ASC CLI 5.4.0 hardens web session storage and fixes Apple cookie scope semantics

rudrank · x · 2026-09-19

App Store Connect CLI 5.4.0 ships a serious web session hardening pass: rejects symlinked, oversized, FIFO, and directory cache entries; stages writes in private exclusive files; falls back from stale or unusable file sessions; and protects attachment credentials across redirects. Cookie handling now keeps Apple's real scope and expiry semantics — positive Max-Age wins over stale Expires, absolute deadlines survive cache serialization, and ambiguous same-name cookies are dropped instead of persisting the wrong host, domain, or path.

Related event: App Store Connect CLI 5.4.0 ships 68 changes to make agent automation safer(10 posts)→

Original post →

More from coding & agent

coding & agent channel →