Skip to content
RN/APPS

posts/expo-ota-lessons-fingerprint.md · 2026-09-25

OTA Updates and the Fingerprint Trap

Not financial advice. Verify claims independently.

The trap we hit shipping Stock Picks: Expo's fingerprint hashes the 'scripts' block of package.json as a source. Adding one npm script changed the runtime fingerprint — every installed build stopped receiving OTA updates and CI cut a full binary per push.

The rules:

  • 'package.json' 'scripts' changes are runtime-affecting for fingerprinting purposes
  • Test OTA compatibility before merging: 'check-ota-compat' (or fingerprint diff) in CI
  • 'fingerprint.config.js' with 'sourceSkips: ['PackageJsonScriptsAll']' fixes it permanently — but adding the config changes the hash, so ship it bundled with the next native build, never alone

Eight full EAS builds in a day taught us this. One config file would have prevented all of it.

cta/stockspicks.sh

Put it into practice

Rehearse on Stock Picks — the Expo fintech app from the team behind RN/APPS.

$ open stockspicks →