Skip to content

fastlane

v2.237.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

android apps automation deployment fastlane ios
+3 more
mobile ruby screenshots

Affected surfaces

deps

Summary

AI summary

Broad release touches @iBotPeaches, @PratikPatil131, @OdNairy, and @sawirricardo.

Full changelog
  • [ci] drop CircleCI for GHA (#30108) via Connor Tumbleson (@iBotPeaches)
  • [fastlane_core] Restore altool -f flag, keep -assetFile only for iTMSTransporter (#30106) via Roman Gardukevich (@OdNairy)
  • [gym] handle xcpretty errors cleaner & promote xcbeautify (#30099) via Connor Tumbleson (@iBotPeaches)
  • [docs] Reflect specification changes regarding iPad Pro 12.9-inch screenshots in deliver (#30103) via 417-72KI (@417-72KI)
  • [core] Reduce duplication on output and noise during failure. (#30097) via Connor Tumbleson (@iBotPeaches)
  • Bump actions/checkout from 6 to 7 (#30100) via dependabot[bot] (@dependabot[bot])
  • [match] Restore renew expired certs (opt in) (#30096) via Roman Gardukevich (@OdNairy)
  • [match] fail fast for SSH authentication prompts in non-interactive shell (#30078) via Pratik Patil (@PratikPatil131)
  • [gem] move to faraday 1.10.6 (#30095) via Connor Tumbleson (@iBotPeaches)
  • [core] Skip repeating the output again when an sh command fails (#19545) via Peter Tutervai (@tutipeti)
  • [scan] Forward force_legacy_xcresulttool to trainer (#30092) via Eyüp Can Akman (@eyupcanakman)
  • [trainer] Fix output_remove_retry_attempts not stripping failures for skipped-on-retry tests (modern xcresult parser) (#30081) via Oliver Fox (@foxware00)
  • [scan] Handle array destination in xcodebuild_destination_parameter (#30069) via Ricardo Sawir (@sawirricardo)
  • [action][swiftlint] Fix path option for SwiftLint 0.48.0 and above (#30080) via Augusto Xavier (@augustocbx)
  • [ci] move more workflows from CircleCI -> GHA (#30090) via Connor Tumbleson (@iBotPeaches)
  • [core] remove upper bound on excon (#30085) via Connor Tumbleson (@iBotPeaches)
  • Bump actions/checkout from 6 to 7 (#30091) via dependabot[bot] (@dependabot[bot])
  • [spaceship] Fix appInfoLocalizations create/delete on the Tunes API (#30084) via Marcel Hoppe (@hoppsen)
  • [match] Fix keychain import path escaping (#30072) via Ricardo Sawir (@sawirricardo)
  • [precheck] Fix copyright year check to allow past years (#30076) via Augusto Xavier (@augustocbx)
  • [supply] Fix version_codes_to_retain causing promote-only flow to use… (#30073) via Pratik Patil (@PratikPatil131)
  • Bump rubygems/configure-rubygems-credentials from 2.0.0 to 2.1.0 (#30074) via dependabot[bot] (@dependabot[bot])
  • [fastlane_core] Fix deprecated Transporter -f flag, use -assetFile fo… (#30061) via Pratik Patil (@PratikPatil131)
  • [core] fix: update addressable to 2.9.0 min for CVE-2026-35611 (#30060) via OrbisAI Security (@orbisai0security)

Security Fixes

  • CVE-2026-35611 — addressable upgraded to minimum version 2.9.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track fastlane

Get notified when new releases ship.

Sign up free

About fastlane

All releases →

Related context

Earlier breaking changes

  • v2.235.0 Drops Ruby 2.7; requires Ruby 3.0 minimum.

Beta — feedback welcome: [email protected]