establish the initial collection-query behavior, while build commands cover build information and expiration.

  • Build upload and submission planning, checksum verification, and the local bin installation path provide the first release workflow.

Improvements and fixes

  • Release tags use the 0.x.y naming convention without a leading v.

Release · Compare changes