Skip to content

Dependency reporting

The SDK reports your app’s third-party dependencies once per app version, so the dashboard can show exactly which libraries each release ships.

It resolves them in two ways, in order:

  1. Bundled manifest — a cimka_dependencies.json file in your app bundle, generated from your resolved Swift packages. Gives exact package coordinates and versions.
  2. Embedded frameworks — if no manifest is bundled, the SDK lists the app’s embedded .frameworks and their versions. This is the fallback and is less precise.

The SDK repository ships scripts/cimka-dependencies.sh — the iOS counterpart of the Android Gradle plugin. Run it from your app’s project directory:

Terminal window
scripts/cimka-dependencies.sh ./cimka_dependencies.json

It reads your Package.resolved (resolve packages in Xcode first) and writes a list like:

[
{ "package": "github.com/apple/swift-log", "version": "1.5.3" },
{ "package": "github.com/Alamofire/Alamofire", "version": "5.10.2" }
]

Add cimka_dependencies.json to your app target’s Copy Bundle Resources. You can wire the script into a Run Script build phase so it regenerates on every build.