{
  "name": "VortX",
  "identifier": "tv.vortx.altstore",
  "subtitle": "Native streaming app for Apple, on stremio-core + libmpv.",
  "iconURL": "https://raw.githubusercontent.com/VortXTV/VortX/main/docs/logo.png",
  "website": "https://vortx.tv",
  "tintColor": "C8A24B",
  "apps": [
    {
      "name": "VortX",
      "bundleIdentifier": "com.stremiox.app.native",
      "developerName": "Mamaclapper",
      "subtitle": "Stream movies and shows on iPhone and iPad.",
      "localizedDescription": "VortX is a native, open-source streaming app for Apple devices, built on the official stremio-core engine and the libmpv player. Multi-profile, HDR and Dolby Vision, skip intro and outro, stream ranking, in-app add-ons and debrid keys, and more. Sideload-friendly: this source delivers one-tap updates so you never re-download an IPA by hand.",
      "iconURL": "https://raw.githubusercontent.com/VortXTV/VortX/main/docs/logo.png",
      "tintColor": "C8A24B",
      "category": "entertainment",
      "screenshotURLs": [],
      "versions": [
        {
          "version": "0.4.0",
          "buildVersion": "258",
          "date": "2026-10-03",
          "localizedDescription": "Apple build 258: repaired iPhone/iPad startup, cleaner touch player, real Wave seek styles, pinch Fit/Fill, clear add-on tabs and unobscured navigation/Search.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.20/VortX-iOS-v0.4.0-beta.20-ci.ipa",
          "size": 65759856,
          "sha256": "e7330dd0aed6d8a33122a4bfa569b049f9ab72ee66c3f1d18771dc4d02682cb8",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "254",
          "date": "2026-10-01",
          "localizedDescription": "# 0.4.0 Beta 18 - Playback settlement, Mac redesign, Android Usenet, and account sync\n\n**Install this over any earlier build.** Beta 18 brings together the reviewed changes since Beta 17 for Apple TV, iPhone, iPad, Apple Silicon Mac, Android phones and Android TV. It retains the preceding playback, binge-watching, automatic-skip and subtitle repairs. Apple build **254**, Android version code **239**. Package versions, signing, checksums and Latest promotion are separate checks before publication.\n\n## What's new\n\n**A native Mac sidebar and in-window Settings.** Home, Discover, Live, Library, Search, Add-ons and Settings now have persistent sidebar destinations. Settings opens inside the app with categorized navigation rather than an oversized floating phone-style sheet. Search remains available in the shell; Command-F and the Go menu route to it. Keyboard shortcuts select destinations, Escape returns focus to the shell when appropriate without stealing a child screen's Back action, and transitions respect Reduce Motion. This is an implemented native shell, not a claim that every Mac screen has received its final visual redesign.\n\n**Direct NZB indexers on Android.** Save and manage Newznab-compatible HTTPS indexers, including NZBGeek, and search them from normal movie and selected-episode source lists. Credentials are encrypted and scoped to the account and profile. Editing, disabling, removing or switching configuration invalidates old requests; a finished search cannot publish stale results into source selection or next-episode preparation. Configuration survives a new session for the same account/profile instead of being keyed to a temporary generation.\n\n**Multiple Android Usenet servers with priority and fallback.** Save, edit, disable, remove and prioritize NNTP servers on phone and TV. Existing single-server settings migrate. Configured routes use the shared resolver rather than an unconnected settings screen. The local provider loop tries the configured alternatives and retains the existing cloud path when separately configured. TorBox cloud preparation still requires its API key and may prepare an uncached job; this is not a guarantee of immediate playback from every article or provider.\n\n**Trakt Continue Watching on Android.** An optional, read-only Home rail loads Trakt's movie and episode playback queues, resolves artwork, and carries the exact series, season and episode into detail navigation. It is Off by default and does not turn imported Trakt progress into synthetic native watched history. Both playback lists must succeed before a new complete cache is published. A same-owner fetch failure can retain the last successful rail.\n\n**Manual Trakt check-in from Android detail pages.** The optional action follows the primary movie or selected episode on phone and TV. It requires the owner profile and manual-check-in opt-in. Duplicate taps are blocked; authentication, profile, title and episode changes reject old results. A conflicting active check-in is not silently replaced: the app offers an explicit “Check in here” action. Manual check-in does not mark the title watched. Apple's check-in chip also re-evaluates the stored session at the authentication boundary while retaining its episode and opt-in requirements.\n\n**Phone Library segments and TV add-on reordering.** Android phone and TV share All, Movies, Shows and Anime segments and their applicable smart filters. Native sorting is retained; the app does not invent genre metadata to populate those filters. Android TV add-on ordering has remote-friendly move controls, and configured Usenet/indexer routes are reachable through TV Settings with normal Back behavior.\n\n## What's fixed\n\n**AVPlayer recovery settles against the current item and the viewer's transport choice.** Recovery seeks have an explicit owner, accepted landing and bounded repair result. A newer seek, source change or player replacement retires the older recovery. An accepted small forward remux landing is normalized to its actual local origin, avoiding a repeated remount loop. A false seek completion or deadline consumes a concrete repair target instead of leaving a ticket silently unresolved. If a ready callback synchronously replaces the item, the retired callback cannot apply tracks, Play/Pause or startup state to the replacement. A paused recovery remains paused until the viewer resumes it.\n\n**VortX Player cache maintenance no longer drops playback before its seek runs.** A complete overnight TV diagnostic showed repeated cache trims followed by a false end-of-file, a failed high-position resume and a restart around nine seconds. The queued buffer-drop and seek were not an atomic transport operation in the shipped player. Maintenance now requests the low-level seek without first resetting the decoder, keeps its temporary cache option until an owned seek receipt settles, and requires an increased low-level-seek counter plus a compatible landing before reporting success. One bounded reissue handles the demux thread's option-adoption race; a timeout is a failure, not a completed trim. Memory-pressure and background cache limits remain in force.\n\n**Paused replacement playback keeps its target and the viewer's choice.** A repair's temporary engine pause is no longer mistaken for the viewer pressing Pause. A paused reopen waits for the exact replacement file and its duration before deciding whether to seek or clear a target, and retains the seek obligation if command admission fails. An early zero-position tick cannot settle a high-position restoration. Stale callbacks carry their original maintenance attempt rather than adopting a later operation.\n\n**Late subtitle discovery cannot resurrect an old selection.** External-subtitle selection settles independently against its owned item and inventory. Explicit choices and Off supersede pending restoration; outgoing and late callbacks cannot restore an older track. Native subtitle single-renderer and background-style handling from earlier betas remain. Authored bitmap styling and system accessibility overrides are still separate limits, not evidence of duplicate-renderer closure on every file.\n\n**The iPhone episode Watch action sits at the hero seam.** Portrait phones retain the large cinematic hero, place the real selected-episode Watch action across its bottom edge and wrap long action text without the narrow vertical-letter collapse. Manual quality, language and player controls remain below it, and source rows preserve add-on-authored formatting. The phone-only overlap is limited to finite portrait phone widths; iPad and Mac retain their source-list Play action rather than losing it through a shared layout change.\n\n**Android Usenet admission uses decoded article evidence.** Whole-file sizing and multipart coverage come from validated yEnc headers, not a sum of estimated article sizes. Invalid, overlapping or incomplete ranges cannot be admitted as complete cached media. Loopback binding happens inside the provider attempt: a bind failure cleans up the session and advances fallback. Cancellation and a configuration/account change after readiness dispose the producer and loopback registration instead of leaving a stale playable URL behind. Credential and provider-document locking use one consistent order.\n\n**Trakt episode intent survives metadata and owner reloads.** Android routes the typed episode hint rather than parsing a display caption. A valid manual selection takes precedence, then the matching Trakt target, then the existing native primary-episode policy. If an interim owner has no matching episode, the original intent remains available when returning to the previous owner. In-player intent changes only after an episode switch is accepted.\n\n**Android filmography opens the latest title selected.** A second tap during a slow title lookup now cancels and supersedes the first instead of being ignored. Back and screen disposal invalidate pending navigation immediately on both phone and TV; an old completion cannot open a title after leaving the page.\n\n**Old Trakt responses cannot repopulate a new account's Home rail.** Requests carry the exact Trakt session epoch, toggle revision and cache generation. Network and artwork work run outside the cache lock. Clear invalidates immediately, including while a fetch is pending. Home clears visible personalized rows before awaiting provider cleanup and checks the receipt again immediately before assignment. Turning the feature off and on cannot admit an old request just because the account name is unchanged.\n\n**Home rail order travels through account sync and backup.** Ordered rail IDs use the same ordered array shape across Apple and Android. Hidden rails remain a string set and layout remains a string. Android converts its local JSON string representation at the account/backup boundary, retains unknown rail IDs in order, reads legacy Android backups and skips malformed values without wiping a valid local arrangement. Local dirty settings are protected from an older pull. Per-profile catalog order stays profile-scoped rather than being flattened into one global arrangement.\n\n**Account add-on changes respect both native ownership and the VortX session.** A delayed install, removal or reorder cannot run under a replacement account merely because the native Stremio UID happens to be the same. Accepted account descriptors enter the actual native gateway, and routine reads cannot acknowledge or replace a newer local order edit. The earlier no-shrink roster, removal/reinstall, local-only mirroring and source-group ordering protections are retained.\n\n**An asynchronous remove/re-add keeps its history ownership.** Android waits for the exact native result of the original account-owned operation instead of assuming its immediate disk read already includes the change. A later re-add, including an authenticated metadata-only account update, continues that captured transition. Failed proof storage cannot be reported as successful publication.\n\n**Android owner-library events have a real native read and restore path.** Account sync now distinguishes library membership from genuine history. Exact title type, current video, position, duration, event timestamp, nullable viewing timestamp, watched bitfield, per-video watched state, count and movie-only whole-title state travel through a receipt-checked batch. Genuinely newer events can update an already-present identity; a metadata-only read cannot overwrite peer progress. Zero progress is valid and is not replaced with a fabricated current viewing time. Partial series progress is not promoted to a fictional whole-series watched flag. Manual movie unwatch retains explicit evidence even when the movie has no viewing timestamp.\n\n**Failed history restoration cannot advance the account's accepted version.** Native and account admission are checked again at dispatch, including a fresh native LWW read. Null, wrong-owner, duplicate, incomplete or mismatched receipts are rejected. Opaque peer fields are preserved rather than “repaired” from an unclocked local snapshot. Real local progress, playback completion and watched/library actions arm the durable debounced account push instead of depending on an app restart.\n\n**Manual watched actions and genuine playback history have separate cross-client carriers.** Apple and Android use the same owner-profile history array for real viewing events, including unsaved titles, without turning Continue Watching into Saved library membership. Watched/unwatched intent remains separately clocked. Sparse Apple events inherit optional fields only from proven same-owner state; malformed, unsupported and oversized peer sections are preserved rather than flattened. Secondary profiles with their own accounts cannot export their history into the main owner's carrier.\n\n**Adding a title cannot erase another device's resume position.** The native library constructor stamps a newly saved title with the current time even before viewing it. That metadata-only clock is no longer treated as a newer viewing event on either side of reconciliation. Genuine zero rewinds and completed playback remain valid, and unknown peer fields survive a metadata refresh.\n\n**A later library edit cannot block a newer real resume.** Android and its native bridge now distinguish an owned playback event from the row's later membership/persistence timestamp. A conditional restore requires the complete, freshly matching account-owned state and a genuinely newer viewing event. It retains the real viewing time and the existing membership time separately; it does not manufacture a later event to satisfy the engine. Changed, unknown or foreign rows keep the stricter original admission rule. The same rule covers a proven pristine newly saved title whose constructor timestamp is not viewing evidence.\n\n**A library removal belongs to the account that made it.** Removal/reinstall stamps use account-specific durable stores and captured revisions. Switching A to B and back invalidates the old A handle while restoring A's own saved stamps. Unassigned legacy data is not adopted by whichever account signs in next. Queued typed library actions capture the account, native owner and removal capability before their first dispatcher suspension; an A action cannot begin its queued body as B. The final upload filter removes only recognized removed identities and retains unknown objects, arrays, scalars and nulls from peer documents.\n\n## Retained from Beta 17\n\nThe configurable automatic intro/credits skip countdown with Off and Cancel, source-owned watch suggestions, real first-frame admission at 0:00, failed-resume retirement across replacement chains, player/source/prewarm lifecycle ownership, independent audio/subtitle restoration, file-matched add-on subtitle requests, Trakt and Top Shelf artwork, bounded batch metadata recovery, recoverable opt-in watched-download cleanup, web source paging/skip parsing and artifact-bound Android update metadata remain. See the [Beta 17 notes](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.17) and their retained Beta 16 list for the preceding repairs.\n\n## Android\n\nThis candidate includes source for both signed distribution variants. Both contain the phone and Android TV interfaces and the three shipped ABIs: arm64-v8a, armeabi-v7a and x86_64.\n\n- `VortX-0.4.0-full-mpv-universal.apk`: the sideloaded VortX/MPV build with Media3 fallback.\n- `VortX-0.4.0-play-media3-universal.apk`: the GPL-native-free Media3 build.\n- `VortX-0.4.0-play-media3.aab`: the matching Play distribution bundle, not an installable APK.\n\nThe direct NZB/Usenet, Library, Trakt and remote-ordering work closes concrete feature gaps. It does **not** establish 100% visual or functional parity with Apple, physical Shield/Fire TV compatibility, or a complete redesign of every Android page. Broader detail/hero composition and live remote journeys remain separate verification work.\n\n## Verification and remaining limits\n\nThe source batch has independent review receipts, passing Apple playback/layout/source contracts and real tvOS/iOS/Apple Silicon macOS debug builds. The integrated Android suites passed **1,492 Full tests and 1,419 Play tests**, with no failures, errors or skipped tests. The native history/storage suite passed **21 tests** against the pinned upstream dependency without a local source override. Apple and both Android build lanes use one immutable, reviewed wrapper revision retaining the shipping add-on lifecycle changes.\n\nAndroid artifact gates verify callable JNI definitions, not just matching symbol names. They check both engines in both APKs and the Play AAB across all three ABIs, including ELF class, architecture, little-endian shared-object type and visible defined function exports. Package signing, exact tagged-source provenance, packaged versions, checksums and feed publication remain separate fail-closed release gates.\n\n**This is a beta with repaired failure paths, not a promise that every playback failure is gone.** Sustained DV/NNTP throughput, hardware HDR/audio output, frame pacing, physical pause/seek/source switching and Android process-death/remote behavior require fresh device receipts. The Mac shell and iPhone detail improvements do not finish every screen's visual work.\n\nAccount publication now requires exact persisted-row ownership, captured account/native admissions and separate authorized outbound history. Sharing a native UID or signed-out bucket is not sufficient evidence. The typed account-library path currently covers movie/series `tt…` and `tmdb:…` identities, not every custom anime provider ID.\n\n**Android upgrade boundary:** older unsynced add-on order/removal/addition records without an exact-owner marker remain quarantined rather than being assigned to whichever account signs in. They are retained on disk, not deleted; cloud sync can restore changes that reached the account, but cannot reconstruct an edit that was never uploaded. Reapply any such pending edits in this version. This is not a transparent migration of ambiguous legacy records.\n\nThe website's latest deployment passed its tests/build and live page readback. Its add-on heading no longer implies every account-saved item is already installed on every device, and QR approval no longer claims that the device has finished sign-in. Those checks do not establish a full live cross-device account journey or provider availability.\n\n## Please test\n\n- Resume from Continue Watching, pause and resume, seek backward, switch source/player and confirm the current episode and pause choice survive.\n- Start a new episode at 0:00, try automatic next episode and manual Next/Previous, and compare any source that previously remained blank or reconnecting.\n- Choose a subtitle, then Off, during recovery; confirm a late inventory cannot restore the prior choice.\n- On Mac, try all sidebar destinations, categorized Settings, Command-F, keyboard route shortcuts and Back/Escape inside a child screen.\n- On iPhone, test episode Watch, long labels and manually formatted source rows; on iPad confirm the source-list Play action remains.\n- On Android, test NZB indexers, ordered NNTP alternatives, disable/remove during a search, and a stale warm-result cancellation. Live provider throughput is not established by protocol fixtures.\n- Enable Android Trakt Continue Watching, open a queued episode, switch accounts or toggle during refresh, and test optional manual check-in and its explicit conflict action.\n- Reorder Home rails, export/import a backup and sync to another current client; test explicit library watch/unwatch and account switching without importing the previous account's history.\n- If a failure remains, export diagnostics promptly with the title, add-on/provider and preceding action so the initiating event is retained.\n\n## Install\n\n**Apple TV.** Use `VortX-tvOS-v0.4.0-beta.18-ci.ipa` for Full or `VortX-tvOS-lite-v0.4.0-beta.18-ci.ipa` for Lite through your usual signing service.\n\n**iPhone and iPad.** Use `VortX-iOS-v0.4.0-beta.18-ci.ipa`. Distribution IPAs require re-signing through your usual installer. [Apple installation guide](https://github.com/VortXTV/VortX/wiki/Installing).\n\n**Mac.** Use `VortX-macOS-v0.4.0-beta.18-ci.dmg`. This is the Apple Silicon, ad-hoc-signed package rather than a notarized release. [Mac installation guide](https://github.com/VortXTV/VortX/wiki/Install-on-Mac).\n\n**Android.** Choose the signed APK appropriate to your preferred engine/distribution. Android checksums and signer evidence are in `SHA256SUMS-android.txt` and `SIGNING_PROVENANCE.txt`; Apple checksums are in `SHA256SUMS-ci.txt`.\n\nThis beta uses the **Latest beta** channel. Package integrity, Latest promotion and the live install/update feeds are verified separately; the GitHub label alone is not an update-feed receipt.\n\n<!-- vortx-build: 254 -->\n<!-- vortx-channel: latest-beta -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.18/VortX-iOS-v0.4.0-beta.18-ci.ipa",
          "size": 65723116,
          "sha256": "54837c4e490acbf02610193764dc92cdfbe14d32ad547171b72a838fec4652b8",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "253",
          "date": "2026-10-01",
          "localizedDescription": "Beta 17: resume recovery, binge playback, cancellable skip controls, subtitles, and Android fixes.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.17/VortX-iOS-v0.4.0-beta.17-ci.ipa",
          "size": 65679291,
          "sha256": "b01e3ae89a9e3d7b40cb374e1551557be0e367330a23ec2acb460f610b886278",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "252",
          "date": "2026-09-27",
          "localizedDescription": "# 0.4.0 Beta 16 - Dolby Vision buffering, player switches, and next-episode recovery\n\n**Install this over any earlier Apple build.** Beta 16 focuses on playback failures reported in diagnostics 21-24: Dolby Vision production stopping, replacement sources opening on the wrong player surface, stalled next-episode recovery, and Apple TV going idle during a player handoff. Apple build **252**. All Beta 15 changes are retained; these packages are built afresh from the reviewed source, not an older beta executable.\n\nThis is an **Apple-only update** for Apple TV, iPhone, iPad, and Apple Silicon Mac. Android remains on the signed Beta 14 packages linked below.\n\n## What's fixed\n\n**Dolby Vision's local rolling buffer no longer gives the same capacity to both rewind history and forward loading.** Both sides previously budgeted against the entire publication allowance independently. Together with the still-advertised previous playlist, that could fill the physical spool and block the next segment from being published. The allocation is now shared, with room for a segment already being closed. Advertised video and subtitle resources keep their validity deadlines; the fix does not prematurely delete segments AVPlayer is still allowed to request.\n\n**AVPlayer's preferred buffer is coupled to what the DV producer can actually supply.** When bitrate is known, the target uses the forward allocation rather than the whole rolling window. Very high-bitrate sources no longer retain an unconditional minimum that can exceed the affordable lead. Unknown-bitrate sources retain their existing behavior until usable measurements arrive. This repairs an app-side producer/player mismatch, not a supposed TorBox outage.\n\n**Changing source or episode keeps the accepted player and the current stream.** A replacement accepted on VortX Player could previously clear fallback state and rebuild an AVPlayer surface using the original launch episode. Both Apple playback surfaces now retain the accepted engine. An explicit player switch uses the active URL, request headers and content hints, not stale launch values. The original source stays separate from any local proxy URL.\n\n**Apple TV stays awake through playback recovery and engine changes.** Idle prevention now follows your Play/Pause choice rather than temporary native pause notifications while buffering or falling back. An outgoing player view cannot release the incoming view's keep-awake ownership. Callbacks tagged for a retired load cannot overwrite the current load's pause or buffering state. An actual viewer pause still remains a pause.\n\n**An empty next-episode source gets one recovery owner instead of competing retry loops.** A prepared URL that produces no video packets is marked exhausted. Its exact load can accept a late-arriving alternative within the bounded settlement window, while conflicting startup and same-URL retry timers are retired. Duplicate errors or EOF callbacks cannot reopen that dead URL. Source changes, episode changes, cancellation and your pause choice still win. If no usable alternative arrives, the error replaces the reconnecting spinner rather than leaving it spinning indefinitely.\n\n**Resume recovery no longer fights itself or enters the manual-seek cache hold.** The ordinary stall watchdog waits while the exact deferred-resume recovery owns an unconfirmed resume. Recovery nudges use the resume-specific seek path and a confirmed position; they do not arm the separate manual-scrub refill watchdog. A valid Continue Watching persistence floor is retained. This targets the confirmed recovery conflict, not every possible late native seek callback.\n\n**Seek-preview contribution stops rechecking unchanged work on every playback tick.** The overnight diagnostic contained thousands of identical upload-admission checks without any new captured frames. An unchanged title now rechecks when duration first becomes known, when new coverage is captured, or during teardown. New titles keep their own initial check. This removes redundant work and keeps useful playback evidence from being buried in repeated preview messages; it does not claim every source now has previews available.\n\n**Diagnostics distinguish local spool capacity from a source-read stall.** A bounded receipt records physical storage accounting and companion-resource bytes when admission waits. It excludes source URLs, credentials and account identifiers. A read stall alone is not labeled as provider downtime.\n\n## Retained from Beta 15\n\nThe previous repairs remain: fresh-episode opening checks, larger next-episode warm-prefix acceptance, viewer-owned pause during source replacement, paused-DV playlist recovery, early-EOF protection, physical-item completion ownership, seek refill protection, exact Continue Watching detail targets, first-episode-to-season focus, supported native-text subtitle styling and redacted hardware-decoder diagnostics. See the [Beta 15 notes](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.15) for the full preceding change list.\n\n## Android\n\n**There is no new Android APK in Beta 16.** Full/MPV and Play/Media3 remain in [Beta 14](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.14), version code **237**. Both variants include phone and Android TV interfaces. This Apple cut does not claim new Android playback, sync or interface-parity work. The separately recorded rapid-title-selection and update-feed work remains open; use the matching signed Beta 14 APK directly.\n\n## Verification and remaining limits\n\nAll 18,757 lines of diagnostic 24 were read, alongside the previous diagnostics and a retrieved device log. The overnight capture includes roughly 55 minutes of healthy Debridio/VortX Player playback with hardware decoding and zero sampled output/decoder drops. It does not contain the initiating AIOStreams/AVPlayer failure, so it cannot establish that the two add-ons selected identical files or request paths.\n\nRegression checks cover the real spool and retained-resource deadlines, producer/buffer coupling, source and episode ownership, empty-source settlement, resume recovery, idle-owner replacement and preview admission. Independent reviewers inspected the actual changes. The release lane builds fresh packages and checks production engine provenance, simulator launch, package contents and update feeds before publishing.\n\n**These are concrete app-side repairs, not a declaration that every playback issue is gone.** Physical-TV testing of this build is still needed for long-running DV, AIOStreams player switches and next episodes. Unusually large segments can still encounter finite storage admission, and this release does not add an unbounded cache, force software decoding, replace DV with HDR10, or claim sustained NNTP throughput has been solved. The separate sync, phone/Mac redesign and Android parity backlog is not bundled into this playback release.\n\n## Please test\n\n- Play a DV title beyond several rolling-window advances, then pause, resume and seek backward and forward.\n- Switch between AVPlayer and VortX Player on an AIOStreams source. Confirm the same title, episode, position and your Play/Pause choice survive.\n- Start a series from Continue Watching and try both automatic advance and the next-episode button. Include a source that previously opened blank or remained reconnecting.\n- Leave playback running through an AVPlayer-to-VortX recovery beyond the TV's usual screensaver interval. Confirm the TV stays awake while video is playing.\n- If a failure remains, export the diagnostic shortly afterward so the initial cause is retained. Include the source/add-on and whether it followed pause, seek, an engine switch or an episode transition.\n\n## Install\n\n**Apple TV.** Use `VortX-tvOS-v0.4.0-beta.16-ci.ipa` for Full or `VortX-tvOS-lite-v0.4.0-beta.16-ci.ipa` for Lite. Install the same variant you normally use through your signing service.\n\n**iPhone and iPad.** Use `VortX-iOS-v0.4.0-beta.16-ci.ipa`. [Apple sideloading instructions](https://github.com/VortXTV/VortX/wiki/Installing) and the [VortX install feed](https://raw.githubusercontent.com/VortXTV/VortX/main/altstore/source.json) are available for supported installers.\n\n**Mac.** Use `VortX-macOS-v0.4.0-beta.16-ci.dmg`. This is the Apple Silicon package, ad-hoc signed rather than notarized. Follow the [Mac installation guide](https://github.com/VortXTV/VortX/wiki/Install-on-Mac).\n\nCheck `SHA256SUMS-ci.txt`; the immutable tag, source commit and protected build provide provenance for these files. This beta is deliberately promoted to **Latest** with Apple update/install feeds verified during publication.\n\n<!-- vortx-build: 252 -->\n<!-- vortx-platforms: apple -->\n<!-- vortx-channel: latest-beta -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.16/VortX-iOS-v0.4.0-beta.16-ci.ipa",
          "size": 65534888,
          "sha256": "5680d0212ac14392d25cd25cc829b6b622389432ac0ad30535402b730ad7300b",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "251",
          "date": "2026-09-12",
          "localizedDescription": "# 0.4.0 Beta 15 - Episode handoffs, paused Dolby Vision, and playback recovery\n\n**Install this over any earlier Apple build.** Beta 15 brings together the Apple playback work tested in local builds 248-250, plus a new guard for next episodes starting several seconds into the video. Apple build **251**. All Beta 14 changes are retained; no earlier executable or release package has been substituted.\n\nThis is an **Apple-only update** for Apple TV, iPhone, iPad, and Apple Silicon Mac. Android remains on the signed Beta 14 packages described below.\n\n## What's fixed\n\n**Next episodes no longer accept an unexpected multi-second opening as a normal start.** A device diagnostic showed a fresh episode committing at 4.046 seconds despite a zero resume point and auto-skip being off. The new check intercepts that first position before it can update the episode identity or watch progress, and makes one precise return to the opening on the already-running player. It does not restart the stream or change your pause state. Genuine resume points, live streams, and your own seeks stay in charge. If the correction cannot reach the opening, the app reports a source failure instead of quietly skipping ahead or repeatedly rewinding. This targets the observed next-episode handoff; the separate native decoder failure still needs device verification.\n\n**Next-episode preloading can retain the whole requested warm prefix.** The preloader requested the first 32 MiB but its response-size validator could reject that same valid response. The limit now matches the request. This removes a specific reason prepared streams were discarded and had to start cold; it is not a promise that every Usenet source can prepare instantly on every server.\n\n**Changing or recovering a source no longer introduces its own hidden Pause.** An implementation pause used while rejecting or retiring a source could survive an in-place player replacement, leaving the new source frozen despite having data. That synthetic pause is removed. An actual viewer pause is still preserved, but is bound only after the replacement is accepted. A failed retiring engine's paused flag does not get mistaken for your choice. Rejected replacements retain the current load's state.\n\n**A paused Dolby Vision stream can recover an expired local HLS playlist without skipping the episode or immediately falling back.** The device trace identified a real conflict: while paused, the bounded local producer stopped adding segments, and AVFoundation eventually rejected the unchanged growing playlist. One failure callback previously bypassed the existing paused-recovery path. It now keeps same-mount recovery evidence and waits for Play. Duplicate failure callbacks coalesce, and existing position, track-selection and DV restoration stay attached to the current item. No fake segments or unbounded producer buffer have been added.\n\n**A producer finishing while you are paused does not mean you finished watching.** Recovery now distinguishes the producer's final playlist from the viewer's actual position. A retained position inside that finished playlist can resume; a real end remains an end, and an invalid or evicted position remains a source error. Retry budgets only re-arm after sustained real playback, not seek jumps or paused ticks, preventing repeated item-replacement loops.\n\n**A stream ending early cannot casually mark the episode watched and play the next one.** Both Apple playback surfaces now compare a decoder's EOF against load-owned position and known duration. An EOF far before the ending enters same-episode source recovery instead of completion handling. Recovery uses observed playback position, not an optimistic scrub target or old resume floor. Duplicate EOF callbacks cannot spend the recovery budget twice. True endings, live playback, trailers and unknown-duration sources keep their existing semantics. This addresses the premature-completion code gap examined alongside issue #223.\n\n**Replacement items do not inherit the previous item's completion evidence.** AVPlayer can recover a physical item while retaining the logical playback request. Completion evidence now also follows the physical item generation, so an old early-EOF rejection cannot prevent the recovered item from genuinely finishing later. Retired callbacks cannot finish a newer episode.\n\n**Apple TV's short backward/forward seeks receive the same refill protection as a scrub.** A relative seek outside the buffered window previously missed the existing refill hold and bounded recovery watchdog. It now uses that protection while retaining relative seek semantics and your latest Pause/Play choice. In-buffer seeks do not unnecessarily invoke the cold-refill path.\n\n**Continue Watching keeps the episode you actually opened when it needs to show Details.** Local CW navigation on Apple TV and iPhone now carries the exact episode ID and resume point into the detail page. An episode with a zero resume point is still a valid selection; it does not fall back to an unwatched special such as S0E1. After you successfully play a newer episode, that newer local receipt supersedes the older navigation hint. If a partial episode list does not yet contain the exact target, the hero waits rather than inventing a different episode.\n\n**The phone's resume offset must belong to its selected episode.** The detail hero no longer applies an offset from one episode to a different selected episode. This matches the existing episode-identity check on Apple TV.\n\n**Up from the first episode returns to the selected season.** On Apple TV, that move now explicitly reveals and focuses the current season chip instead of jumping to the hero or making you navigate back down from Play. Down from the first episode still moves to the second; deeper episode rows retain their normal navigation.\n\n**Supported native AVPlayer WebVTT subtitles can follow the in-player appearance settings.** Their timed text can now use the existing VortX subtitle overlay, so outline, shaded and box styles are app-controlled. The native renderer is suppressed before supported text is displayed, and cues replace rather than accumulate. Seeks, subtitle changes, item replacements and close clear or fence stale cues. Unsupported or bitmap captions remain native; Picture in Picture and AirPlay retain native captions. This does not change the device's system caption settings or claim styling support for every subtitle format.\n\n**Diagnostics preserve useful decoder failure reasons without exporting raw decoder traffic.** Probe-enabled release builds now retain bounded, allowlisted VideoToolbox failure categories, including bad frame status, no-output callbacks, session/format failure and waiting for a keyframe. Signed stream links, request headers and arbitrary log text are excluded. This helps distinguish a native decoding failure from an output-frame drop or an empty network cache.\n\n## Android\n\n**There is no new Android APK in Beta 15.** The current Full/MPV and Play/Media3 packages remain in [Beta 14](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.14), version code **237**. Both variants include phone and Android TV interfaces. Their existing fixes are retained; this Apple release does not claim new Android playback or parity work.\n\nThe separately recorded Android rapid-title-selection race and Android update-feed correction remain open. Use the matching Beta 14 APK directly while that feed still serves the older entry.\n\n## Verification and remaining limits\n\nThe Apple completion, Continue Watching target, focus, resume/seek, source handoff, subtitle and diagnostic policies have executable regression coverage. Independent source review accompanies the changes; the release workflow builds and verifies fresh Apple packages, engine pins, signing/provenance and update feeds before publication.\n\nThe fresh-origin recovery was also exercised against the exact bundled GPL playback libraries with VideoToolbox, GPU-next/MoltenVK and AVFoundation audio. A controlled 4.046-second initial position returned to zero while playing and while paused, without changing the pause state. The matching source itself contains timestamps starting at zero.\n\n**These are specific repairs, not a claim that every playback problem is solved.** The physical Apple TV's initial hardware-decoder failure has not been reproduced on the Mac, and broader active-play DV stalls, provider-specific buffering and sustained NNTP throughput still need live-device testing. This release does not force software decoding, remove Dolby Vision, or disguise a failed source as a completed episode. The broader Android parity and phone/Mac redesign work is not bundled into this playback cut.\n\n## Please test\n\n- Let a series advance automatically and use the next-episode button. Confirm the opening is shown, the selected episode is correct, and watch progress belongs to that episode.\n- Pause a DV/AVPlayer title long enough for the local producer to stop filling, then resume. Confirm it stays paused until Play and recovers the same episode and selections.\n- Seek backward and forward both inside and outside the buffered window, including while paused.\n- Open Family Guy or another series from CW. If Details opens, confirm it targets the current episode instead of an unwatched special. From the first episode, press Up once to reach the season selector.\n- With supported built-in AVPlayer text subtitles, compare outline and box appearance. Include the subtitle format and a diagnostic if it remains native or ignores styling.\n\n## Install\n\n**Apple TV.** Use `VortX-tvOS-v0.4.0-beta.15-ci.ipa` for Full or `VortX-tvOS-lite-v0.4.0-beta.15-ci.ipa` for Lite. Install the same variant you normally use through your signing service.\n\n**iPhone and iPad.** Use `VortX-iOS-v0.4.0-beta.15-ci.ipa`. [Apple sideloading instructions](https://github.com/VortXTV/VortX/wiki/Installing) and the [VortX install feed](https://raw.githubusercontent.com/VortXTV/VortX/main/altstore/source.json) are available for supported installers.\n\n**Mac.** Download `VortX-macOS-v0.4.0-beta.15-ci.dmg`, drag VortX into Applications, and use **System Settings > Privacy & Security > Open Anyway** if needed. This is the Apple Silicon package, ad-hoc signed rather than notarized. [Mac installation guide](https://github.com/VortXTV/VortX/wiki/Install-on-Mac).\n\nCheck `SHA256SUMS-ci.txt`; the immutable tag, source commit, and protected release workflow provide provenance for the published Apple files. This beta is deliberately promoted to **Latest**; Apple update and install feeds are verified as part of publication.\n\n<!-- vortx-build: 251 -->\n<!-- vortx-platforms: apple -->\n<!-- vortx-channel: latest-beta -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.15/VortX-iOS-v0.4.0-beta.15-ci.ipa",
          "size": 65529125,
          "sha256": "7730fd8489c109e413bad11119f9f5b96ebee7b8bbb13b9f959d44c2b4e0c31d",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "247",
          "date": "2026-09-11",
          "localizedDescription": "Apple playback, source controls and episode artwork repairs; Android audio, remote, Discover and title-relation improvements; profile-specific collection visibility.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.14/VortX-iOS-v0.4.0-beta.14-ci.ipa",
          "size": 65500086,
          "sha256": "bc5d4af376778faea57e8d56983df7a1cd1954c00be0c2ea42af7fe1cc5d760b",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "245",
          "date": "2026-09-11",
          "localizedDescription": "Apple build 245: playback recovery, add-on order and sync, artwork, prioritized Usenet and NZB indexers.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.12/VortX-iOS-v0.4.0-beta.12-ci.ipa",
          "size": 65471776,
          "sha256": "bcb72cd2c722dad64b624e8bf03c22b9e363810a8953c612e3bec846c6291e2a",
          "minOSVersion": "16.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "243",
          "date": "2026-09-06",
          "localizedDescription": "Apple Beta 10: Continue Watching episodes, pause and seek recovery, NNTP streaming repairs, and DV integrity checks.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.10/VortX-iOS-v0.4.0-beta.10-ci.ipa",
          "size": 65224079,
          "sha256": "4f8693b7bc4680a2b7777cfd6580bf89551774d9dbf4aa71835940720b09ab13",
          "minOSVersion": "16.0"
        }
      ]
    },
    {
      "name": "VortX (Apple TV)",
      "bundleIdentifier": "com.stremiox.tv",
      "developerName": "Mamaclapper",
      "subtitle": "Stream movies and shows on Apple TV.",
      "localizedDescription": "VortX for Apple TV: a native, open-source streaming app on the official stremio-core engine and the libmpv player, with an in-process streaming server for torrents. HDR and Dolby Vision, Dolby Atmos passthrough, stream ranking, in-app add-ons and debrid keys, Top Shelf, and more. This source delivers one-tap updates so you never sideload an IPA by hand.",
      "iconURL": "https://raw.githubusercontent.com/VortXTV/VortX/main/docs/logo.png",
      "tintColor": "C8A24B",
      "category": "entertainment",
      "screenshotURLs": [],
      "versions": [
        {
          "version": "0.4.0",
          "buildVersion": "258",
          "date": "2026-10-03",
          "localizedDescription": "Apple build 258: repaired iPhone/iPad startup, cleaner touch player, real Wave seek styles, pinch Fit/Fill, clear add-on tabs and unobscured navigation/Search.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.20/VortX-tvOS-v0.4.0-beta.20-ci.ipa",
          "size": 65323795,
          "sha256": "51c7845b3017e719de1dd99f4d89f2299dd3a6d58186d92899258caa8d9fb011",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "254",
          "date": "2026-10-01",
          "localizedDescription": "# 0.4.0 Beta 18 - Playback settlement, Mac redesign, Android Usenet, and account sync\n\n**Install this over any earlier build.** Beta 18 brings together the reviewed changes since Beta 17 for Apple TV, iPhone, iPad, Apple Silicon Mac, Android phones and Android TV. It retains the preceding playback, binge-watching, automatic-skip and subtitle repairs. Apple build **254**, Android version code **239**. Package versions, signing, checksums and Latest promotion are separate checks before publication.\n\n## What's new\n\n**A native Mac sidebar and in-window Settings.** Home, Discover, Live, Library, Search, Add-ons and Settings now have persistent sidebar destinations. Settings opens inside the app with categorized navigation rather than an oversized floating phone-style sheet. Search remains available in the shell; Command-F and the Go menu route to it. Keyboard shortcuts select destinations, Escape returns focus to the shell when appropriate without stealing a child screen's Back action, and transitions respect Reduce Motion. This is an implemented native shell, not a claim that every Mac screen has received its final visual redesign.\n\n**Direct NZB indexers on Android.** Save and manage Newznab-compatible HTTPS indexers, including NZBGeek, and search them from normal movie and selected-episode source lists. Credentials are encrypted and scoped to the account and profile. Editing, disabling, removing or switching configuration invalidates old requests; a finished search cannot publish stale results into source selection or next-episode preparation. Configuration survives a new session for the same account/profile instead of being keyed to a temporary generation.\n\n**Multiple Android Usenet servers with priority and fallback.** Save, edit, disable, remove and prioritize NNTP servers on phone and TV. Existing single-server settings migrate. Configured routes use the shared resolver rather than an unconnected settings screen. The local provider loop tries the configured alternatives and retains the existing cloud path when separately configured. TorBox cloud preparation still requires its API key and may prepare an uncached job; this is not a guarantee of immediate playback from every article or provider.\n\n**Trakt Continue Watching on Android.** An optional, read-only Home rail loads Trakt's movie and episode playback queues, resolves artwork, and carries the exact series, season and episode into detail navigation. It is Off by default and does not turn imported Trakt progress into synthetic native watched history. Both playback lists must succeed before a new complete cache is published. A same-owner fetch failure can retain the last successful rail.\n\n**Manual Trakt check-in from Android detail pages.** The optional action follows the primary movie or selected episode on phone and TV. It requires the owner profile and manual-check-in opt-in. Duplicate taps are blocked; authentication, profile, title and episode changes reject old results. A conflicting active check-in is not silently replaced: the app offers an explicit “Check in here” action. Manual check-in does not mark the title watched. Apple's check-in chip also re-evaluates the stored session at the authentication boundary while retaining its episode and opt-in requirements.\n\n**Phone Library segments and TV add-on reordering.** Android phone and TV share All, Movies, Shows and Anime segments and their applicable smart filters. Native sorting is retained; the app does not invent genre metadata to populate those filters. Android TV add-on ordering has remote-friendly move controls, and configured Usenet/indexer routes are reachable through TV Settings with normal Back behavior.\n\n## What's fixed\n\n**AVPlayer recovery settles against the current item and the viewer's transport choice.** Recovery seeks have an explicit owner, accepted landing and bounded repair result. A newer seek, source change or player replacement retires the older recovery. An accepted small forward remux landing is normalized to its actual local origin, avoiding a repeated remount loop. A false seek completion or deadline consumes a concrete repair target instead of leaving a ticket silently unresolved. If a ready callback synchronously replaces the item, the retired callback cannot apply tracks, Play/Pause or startup state to the replacement. A paused recovery remains paused until the viewer resumes it.\n\n**VortX Player cache maintenance no longer drops playback before its seek runs.** A complete overnight TV diagnostic showed repeated cache trims followed by a false end-of-file, a failed high-position resume and a restart around nine seconds. The queued buffer-drop and seek were not an atomic transport operation in the shipped player. Maintenance now requests the low-level seek without first resetting the decoder, keeps its temporary cache option until an owned seek receipt settles, and requires an increased low-level-seek counter plus a compatible landing before reporting success. One bounded reissue handles the demux thread's option-adoption race; a timeout is a failure, not a completed trim. Memory-pressure and background cache limits remain in force.\n\n**Paused replacement playback keeps its target and the viewer's choice.** A repair's temporary engine pause is no longer mistaken for the viewer pressing Pause. A paused reopen waits for the exact replacement file and its duration before deciding whether to seek or clear a target, and retains the seek obligation if command admission fails. An early zero-position tick cannot settle a high-position restoration. Stale callbacks carry their original maintenance attempt rather than adopting a later operation.\n\n**Late subtitle discovery cannot resurrect an old selection.** External-subtitle selection settles independently against its owned item and inventory. Explicit choices and Off supersede pending restoration; outgoing and late callbacks cannot restore an older track. Native subtitle single-renderer and background-style handling from earlier betas remain. Authored bitmap styling and system accessibility overrides are still separate limits, not evidence of duplicate-renderer closure on every file.\n\n**The iPhone episode Watch action sits at the hero seam.** Portrait phones retain the large cinematic hero, place the real selected-episode Watch action across its bottom edge and wrap long action text without the narrow vertical-letter collapse. Manual quality, language and player controls remain below it, and source rows preserve add-on-authored formatting. The phone-only overlap is limited to finite portrait phone widths; iPad and Mac retain their source-list Play action rather than losing it through a shared layout change.\n\n**Android Usenet admission uses decoded article evidence.** Whole-file sizing and multipart coverage come from validated yEnc headers, not a sum of estimated article sizes. Invalid, overlapping or incomplete ranges cannot be admitted as complete cached media. Loopback binding happens inside the provider attempt: a bind failure cleans up the session and advances fallback. Cancellation and a configuration/account change after readiness dispose the producer and loopback registration instead of leaving a stale playable URL behind. Credential and provider-document locking use one consistent order.\n\n**Trakt episode intent survives metadata and owner reloads.** Android routes the typed episode hint rather than parsing a display caption. A valid manual selection takes precedence, then the matching Trakt target, then the existing native primary-episode policy. If an interim owner has no matching episode, the original intent remains available when returning to the previous owner. In-player intent changes only after an episode switch is accepted.\n\n**Android filmography opens the latest title selected.** A second tap during a slow title lookup now cancels and supersedes the first instead of being ignored. Back and screen disposal invalidate pending navigation immediately on both phone and TV; an old completion cannot open a title after leaving the page.\n\n**Old Trakt responses cannot repopulate a new account's Home rail.** Requests carry the exact Trakt session epoch, toggle revision and cache generation. Network and artwork work run outside the cache lock. Clear invalidates immediately, including while a fetch is pending. Home clears visible personalized rows before awaiting provider cleanup and checks the receipt again immediately before assignment. Turning the feature off and on cannot admit an old request just because the account name is unchanged.\n\n**Home rail order travels through account sync and backup.** Ordered rail IDs use the same ordered array shape across Apple and Android. Hidden rails remain a string set and layout remains a string. Android converts its local JSON string representation at the account/backup boundary, retains unknown rail IDs in order, reads legacy Android backups and skips malformed values without wiping a valid local arrangement. Local dirty settings are protected from an older pull. Per-profile catalog order stays profile-scoped rather than being flattened into one global arrangement.\n\n**Account add-on changes respect both native ownership and the VortX session.** A delayed install, removal or reorder cannot run under a replacement account merely because the native Stremio UID happens to be the same. Accepted account descriptors enter the actual native gateway, and routine reads cannot acknowledge or replace a newer local order edit. The earlier no-shrink roster, removal/reinstall, local-only mirroring and source-group ordering protections are retained.\n\n**An asynchronous remove/re-add keeps its history ownership.** Android waits for the exact native result of the original account-owned operation instead of assuming its immediate disk read already includes the change. A later re-add, including an authenticated metadata-only account update, continues that captured transition. Failed proof storage cannot be reported as successful publication.\n\n**Android owner-library events have a real native read and restore path.** Account sync now distinguishes library membership from genuine history. Exact title type, current video, position, duration, event timestamp, nullable viewing timestamp, watched bitfield, per-video watched state, count and movie-only whole-title state travel through a receipt-checked batch. Genuinely newer events can update an already-present identity; a metadata-only read cannot overwrite peer progress. Zero progress is valid and is not replaced with a fabricated current viewing time. Partial series progress is not promoted to a fictional whole-series watched flag. Manual movie unwatch retains explicit evidence even when the movie has no viewing timestamp.\n\n**Failed history restoration cannot advance the account's accepted version.** Native and account admission are checked again at dispatch, including a fresh native LWW read. Null, wrong-owner, duplicate, incomplete or mismatched receipts are rejected. Opaque peer fields are preserved rather than “repaired” from an unclocked local snapshot. Real local progress, playback completion and watched/library actions arm the durable debounced account push instead of depending on an app restart.\n\n**Manual watched actions and genuine playback history have separate cross-client carriers.** Apple and Android use the same owner-profile history array for real viewing events, including unsaved titles, without turning Continue Watching into Saved library membership. Watched/unwatched intent remains separately clocked. Sparse Apple events inherit optional fields only from proven same-owner state; malformed, unsupported and oversized peer sections are preserved rather than flattened. Secondary profiles with their own accounts cannot export their history into the main owner's carrier.\n\n**Adding a title cannot erase another device's resume position.** The native library constructor stamps a newly saved title with the current time even before viewing it. That metadata-only clock is no longer treated as a newer viewing event on either side of reconciliation. Genuine zero rewinds and completed playback remain valid, and unknown peer fields survive a metadata refresh.\n\n**A later library edit cannot block a newer real resume.** Android and its native bridge now distinguish an owned playback event from the row's later membership/persistence timestamp. A conditional restore requires the complete, freshly matching account-owned state and a genuinely newer viewing event. It retains the real viewing time and the existing membership time separately; it does not manufacture a later event to satisfy the engine. Changed, unknown or foreign rows keep the stricter original admission rule. The same rule covers a proven pristine newly saved title whose constructor timestamp is not viewing evidence.\n\n**A library removal belongs to the account that made it.** Removal/reinstall stamps use account-specific durable stores and captured revisions. Switching A to B and back invalidates the old A handle while restoring A's own saved stamps. Unassigned legacy data is not adopted by whichever account signs in next. Queued typed library actions capture the account, native owner and removal capability before their first dispatcher suspension; an A action cannot begin its queued body as B. The final upload filter removes only recognized removed identities and retains unknown objects, arrays, scalars and nulls from peer documents.\n\n## Retained from Beta 17\n\nThe configurable automatic intro/credits skip countdown with Off and Cancel, source-owned watch suggestions, real first-frame admission at 0:00, failed-resume retirement across replacement chains, player/source/prewarm lifecycle ownership, independent audio/subtitle restoration, file-matched add-on subtitle requests, Trakt and Top Shelf artwork, bounded batch metadata recovery, recoverable opt-in watched-download cleanup, web source paging/skip parsing and artifact-bound Android update metadata remain. See the [Beta 17 notes](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.17) and their retained Beta 16 list for the preceding repairs.\n\n## Android\n\nThis candidate includes source for both signed distribution variants. Both contain the phone and Android TV interfaces and the three shipped ABIs: arm64-v8a, armeabi-v7a and x86_64.\n\n- `VortX-0.4.0-full-mpv-universal.apk`: the sideloaded VortX/MPV build with Media3 fallback.\n- `VortX-0.4.0-play-media3-universal.apk`: the GPL-native-free Media3 build.\n- `VortX-0.4.0-play-media3.aab`: the matching Play distribution bundle, not an installable APK.\n\nThe direct NZB/Usenet, Library, Trakt and remote-ordering work closes concrete feature gaps. It does **not** establish 100% visual or functional parity with Apple, physical Shield/Fire TV compatibility, or a complete redesign of every Android page. Broader detail/hero composition and live remote journeys remain separate verification work.\n\n## Verification and remaining limits\n\nThe source batch has independent review receipts, passing Apple playback/layout/source contracts and real tvOS/iOS/Apple Silicon macOS debug builds. The integrated Android suites passed **1,492 Full tests and 1,419 Play tests**, with no failures, errors or skipped tests. The native history/storage suite passed **21 tests** against the pinned upstream dependency without a local source override. Apple and both Android build lanes use one immutable, reviewed wrapper revision retaining the shipping add-on lifecycle changes.\n\nAndroid artifact gates verify callable JNI definitions, not just matching symbol names. They check both engines in both APKs and the Play AAB across all three ABIs, including ELF class, architecture, little-endian shared-object type and visible defined function exports. Package signing, exact tagged-source provenance, packaged versions, checksums and feed publication remain separate fail-closed release gates.\n\n**This is a beta with repaired failure paths, not a promise that every playback failure is gone.** Sustained DV/NNTP throughput, hardware HDR/audio output, frame pacing, physical pause/seek/source switching and Android process-death/remote behavior require fresh device receipts. The Mac shell and iPhone detail improvements do not finish every screen's visual work.\n\nAccount publication now requires exact persisted-row ownership, captured account/native admissions and separate authorized outbound history. Sharing a native UID or signed-out bucket is not sufficient evidence. The typed account-library path currently covers movie/series `tt…` and `tmdb:…` identities, not every custom anime provider ID.\n\n**Android upgrade boundary:** older unsynced add-on order/removal/addition records without an exact-owner marker remain quarantined rather than being assigned to whichever account signs in. They are retained on disk, not deleted; cloud sync can restore changes that reached the account, but cannot reconstruct an edit that was never uploaded. Reapply any such pending edits in this version. This is not a transparent migration of ambiguous legacy records.\n\nThe website's latest deployment passed its tests/build and live page readback. Its add-on heading no longer implies every account-saved item is already installed on every device, and QR approval no longer claims that the device has finished sign-in. Those checks do not establish a full live cross-device account journey or provider availability.\n\n## Please test\n\n- Resume from Continue Watching, pause and resume, seek backward, switch source/player and confirm the current episode and pause choice survive.\n- Start a new episode at 0:00, try automatic next episode and manual Next/Previous, and compare any source that previously remained blank or reconnecting.\n- Choose a subtitle, then Off, during recovery; confirm a late inventory cannot restore the prior choice.\n- On Mac, try all sidebar destinations, categorized Settings, Command-F, keyboard route shortcuts and Back/Escape inside a child screen.\n- On iPhone, test episode Watch, long labels and manually formatted source rows; on iPad confirm the source-list Play action remains.\n- On Android, test NZB indexers, ordered NNTP alternatives, disable/remove during a search, and a stale warm-result cancellation. Live provider throughput is not established by protocol fixtures.\n- Enable Android Trakt Continue Watching, open a queued episode, switch accounts or toggle during refresh, and test optional manual check-in and its explicit conflict action.\n- Reorder Home rails, export/import a backup and sync to another current client; test explicit library watch/unwatch and account switching without importing the previous account's history.\n- If a failure remains, export diagnostics promptly with the title, add-on/provider and preceding action so the initiating event is retained.\n\n## Install\n\n**Apple TV.** Use `VortX-tvOS-v0.4.0-beta.18-ci.ipa` for Full or `VortX-tvOS-lite-v0.4.0-beta.18-ci.ipa` for Lite through your usual signing service.\n\n**iPhone and iPad.** Use `VortX-iOS-v0.4.0-beta.18-ci.ipa`. Distribution IPAs require re-signing through your usual installer. [Apple installation guide](https://github.com/VortXTV/VortX/wiki/Installing).\n\n**Mac.** Use `VortX-macOS-v0.4.0-beta.18-ci.dmg`. This is the Apple Silicon, ad-hoc-signed package rather than a notarized release. [Mac installation guide](https://github.com/VortXTV/VortX/wiki/Install-on-Mac).\n\n**Android.** Choose the signed APK appropriate to your preferred engine/distribution. Android checksums and signer evidence are in `SHA256SUMS-android.txt` and `SIGNING_PROVENANCE.txt`; Apple checksums are in `SHA256SUMS-ci.txt`.\n\nThis beta uses the **Latest beta** channel. Package integrity, Latest promotion and the live install/update feeds are verified separately; the GitHub label alone is not an update-feed receipt.\n\n<!-- vortx-build: 254 -->\n<!-- vortx-channel: latest-beta -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.18/VortX-tvOS-v0.4.0-beta.18-ci.ipa",
          "size": 65323426,
          "sha256": "96a4e5e1ccadbd62aa19d4522f598828029dc6cb71fac2a13b1101c577453bd3",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "253",
          "date": "2026-10-01",
          "localizedDescription": "Beta 17: resume recovery, binge playback, cancellable skip controls, subtitles, and Android fixes.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.17/VortX-tvOS-v0.4.0-beta.17-ci.ipa",
          "size": 65270673,
          "sha256": "aba43949b0cb7e5cdf7d94f3a71b49b74b8869eb945a0e740600bc6d4a1a61af",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "252",
          "date": "2026-09-27",
          "localizedDescription": "# 0.4.0 Beta 16 - Dolby Vision buffering, player switches, and next-episode recovery\n\n**Install this over any earlier Apple build.** Beta 16 focuses on playback failures reported in diagnostics 21-24: Dolby Vision production stopping, replacement sources opening on the wrong player surface, stalled next-episode recovery, and Apple TV going idle during a player handoff. Apple build **252**. All Beta 15 changes are retained; these packages are built afresh from the reviewed source, not an older beta executable.\n\nThis is an **Apple-only update** for Apple TV, iPhone, iPad, and Apple Silicon Mac. Android remains on the signed Beta 14 packages linked below.\n\n## What's fixed\n\n**Dolby Vision's local rolling buffer no longer gives the same capacity to both rewind history and forward loading.** Both sides previously budgeted against the entire publication allowance independently. Together with the still-advertised previous playlist, that could fill the physical spool and block the next segment from being published. The allocation is now shared, with room for a segment already being closed. Advertised video and subtitle resources keep their validity deadlines; the fix does not prematurely delete segments AVPlayer is still allowed to request.\n\n**AVPlayer's preferred buffer is coupled to what the DV producer can actually supply.** When bitrate is known, the target uses the forward allocation rather than the whole rolling window. Very high-bitrate sources no longer retain an unconditional minimum that can exceed the affordable lead. Unknown-bitrate sources retain their existing behavior until usable measurements arrive. This repairs an app-side producer/player mismatch, not a supposed TorBox outage.\n\n**Changing source or episode keeps the accepted player and the current stream.** A replacement accepted on VortX Player could previously clear fallback state and rebuild an AVPlayer surface using the original launch episode. Both Apple playback surfaces now retain the accepted engine. An explicit player switch uses the active URL, request headers and content hints, not stale launch values. The original source stays separate from any local proxy URL.\n\n**Apple TV stays awake through playback recovery and engine changes.** Idle prevention now follows your Play/Pause choice rather than temporary native pause notifications while buffering or falling back. An outgoing player view cannot release the incoming view's keep-awake ownership. Callbacks tagged for a retired load cannot overwrite the current load's pause or buffering state. An actual viewer pause still remains a pause.\n\n**An empty next-episode source gets one recovery owner instead of competing retry loops.** A prepared URL that produces no video packets is marked exhausted. Its exact load can accept a late-arriving alternative within the bounded settlement window, while conflicting startup and same-URL retry timers are retired. Duplicate errors or EOF callbacks cannot reopen that dead URL. Source changes, episode changes, cancellation and your pause choice still win. If no usable alternative arrives, the error replaces the reconnecting spinner rather than leaving it spinning indefinitely.\n\n**Resume recovery no longer fights itself or enters the manual-seek cache hold.** The ordinary stall watchdog waits while the exact deferred-resume recovery owns an unconfirmed resume. Recovery nudges use the resume-specific seek path and a confirmed position; they do not arm the separate manual-scrub refill watchdog. A valid Continue Watching persistence floor is retained. This targets the confirmed recovery conflict, not every possible late native seek callback.\n\n**Seek-preview contribution stops rechecking unchanged work on every playback tick.** The overnight diagnostic contained thousands of identical upload-admission checks without any new captured frames. An unchanged title now rechecks when duration first becomes known, when new coverage is captured, or during teardown. New titles keep their own initial check. This removes redundant work and keeps useful playback evidence from being buried in repeated preview messages; it does not claim every source now has previews available.\n\n**Diagnostics distinguish local spool capacity from a source-read stall.** A bounded receipt records physical storage accounting and companion-resource bytes when admission waits. It excludes source URLs, credentials and account identifiers. A read stall alone is not labeled as provider downtime.\n\n## Retained from Beta 15\n\nThe previous repairs remain: fresh-episode opening checks, larger next-episode warm-prefix acceptance, viewer-owned pause during source replacement, paused-DV playlist recovery, early-EOF protection, physical-item completion ownership, seek refill protection, exact Continue Watching detail targets, first-episode-to-season focus, supported native-text subtitle styling and redacted hardware-decoder diagnostics. See the [Beta 15 notes](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.15) for the full preceding change list.\n\n## Android\n\n**There is no new Android APK in Beta 16.** Full/MPV and Play/Media3 remain in [Beta 14](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.14), version code **237**. Both variants include phone and Android TV interfaces. This Apple cut does not claim new Android playback, sync or interface-parity work. The separately recorded rapid-title-selection and update-feed work remains open; use the matching signed Beta 14 APK directly.\n\n## Verification and remaining limits\n\nAll 18,757 lines of diagnostic 24 were read, alongside the previous diagnostics and a retrieved device log. The overnight capture includes roughly 55 minutes of healthy Debridio/VortX Player playback with hardware decoding and zero sampled output/decoder drops. It does not contain the initiating AIOStreams/AVPlayer failure, so it cannot establish that the two add-ons selected identical files or request paths.\n\nRegression checks cover the real spool and retained-resource deadlines, producer/buffer coupling, source and episode ownership, empty-source settlement, resume recovery, idle-owner replacement and preview admission. Independent reviewers inspected the actual changes. The release lane builds fresh packages and checks production engine provenance, simulator launch, package contents and update feeds before publishing.\n\n**These are concrete app-side repairs, not a declaration that every playback issue is gone.** Physical-TV testing of this build is still needed for long-running DV, AIOStreams player switches and next episodes. Unusually large segments can still encounter finite storage admission, and this release does not add an unbounded cache, force software decoding, replace DV with HDR10, or claim sustained NNTP throughput has been solved. The separate sync, phone/Mac redesign and Android parity backlog is not bundled into this playback release.\n\n## Please test\n\n- Play a DV title beyond several rolling-window advances, then pause, resume and seek backward and forward.\n- Switch between AVPlayer and VortX Player on an AIOStreams source. Confirm the same title, episode, position and your Play/Pause choice survive.\n- Start a series from Continue Watching and try both automatic advance and the next-episode button. Include a source that previously opened blank or remained reconnecting.\n- Leave playback running through an AVPlayer-to-VortX recovery beyond the TV's usual screensaver interval. Confirm the TV stays awake while video is playing.\n- If a failure remains, export the diagnostic shortly afterward so the initial cause is retained. Include the source/add-on and whether it followed pause, seek, an engine switch or an episode transition.\n\n## Install\n\n**Apple TV.** Use `VortX-tvOS-v0.4.0-beta.16-ci.ipa` for Full or `VortX-tvOS-lite-v0.4.0-beta.16-ci.ipa` for Lite. Install the same variant you normally use through your signing service.\n\n**iPhone and iPad.** Use `VortX-iOS-v0.4.0-beta.16-ci.ipa`. [Apple sideloading instructions](https://github.com/VortXTV/VortX/wiki/Installing) and the [VortX install feed](https://raw.githubusercontent.com/VortXTV/VortX/main/altstore/source.json) are available for supported installers.\n\n**Mac.** Use `VortX-macOS-v0.4.0-beta.16-ci.dmg`. This is the Apple Silicon package, ad-hoc signed rather than notarized. Follow the [Mac installation guide](https://github.com/VortXTV/VortX/wiki/Install-on-Mac).\n\nCheck `SHA256SUMS-ci.txt`; the immutable tag, source commit and protected build provide provenance for these files. This beta is deliberately promoted to **Latest** with Apple update/install feeds verified during publication.\n\n<!-- vortx-build: 252 -->\n<!-- vortx-platforms: apple -->\n<!-- vortx-channel: latest-beta -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.16/VortX-tvOS-v0.4.0-beta.16-ci.ipa",
          "size": 65128621,
          "sha256": "4ede3e867cfbbe77cb42893966b4c894724c1655aeeee0775c253e13a2403938",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "251",
          "date": "2026-09-12",
          "localizedDescription": "# 0.4.0 Beta 15 - Episode handoffs, paused Dolby Vision, and playback recovery\n\n**Install this over any earlier Apple build.** Beta 15 brings together the Apple playback work tested in local builds 248-250, plus a new guard for next episodes starting several seconds into the video. Apple build **251**. All Beta 14 changes are retained; no earlier executable or release package has been substituted.\n\nThis is an **Apple-only update** for Apple TV, iPhone, iPad, and Apple Silicon Mac. Android remains on the signed Beta 14 packages described below.\n\n## What's fixed\n\n**Next episodes no longer accept an unexpected multi-second opening as a normal start.** A device diagnostic showed a fresh episode committing at 4.046 seconds despite a zero resume point and auto-skip being off. The new check intercepts that first position before it can update the episode identity or watch progress, and makes one precise return to the opening on the already-running player. It does not restart the stream or change your pause state. Genuine resume points, live streams, and your own seeks stay in charge. If the correction cannot reach the opening, the app reports a source failure instead of quietly skipping ahead or repeatedly rewinding. This targets the observed next-episode handoff; the separate native decoder failure still needs device verification.\n\n**Next-episode preloading can retain the whole requested warm prefix.** The preloader requested the first 32 MiB but its response-size validator could reject that same valid response. The limit now matches the request. This removes a specific reason prepared streams were discarded and had to start cold; it is not a promise that every Usenet source can prepare instantly on every server.\n\n**Changing or recovering a source no longer introduces its own hidden Pause.** An implementation pause used while rejecting or retiring a source could survive an in-place player replacement, leaving the new source frozen despite having data. That synthetic pause is removed. An actual viewer pause is still preserved, but is bound only after the replacement is accepted. A failed retiring engine's paused flag does not get mistaken for your choice. Rejected replacements retain the current load's state.\n\n**A paused Dolby Vision stream can recover an expired local HLS playlist without skipping the episode or immediately falling back.** The device trace identified a real conflict: while paused, the bounded local producer stopped adding segments, and AVFoundation eventually rejected the unchanged growing playlist. One failure callback previously bypassed the existing paused-recovery path. It now keeps same-mount recovery evidence and waits for Play. Duplicate failure callbacks coalesce, and existing position, track-selection and DV restoration stay attached to the current item. No fake segments or unbounded producer buffer have been added.\n\n**A producer finishing while you are paused does not mean you finished watching.** Recovery now distinguishes the producer's final playlist from the viewer's actual position. A retained position inside that finished playlist can resume; a real end remains an end, and an invalid or evicted position remains a source error. Retry budgets only re-arm after sustained real playback, not seek jumps or paused ticks, preventing repeated item-replacement loops.\n\n**A stream ending early cannot casually mark the episode watched and play the next one.** Both Apple playback surfaces now compare a decoder's EOF against load-owned position and known duration. An EOF far before the ending enters same-episode source recovery instead of completion handling. Recovery uses observed playback position, not an optimistic scrub target or old resume floor. Duplicate EOF callbacks cannot spend the recovery budget twice. True endings, live playback, trailers and unknown-duration sources keep their existing semantics. This addresses the premature-completion code gap examined alongside issue #223.\n\n**Replacement items do not inherit the previous item's completion evidence.** AVPlayer can recover a physical item while retaining the logical playback request. Completion evidence now also follows the physical item generation, so an old early-EOF rejection cannot prevent the recovered item from genuinely finishing later. Retired callbacks cannot finish a newer episode.\n\n**Apple TV's short backward/forward seeks receive the same refill protection as a scrub.** A relative seek outside the buffered window previously missed the existing refill hold and bounded recovery watchdog. It now uses that protection while retaining relative seek semantics and your latest Pause/Play choice. In-buffer seeks do not unnecessarily invoke the cold-refill path.\n\n**Continue Watching keeps the episode you actually opened when it needs to show Details.** Local CW navigation on Apple TV and iPhone now carries the exact episode ID and resume point into the detail page. An episode with a zero resume point is still a valid selection; it does not fall back to an unwatched special such as S0E1. After you successfully play a newer episode, that newer local receipt supersedes the older navigation hint. If a partial episode list does not yet contain the exact target, the hero waits rather than inventing a different episode.\n\n**The phone's resume offset must belong to its selected episode.** The detail hero no longer applies an offset from one episode to a different selected episode. This matches the existing episode-identity check on Apple TV.\n\n**Up from the first episode returns to the selected season.** On Apple TV, that move now explicitly reveals and focuses the current season chip instead of jumping to the hero or making you navigate back down from Play. Down from the first episode still moves to the second; deeper episode rows retain their normal navigation.\n\n**Supported native AVPlayer WebVTT subtitles can follow the in-player appearance settings.** Their timed text can now use the existing VortX subtitle overlay, so outline, shaded and box styles are app-controlled. The native renderer is suppressed before supported text is displayed, and cues replace rather than accumulate. Seeks, subtitle changes, item replacements and close clear or fence stale cues. Unsupported or bitmap captions remain native; Picture in Picture and AirPlay retain native captions. This does not change the device's system caption settings or claim styling support for every subtitle format.\n\n**Diagnostics preserve useful decoder failure reasons without exporting raw decoder traffic.** Probe-enabled release builds now retain bounded, allowlisted VideoToolbox failure categories, including bad frame status, no-output callbacks, session/format failure and waiting for a keyframe. Signed stream links, request headers and arbitrary log text are excluded. This helps distinguish a native decoding failure from an output-frame drop or an empty network cache.\n\n## Android\n\n**There is no new Android APK in Beta 15.** The current Full/MPV and Play/Media3 packages remain in [Beta 14](https://github.com/VortXTV/VortX/releases/tag/v0.4.0-beta.14), version code **237**. Both variants include phone and Android TV interfaces. Their existing fixes are retained; this Apple release does not claim new Android playback or parity work.\n\nThe separately recorded Android rapid-title-selection race and Android update-feed correction remain open. Use the matching Beta 14 APK directly while that feed still serves the older entry.\n\n## Verification and remaining limits\n\nThe Apple completion, Continue Watching target, focus, resume/seek, source handoff, subtitle and diagnostic policies have executable regression coverage. Independent source review accompanies the changes; the release workflow builds and verifies fresh Apple packages, engine pins, signing/provenance and update feeds before publication.\n\nThe fresh-origin recovery was also exercised against the exact bundled GPL playback libraries with VideoToolbox, GPU-next/MoltenVK and AVFoundation audio. A controlled 4.046-second initial position returned to zero while playing and while paused, without changing the pause state. The matching source itself contains timestamps starting at zero.\n\n**These are specific repairs, not a claim that every playback problem is solved.** The physical Apple TV's initial hardware-decoder failure has not been reproduced on the Mac, and broader active-play DV stalls, provider-specific buffering and sustained NNTP throughput still need live-device testing. This release does not force software decoding, remove Dolby Vision, or disguise a failed source as a completed episode. The broader Android parity and phone/Mac redesign work is not bundled into this playback cut.\n\n## Please test\n\n- Let a series advance automatically and use the next-episode button. Confirm the opening is shown, the selected episode is correct, and watch progress belongs to that episode.\n- Pause a DV/AVPlayer title long enough for the local producer to stop filling, then resume. Confirm it stays paused until Play and recovers the same episode and selections.\n- Seek backward and forward both inside and outside the buffered window, including while paused.\n- Open Family Guy or another series from CW. If Details opens, confirm it targets the current episode instead of an unwatched special. From the first episode, press Up once to reach the season selector.\n- With supported built-in AVPlayer text subtitles, compare outline and box appearance. Include the subtitle format and a diagnostic if it remains native or ignores styling.\n\n## Install\n\n**Apple TV.** Use `VortX-tvOS-v0.4.0-beta.15-ci.ipa` for Full or `VortX-tvOS-lite-v0.4.0-beta.15-ci.ipa` for Lite. Install the same variant you normally use through your signing service.\n\n**iPhone and iPad.** Use `VortX-iOS-v0.4.0-beta.15-ci.ipa`. [Apple sideloading instructions](https://github.com/VortXTV/VortX/wiki/Installing) and the [VortX install feed](https://raw.githubusercontent.com/VortXTV/VortX/main/altstore/source.json) are available for supported installers.\n\n**Mac.** Download `VortX-macOS-v0.4.0-beta.15-ci.dmg`, drag VortX into Applications, and use **System Settings > Privacy & Security > Open Anyway** if needed. This is the Apple Silicon package, ad-hoc signed rather than notarized. [Mac installation guide](https://github.com/VortXTV/VortX/wiki/Install-on-Mac).\n\nCheck `SHA256SUMS-ci.txt`; the immutable tag, source commit, and protected release workflow provide provenance for the published Apple files. This beta is deliberately promoted to **Latest**; Apple update and install feeds are verified as part of publication.\n\n<!-- vortx-build: 251 -->\n<!-- vortx-platforms: apple -->\n<!-- vortx-channel: latest-beta -->",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.15/VortX-tvOS-v0.4.0-beta.15-ci.ipa",
          "size": 65096502,
          "sha256": "8cd42c3b1f48290c42090e6b771712e30e97017b4374cb8cd6b6beeb7ac57585",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "247",
          "date": "2026-09-11",
          "localizedDescription": "Apple playback, source controls and episode artwork repairs; Android audio, remote, Discover and title-relation improvements; profile-specific collection visibility.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.14/VortX-tvOS-v0.4.0-beta.14-ci.ipa",
          "size": 65060961,
          "sha256": "bade529bf77d30b5dbf769680769a0c2925e5f9f1679d21fb8a0a9ec1128318c",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "245",
          "date": "2026-09-11",
          "localizedDescription": "Apple build 245: playback recovery, add-on order and sync, artwork, prioritized Usenet and NZB indexers.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.12/VortX-tvOS-v0.4.0-beta.12-ci.ipa",
          "size": 65031315,
          "sha256": "5d33893b6d6a839b52919fb7083516d53e4c51686a00c5c7c71c21cd0b4c8bcc",
          "minOSVersion": "18.0"
        },
        {
          "version": "0.4.0",
          "buildVersion": "243",
          "date": "2026-09-06",
          "localizedDescription": "Apple Beta 10: Continue Watching episodes, pause and seek recovery, NNTP streaming repairs, and DV integrity checks.",
          "downloadURL": "https://github.com/VortXTV/VortX/releases/download/v0.4.0-beta.10/VortX-tvOS-v0.4.0-beta.10-ci.ipa",
          "size": 64777413,
          "sha256": "bd1679b990c729fb2570459fb0e05d2a07abf0892dd75237d7e4d8d81c05d7ad",
          "minOSVersion": "18.0"
        }
      ]
    }
  ],
  "news": []
}
