Skip to content

Bump fastlane to 2.240.1 in lockfile - #99

Merged
devxoul merged 1 commit into
mainfrom
chore/bump-fastlane
Sep 21, 2026
Merged

devxoul merged 1 commit into
mainfrom
chore/bump-fastlane

Conversation

@devxoul

@devxoul devxoul commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Summary

bundle exec fastlane match started failing locally against App Store Connect:

Service key is empty
[!] The request could not be completed because:
	Could not receive latest API key from App Store Connect, this might be a server issue.

Root cause

The bare match invocation (no API key path) authenticates via Apple ID login instead of an App Store Connect API key. Apple's Olympus app/config endpoint, which supplies the authServiceKey for that path, started returning HTTP 404. Spaceship's itc_service_key raised Service key is empty, which fastlane wrapped and surfaced as the misleading "Could not receive latest API key" / AppleTimeoutError.

This is fastlane/fastlane#30199, fixed by fastlane/fastlane#30206 ("Read the App Store Connect API key from where Apple keeps it now"), released in fastlane 2.240.0. The lockfile was pinned to 2.236.1.

Change

bundle update fastlane bumps 2.236.1 to 2.240.1. Only Gemfile.lock changes — no Gemfile, BUNDLED WITH, or RUBY VERSION edits. Transitive gems move along with it (notably rubyzip 2.4.1 to 3.7.0, terminal-table 3.0.2 to 4.0.0, security 0.1.5 to 0.3.0, xcodeproj 1.27.0 to 1.28.1, google-cloud-storage 1.47.0 to 1.62.0, aws-sdk-s3 1.209.0 to 1.232.1).

2.240.1 rather than 2.240.0 because it adds the cgi gem, which Ruby 4 removed from stdlib — relevant here since local dev runs Ruby 4.0.5.

fastlane 2.239.0 raised the minimum supported Ruby to 3.1. .github/workflows/release.yml already pins ruby-version: "3.3" via ruby/setup-ruby@v1, so CI needs no change.

Testing

  • bundle exec fastlane match --readonly true --api_key_path ./fastlane/api_key.json on 2.240.1: exit 0, decrypts the match repo, installs the Apple Distribution certificate (valid through 2027-01-04) and provisioning profile. Also passes on 2.236.1 — API-key auth was never the broken path, only Apple ID auth was.
  • make lint (SwiftFormat): exit 0, 0/23 files need formatting.
  • make generate (Tuist): exit 0.
  • xcodebuild test fails locally with "No signing certificate 'Mac Development' found" — a pre-existing local keychain gap (only the Apple Distribution identity is present), unrelated to this lockfile change. Not run to completion as a result.

Summary by cubic

Bumps fastlane from 2.236.1 to 2.240.1 in Gemfile.lock to restore fastlane match authentication against App Store Connect via Apple ID login, which Apple's server-side changes had broken.

Dependencies

  • Apple's Olympus endpoint returning 404 is fixed by reading the API key from its new location, shipped in fastlane 2.240.0.
  • 2.240.1 over 2.240.0 adds the cgi gem, removed from Ruby 4's stdlib (local dev runs Ruby 4).
  • fastlane 2.239.0 raised minimum supported Ruby to 3.1; CI already runs Ruby 3.3, so no workflow changes.
  • Transitive gems update alongside, including rubyzip, terminal-table, xcodeproj, and aws-sdk-s3.

Written for commit 95824c7. Summary will update on new commits.

Review in cubic

2.236.1 can no longer authenticate against App Store Connect through the
Apple ID path. Apple's Olympus app/config endpoint started returning 404,
so Spaceship failed with "Service key is empty", surfaced as "Could not
receive latest API key from App Store Connect". fastlane#30206 fixes it
by reading the key from where Apple keeps it now, shipped in 2.240.0.

2.240.1 also pulls in the cgi gem that Ruby 4 dropped from stdlib, which
matters for local runs. CI stays on Ruby 3.3, above the Ruby 3.1 floor
that 2.239.0 introduced.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Re-trigger cubic

@devxoul
devxoul merged commit 8e24394 into main Sep 21, 2026
2 checks passed
@devxoul
devxoul deleted the chore/bump-fastlane branch September 21, 2026 01:57

@typeey typeey Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review

The lockfile-only update is coherent and scoped. The upstream authentication fix and Ruby 4 cgi dependency are both present in the resolved version, and the project’s Ruby 3.3 CI satisfies the updated dependency graph.

The Apple ID path was not reproducible here; PR CI was still pending during review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant