What rorkai/App-Store-Connect-CLI shipped
Written by FoxPlug from public releases; not affiliated with Asccli. An automatic summary of the public release, pull request and commit data of github.com/rorkai/App-Store-Connect-CLI. Asccli did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Version 5.7.0 released with raw authenticated request passthrough, dSYM download selection and waiting, global read-only mode, and value indirection for environment variables and files. Release
- Signing sync adds lifecycle operations: profile deletion, certificate revocation, device refresh, and Mac inclusion via
asc signing sync nuke. Pull request #2777 - Signing sync now supports S3-compatible object storage as a backend alongside Git for storing encrypted signing artifacts. Pull request #2778
- Screenshots framing expands to iPad, Apple Watch, and Apple TV devices with per-device colors, text overlays, and resumable batch processing. Pull request #2776
- OpenAPI schema updated to version 4.5 with new endpoints for performance overviews, game-center blocking and score moderation, subscription organization markets, and Korean age ratings. Pull request #2761
- Device registration gains
--via-urlto serve a loopback page for collecting remote device identifiers from iOS devices. Pull request #2698 - Resource ID flags across 399 flag declarations now accept App Store Connect self-links in addition to bare IDs. Pull request #2591
- Web service domain updates for Sign in with Apple now function instead of rejecting every update attempt. Pull request #2705
- Offline metadata inspection added with
asc ipa-infoandasc pkg-infofor local IPA and flat package artifacts. Pull request #2680 - Migration includes App Clip and preview files in the canonical layout during import, export, and validation. Pull request #2704
Why it matters
Version 5.7.0 consolidates months of work on signing infrastructure, screenshots, and API expansion. Object storage for signing, device registration over HTTPS, and new OpenAPI 4.5 endpoints for game-center, subscriptions, and performance data mean the tool handles larger teams and modern app features. Self-link support simplifies piping between commands.
Changelog entry
- feat(api): raw authenticated request passthrough Release
- feat(builds): select and wait for dSYM downloads Release
- feat(cli): global read-only mode (ASC_READ_ONLY / --read-only) Release
- feat(cli): @env: and @file: value indirection for string flags Release
- feat(signing): add sync nuke, profile renewal, device refresh, and Mac inclusion Pull request #2777
- feat(signing): add object storage backend for signing sync Pull request #2778
- feat(screenshots): add iPad, watch, and TV frames with colors, text, and batches on Koubou 0.20.0 Pull request #2776
- feat(cli): accept self-links on the remaining resource ID flags Pull request #2591
- docs(openapi): update schema to 4.5 Pull request #2761
- feat(performance): read API 4.5 performance overviews Pull request #2763
- feat(subscriptions): support organization markets and multi-seat settings Pull request #2764
- feat(game-center): add leaderboard score moderation Pull request #2765
- feat(game-center): add blocked player management Pull request #2766
- feat(age-rating): support API 4.5 Korea ratings and GRAC numbers Pull request #2762
- feat(devices): collect remote UDIDs from a registration URL Pull request #2698
- feat(cli): inspect local IPA and flat package artifacts Pull request #2680
- feat(screenshots): add deterministic frame overlays and resume Pull request #2734
- feat(migrate): keep App Clip and preview files in the canonical layout Pull request #2704
- feat(artifacts): report signer identity in ipa-info and pkg-info Pull request #2769
- fix(devices): single-use --via-url callback tokens and streamed arrival receipts Pull request #2770
asccli 5.7.0: raw API passthrough, dSYM waits, signing nuke, object storage, S3 backends, iPad/Watch/TV frames, self-link IDs, read-only mode, and @env/@file indirection.
asccli 5.7.0 ships: signing sync with lifecycle operations (nuke, revoke, refresh), S3-compatible object storage backends, device registration via HTTPS, screenshots on iPad/Watch/TV with text overlays, OpenAPI 4.5 support (game-center, subscriptions, performance), raw API passthrough, self-link resource IDs, and global read-only mode for safer automation.
Week of September 14, 2026
What shipped
- Release 5.4.0 shipped with web session defaults, environment variable fallbacks for Apple ID, and documentation for web login. Release
- Apps can now configure App Store Server Notification endpoints directly in asc apps update with subscription status URL flags. Pull request #2716
- Custom product page creation now fetches the app primary locale and sends Apple's required compound payload with initial version and localization. Pull request #2724
- Review submission creation errors are now handled by preserving validated IDs when responses contain both success and top-level errors. Pull request #2714
- Build and pre-release pagination used by --since selection is now capped at 1000 pages to prevent unbounded requests. Pull request #2710
- Session credentials are now protected during attachment redirects by sending the authentication cookie exactly once on the initial request. Pull request #2665
- App-scoped build-upload 404s no longer retry indefinitely; the parent app is verified once to distinguish permanent from transient failures. Pull request #2664
- Review submission creation now fails closed when discovery or pagination is uncertain instead of silently creating new submissions. Pull request #2662
- Beta group assignments are now preflight-checked to stop before POST if builds are processing, expired, or blocked by export compliance. Pull request #2658
- Ambiguity diagnostics are now bounded and the tool fails closed on incomplete pagination instead of choosing from partial selector responses. Pull request #2639
Why it matters
This week focused on hardening session handling, validation, and pagination across the CLI. Multiple fixes prevent silent failures when App Store Connect returns incomplete data or errors, ensuring the tool fails closed and provides clear diagnostics. Security improvements protect credentials during redirects and reject symlinked cache files.
Changelog entry
- release: 5.4.0 with web session defaults and environment variable fallbacks Release
- feat: configure App Store Server Notification endpoints via asc apps update Pull request #2716
- fix: create custom product pages with required compound payload and initial version Pull request #2724
- fix: preserve validated review submission IDs when create responses contain errors Pull request #2714
- fix: cap build pagination at 1000 pages in --since selection Pull request #2710
- fix: protect session credentials during attachment redirects Pull request #2665
- fix: verify parent app before retrying app-scoped build-upload 404s Pull request #2664
- fix: fail closed before creating review submissions on uncertain state Pull request #2662
- fix: preflight beta group assignments to check build readiness Pull request #2658
- fix: fail closed on incomplete pagination instead of mutating from partial responses Pull request #2639
asc 5.4.0 ships with App Store Server Notification configuration, stricter validation on review submissions and beta assignments, bounded pagination, and hardened session security.
asc 5.4.0 is out. This release hardens validation across the board: review submissions now fail closed instead of silently creating duplicates, pagination is bounded to prevent runaway requests, session credentials are protected during redirects, and beta group assignments are preflight-checked. More than 30 fixes address security, reliability, and correctness in the CLI's interaction with App Store Connect APIs.