{"_id":"@async-atharv/ipaship","_rev":"2-563a39e759e2d963e8b2115866d267a4","name":"@async-atharv/ipaship","dist-tags":{"latest":"1.2.2"},"versions":{"1.2.1":{"name":"@async-atharv/ipaship","version":"1.2.1","keywords":["flutter","ios","android","app-store","google-play","audit","compliance","cli","ai","gemini","claude","mcp","review","rejection","ipaship"],"author":{"name":"atharvnaik1"},"license":"MIT","_id":"@async-atharv/ipaship@1.2.1","maintainers":[{"name":"async-atharv","email":"atharv1599@gmail.com"}],"homepage":"https://opensource.ipaship.com","bugs":{"url":"https://github.com/atharvnaik1/ipaship-audit/issues"},"bin":{"ipaShip":"src/core/index.js","ipaShip-mcp":"src/core/mcp-server.js"},"dist":{"shasum":"043571e5dd75f4d94ac71bfad9a2d99691809a11","tarball":"https://registry.npmjs.org/@async-atharv/ipaship/-/ipaship-1.2.1.tgz","fileCount":19,"integrity":"sha512-ifzcPr3soZXPQhvG2ZRK7mX9Bxufa19P0RMsO2oG0SzL5n9us1P4KbI5BoC9h4kr/kSOJCxYZqHJh/PfpnhAZg==","signatures":[{"sig":"MEYCIQD0RsnB7DQJzXBSVTktwBrAuollmF3IstDNRSzhBxdXZQIhAMrETLxFHlo0/SqUvNq7/WrfeKjuhIHq5odsyIwDRZAb","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":448577},"main":"src/core/index.js","type":"module","engines":{"node":">=18"},"gitHead":"46178672913380d66ec13752fa5b97e79126f132","scripts":{"dev":"next dev -p 8080","build":"next build","start":"next start -H 0.0.0.0 -p 8080"},"_npmUser":{"name":"async-atharv","email":"atharv1599@gmail.com"},"repository":{"url":"git+https://github.com/atharvnaik1/ipaship-audit.git","type":"git"},"_npmVersion":"11.11.0","description":"AI-powered App Store & Google Play compliance audit CLI for Flutter apps. Catch rejections before you submit.","directories":{},"_nodeVersion":"25.8.1","dependencies":{"next":"^15.5.13","plist":"^5.0.0","react":"^19.2.4","busboy":"^1.6.0","cookie":"^1.1.1","marked":"^15.0.12","js-yaml":"^4.1.1","bcryptjs":"^3.0.3","mongoose":"^8.23.0","lru-cache":"^10.4.3","react-dom":"^19.2.4","posthog-js":"^1.373.4","remark-gfm":"^4.0.1","html2pdf.js":"^0.14.0","jsonwebtoken":"^9.0.3","lucide-react":"^0.577.0","posthog-node":"^5.34.1","@clerk/nextjs":"^6.39.1","framer-motion":"^12.38.0","react-markdown":"^10.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"postcss":"^8.5.8","typescript":"^5.9.3","@types/node":"^25.5.0","tailwindcss":"^3.4.19","@types/react":"^19.2.14","autoprefixer":"^10.4.27","@types/busboy":"^1.5.4","@tailwindcss/typography":"^0.5.10"},"_npmOperationalInternal":{"tmp":"tmp/ipaship_1.2.1_1778706430011_0.6527731588782204","host":"s3://npm-registry-packages-npm-production"}},"1.2.2":{"name":"@async-atharv/ipaship","version":"1.2.2","description":"AI-powered App Store & Google Play compliance audit CLI for Flutter apps. Catch rejections before you submit.","main":"src/core/index.js","type":"module","bin":{"ipaship":"src/core/index.js","ipaship-mcp":"src/core/mcp-server.js"},"engines":{"node":">=18"},"keywords":["flutter","ios","android","app-store","google-play","audit","compliance","cli","ai","gemini","claude","mcp","review","rejection","ipaship"],"author":{"name":"atharvnaik1"},"license":"MIT","homepage":"https://opensource.ipaship.com","repository":{"type":"git","url":"git+https://github.com/atharvnaik1/ipaship-audit.git"},"bugs":{"url":"https://github.com/atharvnaik1/ipaship-audit/issues"},"publishConfig":{"access":"public"},"scripts":{"dev":"next dev -p 8080","build":"next build","start":"next start -H 0.0.0.0 -p 8080"},"dependencies":{"@clerk/nextjs":"^6.39.1","@modelcontextprotocol/sdk":"^1.29.0","bcryptjs":"^3.0.3","busboy":"^1.6.0","chalk":"^5.6.2","commander":"^14.0.3","cookie":"^1.1.1","fast-glob":"^3.3.3","framer-motion":"^12.38.0","html2pdf.js":"^0.14.0","js-yaml":"^4.1.1","jsonwebtoken":"^9.0.3","lru-cache":"^10.4.3","lucide-react":"^0.577.0","marked":"^15.0.12","mongoose":"^8.23.0","next":"^15.5.13","ora":"^9.4.0","plist":"^5.0.0","posthog-js":"^1.373.4","posthog-node":"^5.34.1","react":"^19.2.4","react-dom":"^19.2.4","react-markdown":"^10.1.0","remark-gfm":"^4.0.1","zod":"^4.4.3"},"devDependencies":{"@tailwindcss/typography":"^0.5.10","@types/busboy":"^1.5.4","@types/node":"^25.5.0","@types/react":"^19.2.14","autoprefixer":"^10.4.27","postcss":"^8.5.8","tailwindcss":"^3.4.19","typescript":"^5.9.3"},"gitHead":"46178672913380d66ec13752fa5b97e79126f132","_id":"@async-atharv/ipaship@1.2.2","_nodeVersion":"26.1.0","_npmVersion":"11.13.0","dist":{"integrity":"sha512-w4CPjZD53TZXL4q9Qq7+08PE83p/kWZGE0rzwBRzQixqpA0w41M2koropHy7Pu9GI0Y+Zfq8PJvSy2kusR8Bvw==","shasum":"ed72dfb124699d750b0dfd96805e53421cad6540","tarball":"https://registry.npmjs.org/@async-atharv/ipaship/-/ipaship-1.2.2.tgz","fileCount":21,"unpackedSize":464183,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCe0E2AwctvuIrMeAA9RwQxa0Oy2x4p9aa1e1HGZAkrIwIgIGMVmyXRGisUhNLd8CFAz/hUOtjWdhjApHHKjXxGjr8="}]},"_npmUser":{"name":"async-atharv","email":"atharv1599@gmail.com"},"directories":{},"maintainers":[{"name":"async-atharv","email":"atharv1599@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ipaship_1.2.2_1779292286551_0.4682312838947731"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-13T21:07:09.944Z","modified":"2026-05-20T15:51:26.977Z","1.2.1":"2026-05-13T21:07:10.156Z","1.2.2":"2026-05-20T15:51:26.840Z"},"bugs":{"url":"https://github.com/atharvnaik1/ipaship-audit/issues"},"author":{"name":"atharvnaik1"},"license":"MIT","homepage":"https://opensource.ipaship.com","keywords":["flutter","ios","android","app-store","google-play","audit","compliance","cli","ai","gemini","claude","mcp","review","rejection","ipaship"],"repository":{"type":"git","url":"git+https://github.com/atharvnaik1/ipaship-audit.git"},"description":"AI-powered App Store & Google Play compliance audit CLI for Flutter apps. Catch rejections before you submit.","maintainers":[{"name":"async-atharv","email":"atharv1599@gmail.com"}],"readme":"# ipaShip - App Store Compliance Auditor (Open Source)\n\nAI-powered iOS App Store compliance auditor. Upload your `.ipa` file and get a comprehensive audit against Apple's Review Guidelines — before you submit.\n\n**Live at: [ipaship.com](https://ipaship.com)**\n\n## Features\n\n- **IPA Analysis** — Upload `.ipa` files (up to 150MB) for automated compliance auditing\n- **Full Guidelines Coverage** — Checks all 6 major App Store Review Guideline categories: Safety, Performance, Business, Design, Legal & Privacy, and Technical\n- **Multi-Provider AI** — Bring your own key from Anthropic (Claude), OpenAI (GPT), Google Gemini, or OpenRouter\n- **Model Selection** — Choose specific models per provider (Claude Sonnet 4, GPT-4o, Gemini 2.5 Flash, etc.)\n- **Real-Time Streaming** — Watch your audit report generate live as the AI analyzes your code\n- **Export Reports** — Download as Markdown or PDF\n- **Zero-Trust Security** — Files processed in ephemeral temp storage and deleted immediately. API keys stay in your browser, never on our servers\n- **100% Open Source** — Fully auditable codebase\n\n## Tech Stack\n\n| Layer | Technology |\n|-------|-----------|\n| Frontend | Next.js 15, React 19, TypeScript, Tailwind CSS, Framer Motion |\n| Backend | Next.js API Routes (Node.js) |\n| Database | MongoDB (Mongoose) |\n| AI Providers | Anthropic, OpenAI, Google Gemini, OpenRouter |\n| File Processing | Busboy (streaming uploads), `unzip` (IPA extraction) |\n| Export | html2pdf.js, React Markdown |\n\n## Getting Started\n\n### Prerequisites\n\n- Node.js 18+\n- MongoDB URI (Atlas or local)\n- API key from at least one AI provider\n- `unzip` installed on the server/runtime environment\n\n```bash\n# Ubuntu/Debian\nsudo apt-get update && sudo apt-get install -y unzip\n```\n\n### Setup\n\n```bash\n# Clone the repo\ngit clone https://github.com/atharvnaik1/ipaship-app-reviewer.git\ncd ipaship-app-reviewer\n\n# Install dependencies\nnpm install\n\n# Create environment file and fill in the required values\ncp .env.example .env.local\n\n# Start dev server\nnpm run dev\n```\n\nOpen [http://localhost:8080](http://localhost:8080) in your browser.\n\n### Production Build\n\n```bash\nnpm run build\nnpm start\n```\n\n## How It Works\n\n1. **Upload** — Drop your `.ipa` file. The server streams it to disk via Busboy without buffering in memory.\n2. **Extract** — The IPA is unzipped and all relevant source files are collected (`.swift`, `.m`, `.plist`, `.entitlements`, `.storyboard`, `.xcprivacy`, etc.). Binary files and build artifacts are skipped.\n3. **Analyze** — Source files are sent to your chosen AI provider with a structured audit prompt. The response streams back in real-time.\n4. **Report** — You get a structured compliance report with pass/fail indicators, severity ratings, and a prioritized remediation plan.\n\n## API Endpoints\n\n| Method | Endpoint | Purpose |\n|--------|----------|---------|\n| `POST` | `/api/audit` | Upload IPA, stream AI audit report |\n| `POST` | `/api/save-report` | Save report to MongoDB |\n| `GET` | `/api/visitor` | Increment and return visitor count |\n\n## Client Wrappers / SDKs\n\nipaShip provides ready-to-use boilerplate SDKs and wrappers for various ecosystems and languages. You can find them in the `wrappers/` directory. Each wrapper is skeletoned to pragmatically audit your `.ipa` files directly from your CI/CD pipelines, backend backend, or build environments!\n\n### Commands to Run Wrappers\n\nHere are quick commands to interact with the given wrappers:\n\n**Node.js / NPM**\n```bash\ncd wrappers/npm && npm install\nnode index.js\n```\n\n**Python**\n```bash\ncd wrappers/python\npython3 ipaship.py\n```\n\n**Rust**\n```bash\ncd wrappers/rust\ncargo run --release\n```\n\n**Go**\n```bash\ncd wrappers/go\ngo run ipaship.go\n```\n\n**Homebrew (MacOS CLI)**\n```bash\nbrew install ./wrappers/homebrew/ipaship.rb\nipaship /path/to/app.ipa\n```\n\n**C / C++**\n```bash\ncd wrappers/c && gcc ipaship.c -o ipaship && ./ipaship\ncd wrappers/cpp && g++ ipaship.cpp -o ipaship && ./ipaship\n```\n\n**Java & Kotlin**\n```bash\n# Java\ncd wrappers/java && mvn clean install\n# Kotlin\ncd wrappers/kotlin && ./gradlew build\n```\n\n**Ruby**\n```bash\ncd wrappers/ruby\ngem build ipaship.gemspec\n```\n\n**PHP**\n```bash\ncd wrappers/php\ncomposer install\n```\n\n**C# / .NET**\n```bash\ncd wrappers/csharp-dotnet\ndotnet build\n```\n\n**R**\n```R\n# Load inside your R script (wrappers/r)\nsource(\"R/ipaship.R\")\nipaship_audit(\"app.ipa\", \"API_KEY\")\n```\n\n**Linux (Bash CLI)**\n```bash\nchmod +x wrappers/linux/ipaship-cli.sh\n./wrappers/linux/ipaship-cli.sh /path/to/app.ipa \"YOUR_API_KEY\"\n```\n\n**Swift & Apple Frameworks (Obj-C / Cocoapods)**\n- Add `wrappers/swift-cocoapods` as a local Swift Package Dependency.\n- Integrate the Objective-C headers from `wrappers/objc` into your build.\n\n**Cross-Platform App Frameworks (Dart/Flutter, Expo, Ionic)**\n- **Flutter:** Import `wrappers/flutter-dart` via local path dependency in your `pubspec.yaml`.\n- **Expo:** Integrate `wrappers/expo/index.js` as an Expo config plugin.\n- **Ionic:** Use the `wrappers/ionic` wrapper with Capacitor.\n\n## Deployment\n\nA deployment script is included for Ubuntu 24.04 VMs:\n\n```bash\n# On the server, create .env.local first\ncp .env.example /opt/ipaship/.env.local\n\n# Ensure unzip is installed (required by /api/audit extraction)\nsudo apt-get update && sudo apt-get install -y unzip\n\n# Then run the deploy script\nchmod +x deploy.sh\n./deploy.sh\n```\n\nThe script sets up Node.js 20, PM2, Nginx (with streaming/upload support), and UFW firewall.\n\n## Security\n\n- **No cloud storage** — Files are processed in ephemeral `/tmp` directories and deleted immediately after audit\n- **BYOK (Bring Your Own Key)** — API keys are stored in your browser's localStorage, never sent to our servers\n- **No shell injection** — File extraction uses `execFile` (no shell), preventing command injection via filenames\n- **Binary detection** — Binary plists and compiled files are detected and skipped\n- **Rate limiting** — 5 requests per IP per minute via in-memory LRU cache\n- **Prompt injection guards** — System/user message separation with explicit instructions to treat file contents as data only\n\n## Contributing\n\nContributions are welcome! Feel free to open issues or submit pull requests.\n\n## License\n\nOpen source. See repository for details.\n\n---\n\nBuilt by [ipaShip](https://ipaship.com)\n© ipaShip – Original Creator: Atharv Naik\n","readmeFilename":"README.md"}