← Back to the library
MobileCore · 6 min

A broken mobile release is already in production

“A severe bug shipped, but App Store and Play Store review may delay a replacement binary.”

THE PRINCIPLE

Recovery is a product capability. Ship kill switches, compatible runtime boundaries, staged rollouts, and rollback before the incident.

FIRST MOVES

  1. Disable the risky path with remote configuration if money or data is at risk.
  2. Determine whether the fix changes JavaScript/assets or native code.
  3. Test the exact OTA artifact against the production runtime and canary it.
  4. For native changes, submit a new binary and request expedited review while the mitigation remains active.

TOOLS: THEN → NOW

Microsoft App Center CodePushExpo EAS Update / expo-updates
Hard-coded feature availabilityRemote config and typed feature flags

PATTERN SNAPSHOT

// Runtime-compatible JS hotfix only.
await Updates.fetchUpdateAsync();
await Updates.reloadAsync();

// Native modules changed? Ship a new binary instead.

CLOSE THE AI. EXPLAIN THIS.

Which kinds of fixes cannot safely be delivered as an OTA update, and why?

Guide reviewed