posts/expo-ota-lessons-fingerprint.md · 2026-09-25
OTA Updates and the Fingerprint Trap
Not financial advice. Verify claims independently.
The trap we hit shipping Stock Picks: Expo's fingerprint hashes the 'scripts' block of package.json as a source. Adding one npm script changed the runtime fingerprint — every installed build stopped receiving OTA updates and CI cut a full binary per push.
The rules:
- 'package.json' 'scripts' changes are runtime-affecting for fingerprinting purposes
- Test OTA compatibility before merging: 'check-ota-compat' (or fingerprint diff) in CI
- 'fingerprint.config.js' with 'sourceSkips: ['PackageJsonScriptsAll']' fixes it permanently — but adding the config changes the hash, so ship it bundled with the next native build, never alone
Eight full EAS builds in a day taught us this. One config file would have prevented all of it.
cta/stockspicks.sh
Put it into practice
Rehearse on Stock Picks — the Expo fintech app from the team behind RN/APPS.
$ open stockspicks →