This release includes 1 security fix for security teams reviewing exposed deployments.
Published 21d
Developer Productivity
✓ No known CVEs patched
This release patches 1 known CVE
Topics
android
apps
automation
deployment
fastlane
ios
+3 more
mobile
ruby
screenshots
Affected surfaces
deps
Summary
AI summaryBroad release touches @iBotPeaches, @PratikPatil131, @OdNairy, and @sawirricardo.
Full changelog
- [ci] drop CircleCI for GHA (#30108) via Connor Tumbleson (@iBotPeaches)
- [fastlane_core] Restore altool -f flag, keep -assetFile only for iTMSTransporter (#30106) via Roman Gardukevich (@OdNairy)
- [gym] handle xcpretty errors cleaner & promote xcbeautify (#30099) via Connor Tumbleson (@iBotPeaches)
- [docs] Reflect specification changes regarding iPad Pro 12.9-inch screenshots in
deliver(#30103) via 417-72KI (@417-72KI) - [core] Reduce duplication on output and noise during failure. (#30097) via Connor Tumbleson (@iBotPeaches)
- Bump actions/checkout from 6 to 7 (#30100) via dependabot[bot] (@dependabot[bot])
- [match] Restore renew expired certs (opt in) (#30096) via Roman Gardukevich (@OdNairy)
- [match] fail fast for SSH authentication prompts in non-interactive shell (#30078) via Pratik Patil (@PratikPatil131)
- [gem] move to faraday 1.10.6 (#30095) via Connor Tumbleson (@iBotPeaches)
- [core] Skip repeating the output again when an sh command fails (#19545) via Peter Tutervai (@tutipeti)
- [scan] Forward force_legacy_xcresulttool to trainer (#30092) via Eyüp Can Akman (@eyupcanakman)
- [trainer] Fix output_remove_retry_attempts not stripping failures for skipped-on-retry tests (modern xcresult parser) (#30081) via Oliver Fox (@foxware00)
- [scan] Handle array destination in xcodebuild_destination_parameter (#30069) via Ricardo Sawir (@sawirricardo)
- [action][swiftlint] Fix path option for SwiftLint 0.48.0 and above (#30080) via Augusto Xavier (@augustocbx)
- [ci] move more workflows from CircleCI -> GHA (#30090) via Connor Tumbleson (@iBotPeaches)
- [core] remove upper bound on excon (#30085) via Connor Tumbleson (@iBotPeaches)
- Bump actions/checkout from 6 to 7 (#30091) via dependabot[bot] (@dependabot[bot])
- [spaceship] Fix appInfoLocalizations create/delete on the Tunes API (#30084) via Marcel Hoppe (@hoppsen)
- [match] Fix keychain import path escaping (#30072) via Ricardo Sawir (@sawirricardo)
- [precheck] Fix copyright year check to allow past years (#30076) via Augusto Xavier (@augustocbx)
- [supply] Fix version_codes_to_retain causing promote-only flow to use… (#30073) via Pratik Patil (@PratikPatil131)
- Bump rubygems/configure-rubygems-credentials from 2.0.0 to 2.1.0 (#30074) via dependabot[bot] (@dependabot[bot])
- [fastlane_core] Fix deprecated Transporter -f flag, use -assetFile fo… (#30061) via Pratik Patil (@PratikPatil131)
- [core] fix: update addressable to 2.9.0 min for CVE-2026-35611 (#30060) via OrbisAI Security (@orbisai0security)
Security Fixes
- CVE-2026-35611 — addressable upgraded to minimum version 2.9.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About fastlane
All releases →Related context
Related tools
Earlier breaking changes
- v2.235.0 Drops Ruby 2.7; requires Ruby 3.0 minimum.
Beta — feedback welcome: [email protected]