Skip to content

docs(store): the path to TestFlight and the App Store measured against current rules; #137 PR B and PR C paused - #238

Merged
tornidomaroc-web merged 2 commits into
mainfrom
docs/store-path-decision
Oct 7, 2026
Merged

tornidomaroc-web merged 2 commits into
mainfrom
docs/store-path-decision

Conversation

@tornidomaroc-web

@tornidomaroc-web tornidomaroc-web commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Analysis and decisions only. Nothing is built and nothing in production changes.

Files: docs/store/STORE_PATH.md (new) and one Section 7 block in docs/PROGRESS.md (10 additions, 0 deletions, directly below the preamble). No row is edited; rows 42, 69 and 81 untouched.

What it records

  • docs(#74): the row closes on its real remedy, the notice arc gets #79, and a subject check joins §5 #137 PR B and PR C paused on the owner's ruling of 2026-10-07, with the reason, and why they stay resumable without a new audit. The agent agrees with the pause and gives the evidence.
  • The distance to a TestFlight build on the owner's iPhone (about four sessions) and to the first App Store submission (about ten), item by item, with what each requires and who does it.
  • Apple and Google rules read from the official pages on 2026-10-07 and cited by section: 4.2, 2.5.2, 4.8, 5.1.1(v), 5.1.2(i), 3.1.1, 3.1.3(a)(b)(f), 2.1(a), App Privacy, TestFlight, the Xcode 26 requirement, GitHub runner billing, Codemagic pricing, Play's closed-testing rule, target API 36 and payments policy.

Decisions it asks the owner to sign

New finding with no row: guideline 5.1.2(i) requires explicit in-app permission before content goes to third-party AI; nothing in the app asks today.


Amended 2026-10-07 (head 323b5ac): STORE_PATH.md gains §8, "Lessons from Scan & Action", read only through the GitHub API, and each correction is marked in place. Corrections: Google sign-in through the native plugin Scan & Action proved (#258); its two-job TestFlight workflow copied with a project-integrity check added; EU trader status is required even outside the EU (Apple's page, quoted); Android after the iOS submission; 3 sessions to TestFlight, about 9 to submission. Live-site shell kept, with a first-build check that the Capacitor bridge reaches tryknowflow.com (Capacitor's docs say server.url is not intended for production; weighed in §8.3). A second Section 7 block records it (12 additions, 0 deletions). Reported, not fixed: a live risk in Scan & Action's signing job (§8.5).

🤖 Generated with Claude Code

…n measured against Apple's and Google's current rules; #137 PR B and PR C paused on the owner's ruling, registered and resumable

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
knowflow Ready Ready Preview Oct 7, 2026 8:22am UTC

@fixor-security

fixor-security Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

🛡️ Fixor Security Report

Repository: tornidomaroc-web/knowflow · PR: #238
Commit: 323b5ac1cc642d219934f9ae8d03b17dc5af8e45

⏸️ Fixor scan paused - budget reached

This installation has hit its $0.00 monthly cap (spent $0.00 this month).
This installation's cap is $0, so scans stay paused until the cap is raised.
To raise the cap, contact the Fixor operator. The current cap is shown on your dashboard's billing page.

🔒 Analyzed by Fixor · 2026-10-07T08:21:44.481Z

… job and native sign-in copied, trader status required outside the EU, Android after the iOS submission, live-site shell kept with a first-build bridge check

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@tornidomaroc-web
tornidomaroc-web merged commit 399106e into main Oct 7, 2026
8 checks passed
@tornidomaroc-web
tornidomaroc-web deleted the docs/store-path-decision branch October 7, 2026 08:36

This branch was successfully deployed

1 active deployment
Preview — 323b5ac1 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant