Sample report on an invented project (FieldCrew) — this is what you get for a real app.
Release readiness audit — fieldcrew
Stack: Expo ~53.0.9 · React Native 0.79.2 · TypeScript · tests: 0 · lockfile: yarn.lock
iOS bundle id: com.example.fieldcrew · Android package: com.example.fieldcrew
3 blocking · 10 to fix · 3 notes. This audit reads the project files only; nothing was installed or run.
| Area | Finding | Fix | |
|---|---|---|---|
| 🔴 | Stack | Expo SDK 53 is 4 versions behind the current SDK 57. Store builds now need recent Xcode/iOS SDK and Android target API levels; old SDKs usually cannot meet them. | Upgrade SDK step by step (53→57), fix breaking changes, retest. |
| 🔴 | Security | .env is in the project and .gitignore does not exclude .env files. | Remove it from the repository, rotate the keys, add .env* to .gitignore. |
| 🔴 | Security | Possible Stripe live secret key in src/billing/config.ts. | Move it to the server or EAS secrets and rotate it — anything in the app bundle can be read by anyone. |
| 🟡 | Config | iOS bundle identifier "com.example.fieldcrew" looks like a placeholder. | Choose the final id before the first store upload — it cannot be changed later. |
| 🟡 | Config | Android package "com.example.fieldcrew" looks like a placeholder. | Choose the final id before the first store upload — it cannot be changed later. |
| 🟡 | Build | No eas.json: cloud builds are not set up. | Add EAS build profiles (development / preview / production). |
| 🟡 | App Store | Icon is 512×512; the store needs 1024×1024. | Export the icon at 1024×1024. |
| 🟡 | App Store | Icon PNG has an alpha channel; App Store icons must not be transparent. | Flatten the icon onto a solid background. |
| 🟡 | Google Play | No Android adaptive icon. | Add adaptiveIcon foreground + background colour. |
| 🟡 | App Store | Export compliance (encryption) is not declared, so App Store Connect asks on every upload. | Set ios.config.usesNonExemptEncryption (usually false for HTTPS-only apps). |
| 🟡 | App Store | expo-camera is used but the iOS permission text is not set (NSCameraUsageDescription); generic default texts are a common rejection reason (guideline 5.1.1). | Write a specific purpose string for each permission. |
| 🟡 | App Store | expo-location is used but the iOS permission text is not set (NSLocationWhenInUseUsageDescription); generic default texts are a common rejection reason (guideline 5.1.1). | Write a specific purpose string for each permission. |
| 🟡 | Security | app config "extra" has supabaseServiceKey — values in extra ship inside the app. | Keep only public values there. |
| ⚪ | Build | Install script postinstall: "patch-package" (common tool). | |
| ⚪ | App Store | No app-level privacy manifest declared (Expo adds manifests for its own modules). | Declare data collection / required-reason APIs if the app or its SDKs use them. |
| ⚪ | Quality | No automated tests found. | Add tests for the key logic before changes. |
Estimated work to a store-ready build: about 21 h (fixes above + EAS setup and first builds). Store accounts (Apple Developer, Google Play) and publishing stay on the owner's accounts.
Plan, step by step
- Remove keys and secrets from the code and repository and rotate them (before anything else).
- Upgrade Expo SDK and dependencies, fix breaking changes, run the app.
- Fix the 🟡 items: permission texts, icons, encryption, build settings.
- Set up EAS cloud builds and make test builds for iOS and Android.
- Testing on your devices: TestFlight (iOS) and internal testing (Google Play).
- Submission to App Store and Google Play review from your accounts; answering reviewer notes.