已处理隐私清单规则仍遭Apple ITMS-91053警告的技术求助
Apple警告信息
ITMS-91053: 缺失API声明 - 您的“{app name}”文件中的代码引用了一个或多个需要说明使用理由的API,涉及以下API类别:
NSPrivacyAccessedAPICategoryFileTimestamp。目前无需操作,但自2024年5月1日起,上传新应用或应用更新时,必须在应用隐私清单中包含NSPrivacyAccessedAPITypes数组,说明这些API的合规使用理由。
ITMS-91053: 缺失API声明 - 您的“{app name}”文件中的代码引用了一个或多个需要说明使用理由的API,涉及以下API类别:NSPrivacyAccessedAPICategoryDiskSpace。目前无需操作,但自2024年5月1日起,上传新应用或应用更新时,必须在应用隐私清单中包含NSPrivacyAccessedAPITypes数组,说明这些API的合规使用理由。
ITMS-91053: 缺失API声明 - 您的“{app name}”文件中的代码引用了一个或多个需要说明使用理由的API,涉及以下API类别:NSPrivacyAccessedAPICategorySystemBootTime。目前无需操作,但自2024年5月1日起,上传新应用或应用更新时,必须在应用隐私清单中包含NSPrivacyAccessedAPITypes数组,说明这些API的合规使用理由。
ITMS-91053: 缺失API声明 - 您的“{app name}”文件中的代码引用了一个或多个需要说明使用理由的API,涉及以下API类别:NSPrivacyAccessedAPICategoryUserDefaults。目前无需操作,但自2024年5月1日起,上传新应用或应用更新时,必须在应用隐私清单中包含NSPrivacyAccessedAPITypes数组,说明这些API的合规使用理由。
已采取的措施及疑问
已尝试以下解决步骤:
- 升级第三方SDK至Apple要求的版本,确保SDK自带隐私清单。
- 四个API类别中,仅
NSPrivacyAccessedAPICategoryUserDefaults为应用自身所需(应用使用了UserDefaults),已将其添加到应用的PrivacyInfo.xcprivacy文件中。
但提交新版本后仍收到相同警告。请问:应用与SDK的隐私清单是否会自动合并?还有哪些遗漏的处理步骤?
Swift包及版本
xcodebuild日志输出如下:
[08:11:49]: ▸ Resolved source packages: [08:11:49]: ▸ GoogleAppMeasurement: https://github.com/google/GoogleAppMeasurement.git @ 10.22.0 [08:11:49]: ▸ GoogleDataTransport: https://github.com/google/GoogleDataTransport.git @ 9.4.0 [08:11:49]: ▸ GTMSessionFetcher: https://github.com/google/gtm-session-fetcher.git @ 3.3.1 [08:11:49]: ▸ UIPiPView: git@github.com:torufuruya/UIPiPView.git @ b3183e7 [08:11:49]: ▸ CwlCatchException: https://github.com/mattgallagher/CwlCatchException.git @ 2.1.1 [08:11:49]: ▸ GoogleSignIn: https://github.com/google/GoogleSignIn-iOS @ 7.1.0 [08:11:49]: ▸ CwlPreconditionTesting: https://github.com/mattgallagher/CwlPreconditionTesting.git @ 2.1.0 [08:11:49]: ▸ AudioKit: https://github.com/AudioKit/AudioKit.git @ 5.5.7 [08:11:49]: ▸ nanopb: https://github.com/firebase/nanopb.git @ 2.30910.0 [08:11:49]: ▸ AppCheck: https://github.com/google/app-check.git @ 10.18.0 [08:11:49]: ▸ Pulse: https://github.com/kean/Pulse @ 1.1.0 [08:11:49]: ▸ Quick: https://github.com/Quick/Quick.git @ 6.1.0 [08:11:49]: ▸ SwiftlySearch: https://github.com/thislooksfun/SwiftlySearch.git @ 1.2.5 [08:11:49]: ▸ GoogleUserMessagingPlatform: https://github.com/googleads/swift-package-manager-google-user-messaging-platform.git @ 2.3.0 [08:11:49]: ▸ swift-video-generator: https://github.com/dev-labs-bg/swift-video-generator.git @ 1.4.1 [08:11:49]: ▸ AdvancedScrollView: https://github.com/dmytro-anokhin/advanced-scrollview.git @ 0.0.6 [08:11:49]: ▸ GTMAppAuth: https://github.com/google/GTMAppAuth.git @ 4.1.1 [08:11:49]: ▸ Firebase: https://github.com/firebase/firebase-ios-sdk.git @ 10.22.0 [08:11:49]: ▸ SwiftyStoreKit: https://github.com/bizz84/SwiftyStoreKit.git @ 0.16.4 [08:11:49]: ▸ Mocker: https://github.com/WeTransfer/Mocker.git @ 3.0.1 [08:11:49]: ▸ leveldb: https://github.com/firebase/leveldb.git @ 1.22.3 [08:11:49]: ▸ Promises: https://github.com/google/promises.git @ 2.4.0 [08:11:49]: ▸ abseil: https://github.com/google/abseil-cpp-binary.git @ 1.2022062300.1 [08:11:49]: ▸ URLImage: https://github.com/dmytro-anokhin/url-image @ 3.1.1 [08:11:49]: ▸ AppAuth: https://github.com/openid/AppAuth-iOS.git @ 1.7.3 [08:11:49]: ▸ SwiftProtobuf: https://github.com/apple/swift-protobuf.git @ 1.25.2 [08:11:49]: ▸ swift-log: https://github.com/apple/swift-log.git @ 1.4.4 [08:11:49]: ▸ gRPC: https://github.com/google/grpc-binary.git @ 1.49.2 [08:11:49]: ▸ Mantis: https://github.com/guoyingtao/Mantis.git @ 2.7.0 [08:11:49]: ▸ Get: https://github.com/kean/Get.git @ 1.0.4 [08:11:49]: ▸ Fakery: https://github.com/vadymmarkov/Fakery @ 5.1.0 [08:11:49]: ▸ Nimble: https://github.com/Quick/Nimble.git @ 11.2.1 [08:11:49]: ▸ GoogleMobileAds: https://github.com/googleads/swift-package-manager-google-mobile-ads.git @ 11.2.0 [08:11:49]: ▸ GoogleUtilities: https://github.com/google/GoogleUtilities.git @ 7.13.1 [08:11:49]: ▸ ImagePickerView: https://github.com/ralfebert/ImagePickerView @ 0.5.0 [08:11:49]: ▸ InteropForGoogle: https://github.com/google/interop-ios-for-google-sdks.git @ 100.0.0
声明了受警告API类别的SDK
在Swift包检出目录~/Library/Developer/Xcode/DerivedData/{app name}/SourcePackages/checkouts/中搜索API类别的结果如下:
NSPrivacyAccessedAPICategoryFileTimestamp
➜ checkouts grep NSPrivacyAccessedAPICategoryFileTimestamp . -lr ./firebase-ios-sdk/FirebaseDynamicLinks/Sources/Resources/PrivacyInfo.xcprivacy ./firebase-ios-sdk/Crashlytics/Resources/PrivacyInfo.xcprivacy ./grpc-binary/grpcpp-Wrapper/Resources/PrivacyInfo.xcprivacy ./grpc-binary/grpc-Wrapper/Resources/PrivacyInfo.xcprivacy ./grpc-binary/openssl-grpc-Wrapper/Resources/PrivacyInfo.xcprivacy ./gtm-session-fetcher/Sources/LogView/Resources/PrivacyInfo.xcprivacy ./GoogleUtilities/GoogleUtilities/Privacy/Resources/PrivacyInfo.xcprivacy
NSPrivacyAccessedAPICategoryDiskSpace
无SDK声明该类别。推测此前Firebase Crashlytics曾使用该API,但最新版本已移除:
# 10.22.0 - [fixed] Force validation or rotation of FIDs for FirebaseSessions. - [changed] Removed calls to statfs in the Crashlytics SDK to comply with Apple Privacy Manifests. This change removes support for collecting Disk Space Free in Crashlytics reports.
已确认所有SDK均未使用官方文档中列出的该政策要求的其他API(如statfs)。
NSPrivacyAccessedAPICategorySystemBootTime
➜ checkouts grep NSPrivacyAccessedAPICategorySystemBootTime . -lr ./firebase-ios-sdk/Crashlytics/Resources/PrivacyInfo.xcprivacy ./grpc-binary/grpcpp-Wrapper/Resources/PrivacyInfo.xcprivacy ./grpc-binary/grpc-Wrapper/Resources/PrivacyInfo.xcprivacy ./grpc-binary/openssl-grpc-Wrapper/Resources/PrivacyInfo.xcprivacy
NSPrivacyAccessedAPICategoryUserDefaults
➜ checkouts grep NSPrivacyAccessedAPICategoryUserDefaults . -lr ./GoogleSignIn-iOS/GoogleSignIn/Sources/Resources/PrivacyInfo.xcprivacy ./firebase-ios-sdk/FirebaseDynamicLinks/Sources/Resources/PrivacyInfo.xcprivacy ./firebase-ios-sdk/Crashlytics/Resources/PrivacyInfo.xcprivacy ./firebase-ios-sdk/FirebaseCore/Internal/Sources/Resources/PrivacyInfo.xcprivacy ./firebase-ios-sdk/FirebaseCore/Sources/Resources/PrivacyInfo.xcprivacy ./firebase-ios-sdk/FirebaseAuth/Sources/Resources/PrivacyInfo.xcprivacy ./firebase-ios-sdk/FirebaseRemoteConfig/Swift/Resources/PrivacyInfo.xcprivacy ./gtm-session-fetcher/Sources/Core/Resources/PrivacyInfo.xcprivacy ./GoogleUtilities/GoogleUtilities/Privacy/Resources/PrivacyInfo.xcprivacy
内容的提问来源于stack exchange,提问作者Toru

