Files
opencode-mobile/.github/workflows/ios-ci.yml
Den d6e24e9f99 fix(compliance): disclose email collection in Play Data Safety + align privacy docs (#146)
* fix(compliance): disclose email collection in Play Data Safety + align privacy docs (closes #143)

Google Play rejected cc.agentlabs.opencode (2026-07-22) because the Data
Safety declaration did not disclose collection of Email Address. Root
cause: the optional "OpenCode Connect" waitlist card on the Connect
screen (app/connection/add.tsx -> src/lib/waitlist.ts) collects an email
and forwards it to Brevo (email marketing/CRM) via the beta-signup
backend.

Audited all other PII surfaces and confirmed no other undisclosed
collection: Chatwoot support reports stay anonymous (no email/name),
Sentry strips URLs/tokens and sends no default PII, and PostHog
analytics uses only a random anonymous ID with coarse event properties.

Updates:
- distribution/play-listing.md: Data Safety table now declares
  Personal info / Email address (collected, shared with Brevo,
  optional, purpose account management); embedded privacy-policy draft
  and app description updated to match.
- distribution/privacy-policy.md/.html + docs/privacy/index.html: new
  section 3c discloses the waitlist email collection, third-party
  services list adds Brevo, retention/rights sections and the Apple
  Privacy Nutrition Label table updated accordingly.
- docs/playstore.md: checklist entry documents the rejection and points
  to the fix.
- PUBLISHING.md: adds exact Play Console resubmission steps (Data
  types -> Personal info -> Email address -> collected/shared/purpose)
  plus a note on the earlier unrelated "Missing sign-in details" App
  access blocker in case it resurfaces.

No app code changed; npm test (209 pass) and tsc --noEmit are clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(ci): run required checks on docs-only PRs (unblock branch protection)

ios-ci.yml (which emits the required 'Typecheck and unit tests' check) had
paths-ignore for docs/**, docs-site/**, distribution/**, **/*.md. A required
status check that is path-filtered never runs on docs-only PRs, so those PRs
sit permanently in mergeStateStatus=BLOCKED (missing required check). Remove the
paths-ignore so required checks always run.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: test <test@test.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 15:01:48 -07:00

133 lines
4.4 KiB
YAML

# iOS build gate for pull requests and main.
#
# Requires NO Apple/EAS secrets: it validates the Expo config, exports the iOS JS
# bundle, generates the native project, installs CocoaPods, and compiles an
# UNSIGNED iPhone Simulator target with xcodebuild. Signing/TestFlight lives in
# publish-app-store.yml.
#
# Cheap platform-neutral checks (typecheck + unit tests) run first on Linux and
# gate the costly macOS native build.
name: iOS CI
# NOTE: no paths-ignore here. "Typecheck and unit tests" is a REQUIRED status
# check in branch protection; a path-filtered required check never runs on
# docs-only PRs, leaving them permanently BLOCKED. Running the cheap Linux
# typecheck/test job (and the gated macOS build) on every PR keeps the required
# check satisfiable. See #143 (docs PR stuck) for why.
on:
pull_request:
branches: [main]
push:
branches: [main]
# Cancel superseded runs for the same ref (e.g. new push to an open PR).
concurrency:
group: ios-ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
test:
name: Typecheck and unit tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-node@v6
with:
# Node >= 23.6 runs the TypeScript test files natively (type-stripping),
# matching the local toolchain. No build step or extra deps required.
node-version: 24
cache: npm
- name: Install dependencies (deterministic)
run: npm ci --legacy-peer-deps
- name: Typecheck
run: npm run typecheck
- name: Unit tests
run: npm test
ios-build:
name: Unsigned iOS Simulator build
needs: test
# macos-15 ships Xcode 16.x, which React Native 0.81 / Expo SDK 54 require.
runs-on: macos-15
timeout-minutes: 45
env:
# No source-map upload from CI (no Sentry auth token here); keep the build hermetic.
SENTRY_DISABLE_AUTO_UPLOAD: "true"
steps:
- uses: actions/checkout@v6
- uses: actions/setup-node@v6
with:
node-version: 20
cache: npm
- name: Install dependencies (deterministic)
run: npm ci --legacy-peer-deps
- name: Validate Expo config and plugin resolution
run: npx expo config --type introspect --json > expo-config.introspect.json
- name: Export iOS JavaScript bundle
run: npx expo export --platform ios --output-dir dist
- name: Prebuild native iOS project
run: npx expo prebuild --platform ios --no-install
- name: Install CocoaPods dependencies
working-directory: ios
run: pod install
- name: Resolve Xcode workspace and scheme
id: xc
run: |
set -euo pipefail
shopt -s nullglob
workspaces=(ios/*.xcworkspace)
workspace="${workspaces[0]:-}"
if [ -z "$workspace" ]; then
echo "::error::No .xcworkspace was generated by expo prebuild."
exit 1
fi
scheme=$(xcodebuild -workspace "$workspace" -list -json | node -e "
const d = JSON.parse(require('fs').readFileSync(0, 'utf8'));
const all = (d.workspace && d.workspace.schemes) || [];
const app = all.filter((s) => s !== 'Pods' && !s.startsWith('Pods-'));
if (app.length === 0) { console.error('No application scheme found in workspace'); process.exit(1); }
process.stdout.write(app[0]);
")
echo "workspace=$workspace" >> "$GITHUB_OUTPUT"
echo "scheme=$scheme" >> "$GITHUB_OUTPUT"
echo "Using workspace='$workspace' scheme='$scheme'"
- name: Build unsigned iPhone Simulator app
run: |
set -euo pipefail
NSUnbufferedIO=YES xcodebuild \
-workspace "${{ steps.xc.outputs.workspace }}" \
-scheme "${{ steps.xc.outputs.scheme }}" \
-configuration Debug \
-sdk iphonesimulator \
-destination 'generic/platform=iOS Simulator' \
-derivedDataPath ios/build \
CODE_SIGNING_ALLOWED=NO \
CODE_SIGNING_REQUIRED=NO \
CODE_SIGN_IDENTITY="" \
build 2>&1 | tee xcodebuild.log
- name: Upload xcodebuild log
if: always()
uses: actions/upload-artifact@v7
with:
name: ios-xcodebuild-log
path: xcodebuild.log
retention-days: 14
if-no-files-found: ignore