fuzzfetch
Downloader for firefox/jsshell builds.
Decision gist · record as of 2026-08-14
Yes. Fuzzfetch is actively maintained, has no known vulnerabilities, low install friction, and solves a real problem for anyone working with Mozilla builds. The MPL 2.0 copyleft license is standard for Mozilla projects and poses no barrier to internal use or testing. Install it if you regularly need to fetch Firefox, Spidermonkey, or Thunderbird builds from Firefox-CI.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Low install friction with only two runtime dependencies (pytz and requests).
- The package is actively maintained with a recent commit on 2026-07-06 and has been in production since 2017.
License · maintenance · safety
MPL 2.0 (copyleft) — Licensed under MPL 2.0 (copyleft), which requires derivative works to disclose source code changes under the same license if distributed; acceptable for internal use and testing.
last release 2025-12-11 (246 days) · last repo commit 2026-07-06 · 47 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 95,635 downloads/mo, #13,259 on PyPI
Alternatives
Verify before relying
pip install fuzzfetch
from fuzzfetch import Fuzzfetch
# Retrieve latest AddressSanitizer + fuzzing build
fuzzfetch -a --fuzzing
# Or retrieve debug build of JS shell
fuzzfetch --target js -d- Whether builds are cached locally or re-downloaded on each invocation.
- Network timeout behavior and retry logic when Firefox-CI is unavailable.
- Disk space requirements for typical build downloads.
What it is and what it does
Fuzzfetch is a command-line tool that automates downloading pre-built Firefox, Spidermonkey, and Thunderbird binaries from Mozilla's Firefox-CI Taskcluster service. It abstracts away the complexity of navigating Taskcluster namespaces and build metadata, letting you specify a branch, build date or revision, and build variant (debug, AddressSanitizer, ThreadSanitizer, fuzzing, coverage, etc.) and get the matching artifact. The tool supports multiple operating systems (Android, Darwin, Linux, Windows) and CPU architectures, and can search for the nearest available build if an exact match isn't found.
The package is designed for security researchers, fuzzing engineers, and developers who need to test against specific Firefox builds or variants. It depends only on pytz and requests, making it lightweight to install. The tool runs as a CLI with a rich set of options for targeting specific builds, and also supports dry-run mode to inspect metadata without downloading.
Use it for
- Download AddressSanitizer or ThreadSanitizer builds for security testing and memory-safety validation.
- Retrieve fuzzing builds (AFL++, Fuzzilli, Nyx) for automated fuzz testing campaigns.
- Fetch debug builds of SpiderMonkey for JavaScript engine development and debugging.
- Obtain coverage builds to measure test coverage across Firefox test suites.
- Automate CI/CD pipelines that need specific Firefox or Thunderbird revisions for regression testing.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Fuzzfetch is actively maintained, has no known vulnerabilities, low install friction, and solves a real problem for anyone working with Mozilla builds. The MPL 2.0 copyleft license is standard for Mozilla projects and poses no barrier to internal use or testing. Install it if you regularly need to fetch Firefox, Spidermonkey, or Thunderbird builds from Firefox-CI.
Install
fuzzfetch on PyPI
Before you install
Low install friction with only two runtime dependencies (pytz and requests). The package is actively maintained with a recent commit on 2026-07-06 and has been in production since 2017.
Requires Python 3.10 or later.
License in practice
Licensed under MPL 2.0 (copyleft), which requires derivative works to disclose source code changes under the same license if distributed; acceptable for internal use and testing.
Quickstart
pip install fuzzfetch
from fuzzfetch import Fuzzfetch
# Retrieve latest AddressSanitizer + fuzzing build
fuzzfetch -a --fuzzing
# Or retrieve debug build of JS shell
fuzzfetch --target js -d
Verify before relying
- Whether builds are cached locally or re-downloaded on each invocation.
- Network timeout behavior and retry logic when Firefox-CI is unavailable.
- Disk space requirements for typical build downloads.
Package facts
| License | MPL 2.0 copyleft |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagespytzrequests |
| Maintenance | Actively maintained 246 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 95,635 / month, #13,259 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Mozilla Public License 2.0 (MPL 2.0)Programming Language :: Python :: 3Topic :: SecurityTopic :: Software Development :: Testing |
Evidence: fuzzfetch-16.1.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “firefox build downloader”
- fuzzfetchFuzzfetch retrieves Firefox, Spidermonkey, and Thunderbird builds…
- mozversionExtracts and reports version information from Firefox and other…
- mozrunnerMozrunner manages the lifecycle of Mozilla applications (Firefox,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Testing packages
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
virtualenv creates isolated Python environments where packages can be installed independently without affecting the system Python or other projects.
Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.
Install it if you want to measure test completeness or enforce coverage thresholds in your project.
pytest-asyncio is a pytest plugin that enables writing and running async test functions using the asyncio library, allowing developers to await code directly within test cases.
Install it if you write tests for any asyncio-based code.
A pytest plugin that generates test reports in Common Test Report Format (CTRF) as JSON, compatible with pytest-xdist and pytest-playwright for distributed and browser-based testing.
Install it if you need CTRF-formatted test output for CI/CD integration or cross-tool reporting.
See also mozilla-taskgraph · mozrunner · boofuzz · taskcluster-taskgraph · mozversion · mozprofile · mozleak · taskcluster · mozcrash · taskcluster-urls