mix mob.release (mob_dev v0.7.17)

Copy Markdown View Source

Builds a release-signed artifact ready to upload to the app store.

mix mob.release                     # iOS .ipa (default)
mix mob.release --ios               # iOS .ipa (explicit)
mix mob.release --android           # Android .aab
mix mob.release --security-gate     # run mix mob.security_scan first;
                                    # abort the release on any
                                    # critical/high/medium finding

--security-gate

Runs the full security scan against the project (every layer: Hex/Gradle/Swift dep CVEs, bundled-runtime drift, C/Kotlin/Swift static analysis) before building or signing. If the scan surfaces any critical/high/medium finding, the release aborts with a non-zero exit code — nothing is built, nothing is signed. Combine with the rest of your release flags as needed:

mix mob.release --android --security-gate
mix mob.release --ios --security-gate

Equivalent to running mix mob.security_scan --strict and only proceeding to mix mob.release if the scan exits 0; the gate flag just bundles the two into one command so a wrong-order invocation can't slip through.

--ios output

_build/mob_release/<App>.ipa

--android output

android/app/build/outputs/bundle/release/app-release.aab

--ios prerequisites

  1. Apple Developer Program membership (paid, $99/yr)
  2. An "Apple Distribution" certificate in your keychain (Xcode → Settings → Accounts → Manage Certificates → +)
  3. An App Store provisioning profile for your bundle ID, downloaded to ~/Library/Developer/Xcode/UserData/Provisioning Profiles/. mix mob.provision --distribution automates the profile download.

--android prerequisites

  1. android/keystore.properties filled in with your upload keystore credentials. android/upload_jks.keystore must exist. See android/keystore.properties.example.

What --android does

  1. Regenerates the mob.exs url_schemes deep-link intent filter in AndroidManifest.xml.
  2. Regenerates the plugin-derived files and runs the same native build as mix mob.deploy --native for every abiFilters ABI, so jniLibs/<abi>/lib<app>.so links the current plugins instead of whatever the last deploy left there. Needs zig and the NDK, not a device.
  3. Stages a temp tree: OTP runtime + app BEAMs + exqlite BEAMs.
  4. Runs MobDev.OtpAssetBundle.build/2 to produce android/app/src/release/assets/otp.zip — stripped and compressed. MobBridge.extractOtpIfNeeded() extracts this on first launch. The release-variant asset dir keeps this out of debug builds.
  5. Runs ./gradlew bundleRelease to produce the signed AAB.

Use mix mob.publish --android to upload to Google Play.