NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #4827 most downloaded on crates.io
A `cargo` subcommand for fuzzing with `libFuzzer`! Easy to use!
Last release 4 months ago
09 Jun 2026
Release timing varies
gaps range from 2 weeks to 1.3 years
Most releases are documented
notes for 28 of 40 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
40 releases · first in 2017
Merge pull request #446 from fitzgen/bump-to-v0.13.2
Merge pull request #446 from fitzgen/bump-to-v0.13.2
Bump to version 0.13.2
Released 2026-06-09.
--fuzz-engine flag to cargo fuzz init.Merge pull request #419 from fitzgen/bump-to-version-0.13.1
Merge pull request #419 from fitzgen/bump-to-version-0.13.1
Bump to version 0.13.1 and fix release build CI
One column per quarter.
Released 2025-06-26.
rustc
flag that affected not only the debug info level, but also whether split debug
info was enabled and whether debug info stripping was enabled. Now we
correctly configure precisely and only the debug info level and not any other
debug info related settings.Added --disable-branch-folding CLI flag to toggle whether LLVM will fold branches or not. This can have an affect on coverage.
Released 2025-06-25.
--disable-branch-folding CLI flag to toggle whether LLVM will fold
branches or not. This can have an affect on coverage.--strip-dead-code CLI flag to toggle whether dead code is stripped
from builds or not. This can have an affect on coverage.--codegen-units CLI flag. The default is 1, which gives best fuzzing
throughput. You can, however, provide a larger value to significantly reduce
compile times at the cost of worsening fuzzing throughput.--no-include-main-msvc
flag.cargo fuzz b for cargo fuzz build.Removed the definition of cfg(fuzzing_repro) from cargo fuzz run on select inputs. This caused too many recompiles in practice during the common fuzzi
Released 2024-02-20.
cfg(fuzzing_repro) from cargo fuzz run on select
inputs. This caused too many recompiles in practice during the common fuzzing
workflow where you are fuzzing, find a crash, repeatedly run the fuzzer on
just the crashing input until you fix the crash, and then start fuzzing in
general again and the process repeats.cargo fuzz init will not put the generated fuzzing crate in a separate workspace by default anymore. There is an option to generate a workspace if tha
Released 2024-01-25.
cargo fuzz init will not put the generated fuzzing crate in a separate
workspace by default anymore. There is an option to generate a workspace if
that is still the desired behavior: --fuzzing-workspace=true.cargo fuzz init's generated dependencies in Cargo.toml.Added a "careful mode" inspired by the cargo-careful project
Released 2024-01-02.
cargo-careful projectrustup-merge=1 option---cfg fuzzing_reproNo longer rebuilds the fuzz target binary for each coverage run.
Released 2023-02-13.
Fixed the suggested reproducer command outputted by cargo fuzz tmin to preserve any build flags (such as sanitizers) the same way that cargo fuzz fun'
Released 2022-10-25.
cargo fuzz tmin to
preserve any build flags (such as sanitizers) the same way that cargo fuzz fun's suggested reproducer command will.Added the --no-trace-compares flag which opts out of the -sanitizer-coverage-trace-compares LLVM argument.
Released YYYY-MM-DD.
Added the --no-trace-compares flag which opts out of the
-sanitizer-coverage-trace-compares LLVM argument.
Using this may improve fuzzer throughput at the cost of worse coverage accuracy.
It also allows older CPUs lacking the popcnt instruction to use cargo-fuzz;
the *-trace-compares instrumentation assumes that the instruction is
available.
Added the --fuzz-dir flag to all subcommands, so that you can put your fuzzing files in a directory other than my_crate/fuzz if you want. #262
Released 2020-05-13.
--fuzz-dir <dir> flag to all subcommands, so that you can put your
fuzzing files in a directory other than my_crate/fuzz if you
want. #262Added the --strip-dead-code to allow stripping dead code in the linker.
Released 2020-04-19.
Added the --strip-dead-code to allow stripping dead code in the linker.
By default, dead code is linked because LLVM's code coverage instrumentation assumes it is present in the coverage maps for some targets. Some code bases, however, require stripping dead code to avoid "undefined symbol" linker errors. This flag allows controlling whether dead code is stripped or not in your build. #260
cargo fuzz coverage subcommand now passes the raw coverage files to the
llvm-profdata command as a whole directory, rather than as individual files,
which avoids an issue where too many command-line arguments were provided in
some scenarios. #258Added the cargo fuzz coverage subcommand to generate coverage data for a fuzz target. Learn more in the Coverage chapter of the Rust Fuzzing Book!
Released 2021-03-10.
cargo fuzz coverage subcommand to generate coverage data for a
fuzz target. Learn more in the Coverage chapter of the Rust Fuzzing
Book!--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
cargo fuzz build and cargo fuzz run default to building with optimizations *and* debug assertions by default now. This is the most common configuratio
Released 2020-06-25.
cargo fuzz build and cargo fuzz run default to building with optimizations
and debug assertions by default now. This is the most common configuration
for running fuzzers, so we've made it the default. To build without
optimizations, use the --dev flag, which enables Cargo's development
profile. To build without debug assertions, use the --release flag, which
enables Cargo's release profile.--sanitizer=memory flag works correctly now! Previously, we did not rebuild
std with memory sanitizer enabled, and so programs compiled with memory
sanitizer would immediately segfault in practice.Updated locked dependencies away from yanked versions.
Released 2020-06-09.
Added a -v/--verbose flag for enabling verbose cargo builds. This was always implicitly enabled before, but now is optional.
Released 2020-06-09.
-v/--verbose flag for enabling verbose cargo builds. This was
always implicitly enabled before, but now is optional.cargo test --all and cargo doc --all and the fuzz crate is a part of a
workspace. Previously, this caused cargo to accidentally start running the
fuzzers.-sanitizer-coverage-trace-geps and -sanitizer-coverage-prune-blocks=0
flags are not passed to LLVM anymore, as they created a lot of overhead for
fuzz targets, without actually guiding fuzzing much.Added the cargo fuzz fmt subcommand. This prints the std::Debug output of the input. This is especially useful when the fuzz target takes an Arbitrary
Released 2020-03-31.
cargo fuzz fmt <target> <input> subcommand. This prints the
std::fmt::Debug output of the input. This is especially useful when the fuzz
target takes an Arbitrary input type.Force 1 CGU when release mode is enabled
New projects will be initialized with libfuzzer-sys version 0.3.0.
Released 2020-01-22.
libfuzzer-sys version 0.3.0.Updated Cargo.lock file's self version for cargo-fuzz, so that building doesn't change the lock file.
Released 2020-01-15.
Cargo.lock file's self version for cargo-fuzz, so that building
doesn't change the lock file.cargo fuzz will show you the Debug output of failing inputs. This is particularly useful when you're using Arbitrary to create structured fuzz inputs.
Released 2020-01-15.
cargo fuzz will show you the Debug output of failing inputs. This is
particularly useful when you're using Arbitrary to create structured fuzz
inputs. This requires that your fuzz target is using libfuzzer-sys >= 0.2.0
from crates.io.cargo fuzz will now suggest common next tasks after finding a failing
input. It gives you instructions on how to reproduce the failure, and how to
run test case minimization.libfuzzer-sys version
0.2.0
from crates.io now, instead of a git dependency. This also pulls in
arbitrary version
0.3.0
and all the new goodies it contains.--------------------------------------------------------------------------------
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
--------------------------------------------------------------------------------
Nothing published for this version
Nothing published for this version
Nothing published for this version
--------------------------------------------------------------------------------
Nothing published for this version
--------------------------------------------------------------------------------
Nothing published for this version
Nothing published for this version
--------------------------------------------------------------------------------
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →