Sample report on an invented project (FieldCrew) — this is what you get for a real app.

Release readiness audit — fieldcrew

Stack: Expo ~53.0.9 · React Native 0.79.2 · TypeScript · tests: 0 · lockfile: yarn.lock

iOS bundle id: com.example.fieldcrew · Android package: com.example.fieldcrew

3 blocking · 10 to fix · 3 notes. This audit reads the project files only; nothing was installed or run.

AreaFindingFix
🔴StackExpo SDK 53 is 4 versions behind the current SDK 57. Store builds now need recent Xcode/iOS SDK and Android target API levels; old SDKs usually cannot meet them.Upgrade SDK step by step (53→57), fix breaking changes, retest.
🔴Security.env is in the project and .gitignore does not exclude .env files.Remove it from the repository, rotate the keys, add .env* to .gitignore.
🔴SecurityPossible Stripe live secret key in src/billing/config.ts.Move it to the server or EAS secrets and rotate it — anything in the app bundle can be read by anyone.
🟡ConfigiOS bundle identifier "com.example.fieldcrew" looks like a placeholder.Choose the final id before the first store upload — it cannot be changed later.
🟡ConfigAndroid package "com.example.fieldcrew" looks like a placeholder.Choose the final id before the first store upload — it cannot be changed later.
🟡BuildNo eas.json: cloud builds are not set up.Add EAS build profiles (development / preview / production).
🟡App StoreIcon is 512×512; the store needs 1024×1024.Export the icon at 1024×1024.
🟡App StoreIcon PNG has an alpha channel; App Store icons must not be transparent.Flatten the icon onto a solid background.
🟡Google PlayNo Android adaptive icon.Add adaptiveIcon foreground + background colour.
🟡App StoreExport compliance (encryption) is not declared, so App Store Connect asks on every upload.Set ios.config.usesNonExemptEncryption (usually false for HTTPS-only apps).
🟡App Storeexpo-camera is used but the iOS permission text is not set (NSCameraUsageDescription); generic default texts are a common rejection reason (guideline 5.1.1).Write a specific purpose string for each permission.
🟡App Storeexpo-location is used but the iOS permission text is not set (NSLocationWhenInUseUsageDescription); generic default texts are a common rejection reason (guideline 5.1.1).Write a specific purpose string for each permission.
🟡Securityapp config "extra" has supabaseServiceKey — values in extra ship inside the app.Keep only public values there.
⚪BuildInstall script postinstall: "patch-package" (common tool).
⚪App StoreNo app-level privacy manifest declared (Expo adds manifests for its own modules).Declare data collection / required-reason APIs if the app or its SDKs use them.
⚪QualityNo automated tests found.Add tests for the key logic before changes.

Estimated work to a store-ready build: about 21 h (fixes above + EAS setup and first builds). Store accounts (Apple Developer, Google Play) and publishing stay on the owner's accounts.

Plan, step by step

  1. Remove keys and secrets from the code and repository and rotate them (before anything else).
  2. Upgrade Expo SDK and dependencies, fix breaking changes, run the app.
  3. Fix the 🟡 items: permission texts, icons, encryption, build settings.
  4. Set up EAS cloud builds and make test builds for iOS and Android.
  5. Testing on your devices: TestFlight (iOS) and internal testing (Google Play).
  6. Submission to App Store and Google Play review from your accounts; answering reviewer notes.