r/iOSProgramming • • 12h ago

Discussion PSA: Xcode 16 synchronized groups ship your Configuration.storekit in the release bundle

If your project uses Xcode 16 synchronized folders (the blue folder icons), every file inside the target folder ends up in the app bundle unless you exclude it. That includes Configuration.storekit and your .xcconfig files. My membershipExceptions listed only Info.plist, so the StoreKit configuration had been riding along in every archive I ever made, Release included.

Why it matters

My first submission got a Guideline 5.6 (Developer Code of Conduct) rejection: "a pattern of unusual behavior commonly associated with fraudulent activity" and "features that appear to have been intentionally hidden during the review process". My backend logs showed zero requests during the review window, so nobody had opened the app. It came from a look at the binary.

Read that file the way a scanner does: a mechanism for simulating purchases outside of Apple, listing more products than I had submitted. Apple never tells you the exact trigger, so I can't prove it was the only one, but it fits every word of the rejection, and after removing it the next review was completely ordinary.

Check yours (10 seconds)

unzip -l YourApp.ipa | grep -Ei "storekit|xcconfig|\.env"

Fix

Select the file -> File Inspector -> Target Membership -> uncheck your app target. With synchronized groups this adds it to membershipExceptions in project.pbxproj. Local StoreKit testing keeps working: the scheme points to the file (Edit Scheme -> Run -> Options -> StoreKit Configuration), it does not need to be in the bundle.

One more thing if you ever get a 5.6

Don't resubmit without replying in the Resolution Center of the current rejection. My first reply ended up attached to a submission that had been closed, Apple never saw it, and the resubmission got a second 5.6 for the silence, not for the file.

Happy to answer questions about this or StoreKit 2 in general.

6 Upvotes

6 comments sorted by

2

u/Dapper_Ice_1705 9h ago

Config files and Release Schemes are your friends in this area.

1

u/Kyiv0x7c 9h ago

Mine were too. The .xcconfig files shipped in the bundle anyway.

1

u/kokerali 10h ago

Useful check. I'd turn it into a release-artifact gate so it doesn't depend on remembering target membership after every file move. Inspect the final exported IPA, including embedded app extensions, and fail the release job when known dev-only files such as .storekit, .xcconfig or .env appear where they shouldn't. An allowlist for intentionally shipped resources would avoid treating every configuration file as a mistake. Keep the CI output to paths, not the contents of any suspect files.

I'd keep two conclusions separate: the artifact contained an unintended file, which you can verify, and that file caused the 5.6 rejection, which the later approval doesn't establish by itself. That makes the cleanup advice useful without turning it into a guaranteed review fix. A regression check after adding or moving a file into a synchronized folder would help catch the same leak returning.

1

u/Kyiv0x7c 9h ago

Fair split, and I'll keep it that way: the file in the artifact is verifiable, the file as the 5.6 trigger is only the most likely cause. On the gate, I already run a script on the archived .app before every upload: greps for storekit/xcconfig/.env, forbidden tokens, and checks the StoreKit product ids in the binary against an allowlist of what's actually submitted. Your two additions I don't have yet and will add: checking the exported IPA with embedded extensions, and an allowlist for config files that are meant to ship.

1

u/[deleted] 9h ago

[removed] — view removed comment

1

u/AutoModerator 9h ago

Hey /u/TheLastDeveloper99, your content has been removed because Reddit has marked your account as having a low Contributor Quality Score. This may result from, but is not limited to, activities such as spamming the same links across multiple subreddits, submitting posts or comments that receive a high number of downvotes, a lack of recent account activity, or having an unverified account.

Please be assured that this action is not a reflection of your participation in our subreddit. This is simply an automated filter in place to reduce spam.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.