Lesson 23 / 25
Building and Releasing
EAS Build, signing, stores and OTA updates.
Builds, signing and submission
Store apps must be signed: iOS needs an Apple Developer account, a distribution certificate and provisioning profile; Android needs an upload keystore, and Play App Signing manages the final app signing key. EAS Build builds iOS and Android binaries in the cloud (or locally with --local) using build profiles in eas.json such as development, preview and production, and can generate and store credentials for you. EAS Submit uploads builds to App Store Connect (TestFlight) and Google Play. Increase version numbers for each store release; EAS can auto-increment build numbers. Both stores review apps, so allow time and follow their policies on privacy disclosures and permissions.
OTA updates and their limits
EAS Update ships new JavaScript bundles and assets to installed apps without a store release, which is ideal for quick fixes. Updates are grouped by channel (for example production) and only apply to builds with a compatible runtime version. They cannot change native code: adding a native library, changing permissions or upgrading the SDK needs a new store build. Store rules still apply, so OTA updates must not change the app's core purpose; Apple's guidelines restrict downloading code that changes app features significantly. Use staged rollouts and keep the ability to roll back. By default the app checks for an update on launch and applies it on a later start; check the docs for your version.
Build, submit and update
EAS CLI commands; check the docs for your version.
# one-time setup
npm install -g eas-cli
eas login
eas build:configure # creates eas.json with build profiles
# store builds (credentials can be managed by EAS)
eas build --platform ios --profile production
eas build --platform android --profile production
# upload to App Store Connect / Google Play
eas submit --platform ios
eas submit --platform android
# ship a JS-only fix to installed production builds
eas update --channel production --message "Fix checkout total rounding"Protect your signing keys
Losing an Android upload key or leaking credentials is painful. Let EAS or a secrets manager hold them, and never commit keystores to git.
Quick check: Which change can be shipped with an OTA update?
- A JavaScript bug fix that does not change native code
- Adding a new native camera library
- Requesting a new iOS permission
- Upgrading to a new Expo SDK with native changes
Answer
A JavaScript bug fix that does not change native code — OTA updates replace JS and assets only.