Skip to content
Back to skills

Eas Update Rollout

ASecurity

Use EAS Update to ship JS-only OTA updates with channels and rollouts. Use when the user says 'EAS Update', 'OTA update', 'over the air', 'rollout percentage'.

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 4, 2026
developmentgobashreact

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned October 4, 2026

npx -y skills add khadinakbarlabs/expo-mobile-app-builder --skill eas-update-rollout --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Eas Update Rollout?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Eas Update Rollout
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/khadinakbarlabs-eas-update-rollout/badge)](https://www.skillsdirectory.com/skills/khadinakbarlabs-eas-update-rollout)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "eas-update-rollout"
description: "Use EAS Update to ship JS-only OTA updates with channels and rollouts. Use when the user says 'EAS Update', 'OTA update', 'over the air', 'rollout percentage'."
---

# EAS Update Rollout

OTA push for JS, assets, styles without store re-submission. Native code can NOT be OTA'd.

## External action gate

Preparing an update is safe; publishing one changes a live product. Before any `eas update`, `eas update:edit`, or rollback command, confirm the EAS account, project, channel, runtime version, rollout percentage, monitoring owner, and rollback update group with the owner. Never infer production approval from a request to draft a release plan.

## What can / cannot OTA
**OTA OK:** screens, business logic, copy, styles, assets, react-native libs with no native code, dependency updates within same major.

**Requires new binary:** new native module, native dep upgrade, Expo SDK bump, app.json key affecting native (permissions, plugins, entitlements, bundle ID, Info.plist), new platform target.

## Runtime versioning (use fingerprint)
app.json:
```json
{
  "expo": {
    "runtimeVersion": { "policy": "fingerprint" }
  }
}
```

`fingerprint` hashes everything that can affect native runtime — config plugins, native modules, app.json keys. Hash bumps automatically on native change. JS-only changes don't bump it. Eliminates the entire class of "OTA crashed because native is out of sync" bugs.

## Publish update after confirmation
```bash
# Start at 10%
eas update --channel production --message "Fix onboarding crash" --rollout-percentage 10

# After 2h of clean Sentry, ramp
eas update:edit --rollout-percentage 50
eas update:edit --rollout-percentage 100
```

## Rollback after confirmation
Republish previous good update:
```bash
eas update:republish --group <previous-update-group-id>
```

Note: native changes can't roll back via EAS Update — must ship new binary.

## Apple's OTA rules (3.3.2)
OTA may not change app's primary purpose or add features the reviewed binary couldn't have done. **Bug fixes, perf, copy, A/B tests, feature flags = fine. Adding a new permission prompt or pivoting product = not fine, build a new binary.**

## Pricing
EAS Update usage and pricing can change. Check the current Expo pricing page before approving a release that could incur charges.

## Reference
`references/02-eas-pipeline.md`

Files in this skill

  • SKILL.md2.3 KB
  • agents/openai.yaml185 B
  • references/02-eas-pipeline.md1.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…