Skip to content
CAI
Software that uses CAICheck a score

mozilla-mobile/firefox-ios

49.1

Weak · 28 September 2026

239k

lines of production code

Swift

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Firefox iOS browser application, structured as a monorepo that consolidates the main browser, Focus iOS, and a shared component library called BrowserKit. It provides core web browsing capabilities including tab management, secure authentication via Firefox Accounts, and synchronization of user data through Rust-based App Services. The platform integrates advanced features such as AI-driven Quick Answers and page summarization, content blocking, and a modernized UI framework supporting responsive layouts and theming.

How it got here

2014–2023 — BrowserKit modularization and Rust migration

118 changes.

This period focused on extracting shared infrastructure into the BrowserKit Swift package, establishing a modular architecture with dedicated components for UI, web engine abstraction, and data storage. Concurrently, the project migrated core sync, storage, and account services to Rust-based Mozilla Application Services, while significantly expanding unit and integration test coverage to support the new concurrency-safe codebase.

2024–2025 — BrowserKit modularization and feature expansion

84 changes.

This period focused on extracting and modularizing core browser components into the BrowserKit library, including the toolbar, address bar, and web engine infrastructure. Significant features were introduced, such as Apple Intelligence summarization, content blocking generation, and a new onboarding flow, alongside extensive security and navigation policy improvements. The work was heavily supported by comprehensive unit and UI test coverage for these new modules and existing features like the homepage and search.

2026 — Quick Answers and UI modernization

38 changes.

This period focused on implementing the Quick Answers feature, including its backend services for speech transcription and LLM integration, alongside comprehensive unit testing. Concurrently, the onboarding flow was modernized with responsive layouts and iOS 26 styling, while new libraries were introduced for web compatibility reporting and secure request authentication.

Features

Add 'Open in Firefox' share extension

Users can now use the system share sheet to open web pages or text directly in Firefox. This new iOS action extension, located in the ActionExtension module, intercepts shared content, extracts URLs or text, and launches the Firefox app to display the item. The extension is fully localized into dozens of languages and includes the necessary app icon assets and configuration to appear as 'Open in Firefox' in the share menu.

firefox-ios/Extensions/ActionExtension · high confidence

Add Merino recommendation data models

New model structs, MerinoCategory and MerinoStory, have been added to the Merino provider to represent recommendation data. These models parse and store details such as titles, excerpts, URLs, and ranking information from the Merino service, enabling the app to display categorized content recommendations on the homepage.

firefox-ios/Providers/Merino/Model · high confidence

Add Nimbus FML and Glean SDK build configuration scripts

Added \nimbus-fml-configuration.sh\ and \sdk\_generator.sh\ to the \firefox-ios/bin\ directory. The Nimbus script maps Xcode build configurations (such as Debug, FirefoxStaging, and Firefox) to specific feature flag channels (developer, beta, release) for code generation. The Glean script automates the creation of a Python virtual environment, installs the \glean\_parser\ (version 20.1), and generates Swift code from YAML metric definitions during the build process.

firefox-ios/bin · high confidence

Add Sample Component Library app

A new sample application has been added to demonstrate the Component Library. It includes a full Xcode project structure with an app delegate, scene delegate, and launch screen, along with assets like the Firefox logo and chevron icons. The app showcases various UI components, including buttons (primary, secondary, rounded, link, close), switches, bottom sheets, cards, and headers, all integrated with the theme manager for light and dark mode support.

SampleComponentLibraryApp · high confidence

Add URL and URLRequest extensions for Reader Mode and internal URL handling

This change introduces two new public extensions in the WebEngine module. The URL extension adds an encodeReaderModeURL method, allowing URLs to be encoded and appended to a base Reader Mode URL. The URLRequest extension adds an isPrivileged computed property, which checks if a request's URL is an authorized internal URL. These utilities support internal webview operations and Reader Mode functionality.

BrowserKit/Sources/WebEngine/WKWebview/Extension · high confidence

Add Web Compatibility Report UI cells

This change introduces a suite of new UI components for the Web Compatibility Reporter, including cells for selecting categories, entering URLs and additional details, viewing a page thumbnail and plain-language summary, and submitting the report. It also adds support for technical data display, a 'Learn More' footer with links, and accessibility improvements such as VoiceOver-friendly checkboxes and proper error handling for invalid URLs.

BrowserKit/Sources/WebCompatReporterKit/Cells · high confidence

Add Xcode project configuration and generated Swift wrappers for MozillaRustComponents

The MozillaRustComponents package now includes the necessary Xcode workspace and scheme files to support building and testing within Xcode, alongside a new test plan targeting the MozillaRustComponentsTests suite. Additionally, generated Swift wrapper files for the FocusRustComponentsWrapper (including Nimbus, AdsClient, Remote Settings, and Glean metrics) have been added, providing the Swift interfaces to the underlying Rust components.

MozillaRustComponents · high confidence

Add configurable context menu options for web, login, and URL bar fields

The BrowserKit package now includes a new MenuHelper utility that allows applications to dynamically configure context menu items for different text field types. This change introduces a \DefaultMenuHelper\ implementation and associated protocols/models (\MenuHelperLoginModel\, \MenuHelperURLBarModel\, \MenuHelperWebViewModel\) to support specific menu actions: 'Search' and 'Find in Page' for web views, 'Open and Fill', 'Reveal/Hide Password', and 'Copy' for login details, and 'Paste and Go' for the URL bar. This enables consistent, configurable menu behavior across these key user interaction points.

BrowserKit/Sources/Common/Utilities/MenuHelper · high confidence

Add iMessage Sticker Pack extension

The Firefox iOS app now includes a new Sticker extension that allows users to send Firefox-themed stickers within iMessage. This change adds the necessary bundle configuration (Info.plist) and a sticker pack containing 21 images (1.png through 21.png), along with the required app icons for the iMessage interface.

firefox-ios/Sticker · high confidence

Added HeroImageFetcher to extract site hero images via LinkPresentation

The SiteImageView package now includes a HeroImageFetcher protocol and DefaultHeroImageFetcher implementation that retrieves a site's hero image by leveraging Apple's LinkPresentation framework (LPMetadataProvider). This change introduces a dedicated, thread-safe mechanism for fetching hero images, ensuring that metadata provider operations run on the main thread as required by the framework, and exposes this capability through a Sendable interface for use within the BrowserKit.

BrowserKit/Sources/SiteImageView/ImageProcessing/HeroImageFetcher · high confidence

Added Xcode schemes for BrowserKit subpackages

New Xcode scheme files have been added for BrowserKit subpackages including ActionExtensionKit, Common, ComponentLibrary, ContentBlockingGenerator, JWTKit, Logger, MenuKit, OnboardingKit, QuickAnswersKit, Redux, Shared, SiteImageView, SummarizeKit, TabDataStore, ToolbarKit, UnifiedSearchKit, VoiceSearchKit, and WebCompatReporterKit. These schemes configure build, test, launch, profile, analyze, and archive actions for each package, enabling developers to build and test these components directly within Xcode.

BrowserKit/.swiftpm/xcode/xcshareddata · high confidence

Added Xcode workspace configuration for Swift Package

A new Xcode workspace file (contents.xcworkspacedata) has been added to the .swiftpm directory, configuring the Swift Package Manager package to open in Xcode with a reference to the local package root. This enables developers to easily open and edit the package source code directly within the Xcode IDE.

.swiftpm · high confidence

Added preview model for onboarding card components

A new PreviewModel implementation has been added to the OnboardingKit to support SwiftUI previews of onboarding cards. This includes definitions for basic and multiple-choice card types, covering brand refresh flows such as setting the default browser, customizing toolbar position (top/bottom), and selecting themes (dark/light/system). The model provides the necessary data structures and sample content to allow developers to visualize these onboarding screens during development.

BrowserKit/Sources/OnboardingKit/Preview · high confidence

Added utility scripts for managing Glean metrics and Nimbus features

Two new shell scripts have been added to the archived-scripts directory to streamline developer workflows. FirefoxTelemetryUtility.sh automates the maintenance of Glean telemetry by updating the glean\_index.yaml and gleanProbes.xcfilelist files with paths to metric YAMLs in the Client/Glean/probes directory, and supports creating new metric files with the --add flag. iOSNimbusFeatureUtility.sh manages the Firefox for iOS Nimbus feature flags by updating the include block in nimbus.fml.yaml with files from the nimbus-features directory and supports creating new feature configuration files with the --add flag.

archived-scripts · high confidence

Apple Intelligence summarizer backend implementation

The SummarizeKit backend now includes a new implementation for Apple's Foundation Models (Apple Intelligence). This change introduces the \FoundationModelsSummarizer\ which wraps \LanguageModelSession\ to provide both synchronous and streaming summarization capabilities. It includes configuration for input limits (3,000 words) and supports permissive guardrails for content transformation. The implementation relies on new protocol abstractions (\LanguageModelSessionProtocol\, \LanguageModelResponseProtocol\, etc.) to bridge Apple's concrete types, enabling testability and separation of concerns within the AppleIntelligence backend directory.

BrowserKit/Sources/SummarizeKit/Backend/AppleIntelligence · high confidence

Executable content blocker generator added to BrowserKit

An executable entry point (MainContentBlockerGenerator) has been added to the BrowserKit package, allowing the content blocker list generation logic to be invoked directly from the command line. This change introduces a thread-safe generator instance to address FXIOS-14548, enabling users to trigger the generation of content blocking lists via a terminal command rather than relying solely on internal app integration.

BrowserKit/Sources/ExecutableContentBlockingGenerator · high confidence

Initial CI/CD configuration for Firefox iOS

This change introduces the foundational continuous integration and deployment infrastructure for the Firefox iOS repository. It establishes Taskcluster cron jobs for periodic tasks like localization screenshots and performance testing, configures Mergify to automate pull request merging for specific bot-driven updates (such as Bitrise, Rust components, and L10N changes), and sets up SwiftLint versioning to enforce code quality standards across the codebase.

(repo-wide) · high confidence

Initial Taskgraph configuration and release automation for Firefox for iOS

This change introduces the core Taskgraph configuration and task definitions for Firefox for iOS, enabling automated CI/CD workflows. It establishes worker aliases for Bitrise, GitHub, and Docker-based tasks, and defines specific task kinds for building, performance testing (Bitrise and Firebase), and generating localized screenshots. Additionally, it implements the release promotion pipeline, including logic for version bumping, branch management, and shipping releases via Shipit and GitHub.

taskcluster · high confidence

Introduce Architectural Decision Records (ADRs) for Firefox iOS

The project now includes a structured directory for Architectural Decision Records (ADRs) to document key technical choices. This change adds a standard MADR-compliant template and an initial set of 13 records covering foundational decisions: adopting Markdown for ADRs, modernizing the logging infrastructure with SwiftyBeaver, implementing the Coordinator pattern for navigation, migrating from MVVM to a Redux-style architecture (including state management, navigation integration, action guidelines, and reducer best practices), refactoring feature flags, optimizing the deeplink startup flow and tab screenshot restoration, and offloading background WebViews to mitigate memory-related crashes.

adr · high confidence

Introduce JWTKit for secure token encoding and Shared framework utilities

This change introduces the JWTKit library to the Shared framework, providing a new \JWTEncoder\ and algorithm strategies (\none\, \HS256\) for creating and verifying JSON Web Tokens, which supports the Summarizer feature's need for signed tokens. Alongside this, the Shared framework adds several utility components: an \AlertController\ subclass that enables accessibility identifiers for UI testing, \InstallationUtils\ to detect the app's installation date, and \InternalURL\ helpers to manage and authorize internal browser URLs. The update also includes foundational utilities such as \Bytes\ for Base64URL encoding, \DateGroupedTableData\ for organizing list items by time, and \KeyboardHelper\ for observing keyboard state changes.

BrowserKit/Sources/Shared · high confidence

Introduce LLMKit and AppAttestKit for secure LLM integration

This change introduces two new modular libraries, LLMKit and AppAttestKit, to support the Quick Answers feature. LLMKit provides a \LiteLLMClient\ that communicates with OpenAI-style chat completion endpoints, supporting both non-streaming and Server-Sent Events (SSE) streaming responses, along with configuration management and provider-specific field handling. AppAttestKit encapsulates the Apple App Attest flow, managing hardware-backed key generation, attestation, and assertion to securely authenticate requests to the Mozilla LLM Proxy Auth (MLPA) service. The \LiteLLMCreator\ ties these together, instantiating the LLM client with App Attest authentication and handling environment-based key resets.

BrowserKit/Sources/LLMKit · high confidence

Introduce NotificationService extension for handling Firefox Sync push notifications

The NotificationService extension has been added to the Firefox iOS app to handle incoming push notifications from Firefox Sync. This extension initializes the Rust network stack (Viaduct) and MozillaAppServices to decrypt and process encrypted push messages. It supports displaying notifications for various sync events, including received tabs, closed remote tabs, and device connection/disconnection status, ensuring users are informed about sync activities even when the app is in the background.

firefox-ios/Extensions/NotificationService · high confidence

Introduce Nova design system and theme architecture

The theming system in BrowserKit has been updated to support the new Nova design language. This change introduces dedicated theme structs (NovaLightTheme, NovaDarkTheme, NovaNightModeTheme) and a corresponding color palette (NovaColors) that replaces the legacy FXColors for Nova-enabled users. The DefaultThemeManager now checks a feature flag to determine whether to apply the Nova palette or the standard Firefox palette, ensuring that the visual appearance adapts based on the active design system. Additionally, the underlying color infrastructure has been refactored to support theme-aware shadows (FxShadow) and gradients (Gradient) that integrate with the new token-based system.

BrowserKit/Sources/Common/Theming · high confidence

Introduce Quick Answers backend service with platform-aware speech transcription

The Quick Answers feature now includes a dedicated backend layer in BrowserKit that handles voice recording and search result retrieval. The new \QuickAnswersService\ protocol and its \DefaultQuickAnswersService\ implementation manage the recording lifecycle and delegate transcription to a platform-specific engine: iOS 26+ devices use \SpeechAnalyzerEngine\, while earlier versions fall back to \SFSpeechRecognizerEngine\. The service also integrates with a \ResultsService\ to fetch search results and sources based on the transcribed text, exposing a clean interface for starting/stopping recording and querying results.

BrowserKit/Sources/QuickAnswersKit/Backend · high confidence

Introduce Rust-based Firefox Account sign-in and pairing infrastructure

This change adds the core Swift components for the new Rust FxA integration in firefox-ios/RustFxA, including the \FirefoxAccountSignInViewController\ for QR and email sign-in, \FxAWebViewController\ and \FxAWebViewModel\ to manage the web-based authentication flow, and \FxAPairingOAuthHandler\ to support pairing v2 via OAuth. It also introduces supporting types such as \Avatar\ for profile images, \FxAEntryPoint\ and \FxALaunchParams\ to track sign-in origins, \FxAWebViewTelemetry\ for usage metrics, and \PushNotificationSetup\ for device push registration, establishing the foundation for the updated account management experience.

firefox-ios/RustFxA · high confidence

Introduce TabDataStore for persistent tab and window data management

A new TabDataStore library has been added to manage the storage and restoration of tab and window data. It introduces distinct data models for WindowData (containing window UUIDs, active tab IDs, and tab lists) and TabData (containing URL, title, and session info), along with a TabSessionStore for handling individual tab session data. The implementation includes a DefaultTabDataStore that persists window data to disk with backup support and throttled saves, and a DefaultTabFileManager that abstracts file system operations for storing these files in the app's shared container.

BrowserKit/Sources/TabDataStore · high confidence

Introduce ToolbarKit component library

This change introduces the ToolbarKit library, a new modular component for building the browser's toolbar. It provides a configurable ToolbarElement data model and a ToolbarManager that handles address bar border visibility logic. The kit includes specialized UI controls such as StackedTabButton (displaying tab screenshots with gradients), TabNumberButton (showing tab counts with dimming states), and a base ToolbarButton supporting long-press actions, badges, masks, and accessibility features. A caching mechanism (ToolbarButtonCaching) is included to optimize performance by reusing button instances.

BrowserKit/Sources/ToolbarKit · high confidence

Introduce URLSession abstractions in BrowserKit for easier network testing

New protocol definitions (URLSessionProtocol, URLSessionDataTaskProtocol, URLSessionUploadTaskProtocol) and their default implementations have been added to the BrowserKit package. This allows network-dependent code to depend on these abstractions rather than the concrete Foundation URLSession, enabling developers to inject mock implementations for unit testing without needing to modify the underlying network logic.

BrowserKit/Sources/Shared/URLSession · high confidence

Introduce WebEngine abstraction layer with core protocols and session management

This change introduces the foundational WebEngine package in BrowserKit, providing a new abstraction layer for web content rendering. It defines core protocols including Engine, EngineSession, and EngineView to standardize how web views are created, managed, and rendered. The update adds a BrowserURL type that enforces browsing context security checks before navigation, and introduces EngineSession to handle tab-like state, including navigation history, tracking protection modes, page zoom, and find-in-page interactions. Additionally, it establishes a telemetry proxy system for tracking events like ad interactions and navigation failures, along with support for page metadata extraction and script-based event handling.

BrowserKit/Sources/WebEngine · high confidence

Introduce WebEngine as a new WebKit-based rendering engine

This change introduces the WebEngine, a new WebKit-based rendering engine for Firefox iOS, located in BrowserKit/Sources/WebEngine/WKWebview. It provides a complete abstraction layer over WKWebView, including WKEngine for lifecycle management, WKEngineSession for navigation and state, and WKEngineView for UI integration. The engine supports configuration via WKEngineConfigurationProvider, handles content blocking settings, manages user scripts and content scripts, and implements navigation, UI, and lifecycle handlers. This enables a modular, testable, and Swift 6-concurrent web engine implementation that can be used as a drop-in replacement or alongside existing web view implementations.

BrowserKit/Sources/WebEngine/WKWebview · high confidence

Introduce WebEngine content and user script injection infrastructure

The WebEngine now supports injecting JavaScript content scripts and user scripts into WKWebViews via a new \WKContentScriptManager\ and \WKUserScriptManager\. This infrastructure enables specific capabilities such as tracking ad telemetry, detecting field focus changes, and handling print actions (including using page titles for PDF filenames). The system loads JavaScript files from the bundle, wraps them with an app ID token for security, and manages their lifecycle within the web view's content worlds.

BrowserKit/Sources/WebEngine/WKWebview/Scripts · high confidence

Introduce async SiteImageFetcher with SVG support and Kingfisher integration

This change introduces a new image fetching infrastructure in BrowserKit's SiteImageView, replacing previous synchronous or less structured approaches with an async-first design. It adds DefaultSiteImageDownloader and FaviconFetcher components that leverage the Kingfisher library for network requests, enabling proper timeout handling and error logging. A key capability added is native SVG favicon support via a new SVGImageProcessor, which rasterizes SVG data into UIImages using the SwiftDraw library. The implementation also ensures thread safety through explicit Sendable conformance and provides a clean, testable protocol-based API for downloading and processing site images.

BrowserKit/Sources/SiteImageView/ImageProcessing/SiteImageFetcher · high confidence

Introduce backend service for Quick Answers results

This change adds the backend infrastructure for the Quick Answers feature, introducing a \ResultsService\ that fetches answers via an LLM client (LiteLLM) and formats results with up to two citations. It includes configuration handling for model selection (Exa or Liner), error mapping for API responses (such as rate limits or invalid responses), and a factory for creating the service with App Attest authentication.

BrowserKit/Sources/QuickAnswersKit/Backend/ResultsService · high confidence

Introduce configurable backend for Apple and hosted LLM summarizers

The SummarizeKit backend now supports two distinct summarization engines: a local Apple Foundation Model (available on iOS 26+) and a hosted LiteLLM service. This change introduces a configuration system that allows the app to select the active backend, apply specific model parameters (such as temperature and token limits), and handle authentication for the hosted provider via App Attest or API keys. It also adds a content checker to validate page suitability before summarization and defines a unified error model to surface issues like rate limits or unsupported content to the user.

BrowserKit/Sources/SummarizeKit/Backend · high confidence

Introduce custom domain autocomplete and enhanced tracking protection infrastructure

Users can now add custom domains to the URL autocomplete list, with the system automatically sanitizing inputs (removing protocols and trailing slashes), preventing duplicates, and rejecting invalid formats. Additionally, the app introduces a new tracking protection architecture that injects JavaScript to monitor and report script and image sources, supporting configurable blocklists for advertising, analytics, content, and social trackers.

focus-ios/Blockzilla · high confidence

Introduce local web server for Reader Mode and testing

A new local web server implementation has been added to the WebEngine to serve Reader Mode content and test fixtures. This change introduces \WKEngineWebServer\ and \DefaultWKWebServerUtil\ to manage a localhost-based server that hosts Reader Mode resources and various HTML test fixtures, enabling isolated testing and improved resource handling for Reader Mode within the browser engine.

BrowserKit/Sources/WebEngine/WKWebview/WebServer · high confidence

Introduce modular speech transcription service for Quick Answers

The Quick Answers feature now uses a new, modular speech service located in the SpeechService backend. This introduces an abstraction layer (AudioManager, AuthorizationHandler) for microphone and audio session management, and provides two distinct transcription engines: a standard SFSpeechRecognizer engine for general iOS devices and a new SpeechAnalyzerEngine that leverages the iOS 26 SpeechTranscriber for on-device recognition. The service handles permission requests, audio capture, and streaming transcription results, with specific error handling for permission denials and recognizer availability.

BrowserKit/Sources/QuickAnswersKit/Backend/SpeechService · high confidence

Introduce new MenuKit UI components for the redesigned menu

The MenuKit library now includes a new set of UI components to support the redesigned menu interface. This adds a HeaderBanner for default browser notifications, a SiteProtectionsHeader with badges for protections and ad-blocking, and new cell types (MenuCell, MenuAccountCell, MenuInfoCell, MenuSquareCell) to display menu options with updated styling, active states, and accessibility labels. These components form the visual foundation for the new menu layout.

BrowserKit/Sources/MenuKit · high confidence

Introduce new Storage framework components and data models

The Storage module now includes a suite of new foundational types and services: an in-memory certificate store (CertStore), a disk-backed image cache for screenshots (DiskImageStore), and a file accessor abstraction (FileAccessor). It also introduces data models and protocols for managing remote clients and tabs (RemoteClient, RemoteTab, ClientAndTabs), reading list items (ReadingListItem), pinned sites (PinnedSites), and page metadata (PageMetadata), alongside utilities for handling share extensions (ExtensionUtils) and a mock implementation for the Rust keychain (MockRustKeychain) to support testing.

firefox-ios/Storage · high confidence

Introduce new modular AddressToolbar component in BrowserKit

The AddressToolbar location now contains a new, modular implementation of the address bar UI, replacing the previous monolithic structure. This change introduces a dedicated \AddressToolbar\ protocol and a \BrowserAddressToolbar\ view that manages the layout of navigation, page, and browser actions via stack views, along with a \LocationView\ for URL display. It adds support for configurable UX states (such as minimized mode, blur effects, and corner radius adjustments for iOS 26), handles drag-and-drop interactions for URLs, and exposes a delegate protocol for search suggestions and editing events. The new component also includes specific views like \AddressToolbarAddTabView\ for the new-tab gesture and supports both top and bottom toolbar positions via \AddressToolbarPosition\.

BrowserKit/Sources/ToolbarKit/AddressToolbar · high confidence

Introduce shared date formatting and device identification utilities

The Shared framework now includes a new Date extension that converts timestamps into human-readable relative time strings (e.g., "Yesterday", "2 days ago", "Just now") for use across the app. Additionally, a new DeviceInfo extension provides a standardized method for generating client names for sync and telemetry, while a new FSUtils utility exposes a list of open file descriptors for debugging and diagnostics.

firefox-ios/Shared · high confidence

The OnboardingKit now includes dedicated model structs for managing onboarding UI elements: OnboardingButtons defines primary and secondary actions, OnboardingButtonInfoModel and OnboardingMultipleChoiceButtonModel handle button titles, actions, and image states, and OnboardingLinkInfoModel represents clickable links. These models provide a type-safe, Sendable foundation for onboarding interactions, replacing ad-hoc data structures with explicit, reusable components.

BrowserKit/Sources/OnboardingKit/Models/Buttons · high confidence

Introduce the Web Compatibility Reporter Kit

This change adds the WebCompatReporterKit, a new UI component library that implements the 'Report a Website Issue' bottom sheet. It provides the full user flow for reporting broken sites, including a main sheet for entering the URL, selecting the issue category, and adding details, as well as a Report Preview screen that displays a plain-language summary and a link to Technical Data. The kit also includes a full-page screenshot viewer with a scroll rail, a custom checkbox control, and the underlying view models and data sources to drive these interfaces.

BrowserKit/Sources/WebCompatReporterKit · high confidence

Introduces Reader Mode styling and state models

Adds the foundational data models for Reader Mode customization, including enums for font size (13 levels), font type (serif/sans-serif, normal/bold), and theme (light, dark, sepia). Introduces a ReaderModeStyle class to manage these preferences and encode them for storage or transmission, along with a ReaderModeState enum to track availability and activity. These components provide the backend structure for user-facing Reader Mode theming and typography settings.

BrowserKit/Sources/Common/ReaderMode · high confidence

Introduces SiteImageCache for typed favicon storage

BrowserKit now includes a new \SiteImageCache\ component that manages image caching for site icons (favicons). This implementation wraps the Kingfisher library to provide a structured cache keyed by both the site identifier and the specific image type (e.g., favicon vs. large icon), ensuring that different icon variants are stored and retrieved separately. The cache supports both asynchronous retrieval and fast memory-only lookups, and it is designed to be thread-safe via Swift's \Sendable\ protocol.

BrowserKit/Sources/SiteImageView/ImageProcessing/SiteImageCache · high confidence

Introduces site image error handling and data models

The SiteImageView package now includes dedicated error handling and data structures for site images. A new \SiteImageError\ enum defines specific failure cases such as missing favicons, download failures, and cache issues, while \ServerErrorHelper\ distinguishes client connectivity errors from server-side problems. Additionally, \SiteImageModel\ and \SiteResource\ provide the underlying data structures to manage image requests, cache keys, and resource sources (remote URLs vs. bundled assets).

BrowserKit/Sources/SiteImageView/Entities · high confidence

Introduction of LegacyWebViewController for WebView management

A new \LegacyWebViewController\ class has been added to the \focus-ios/Blockzilla/Modules/WebView\ module to manage the \WKWebView\ lifecycle and configuration. This controller implements the \LegacyWebController\ protocol, handling navigation state, tracking protection integration, and user agent configuration (specifically setting UA strings for iPad and iPhone based on version 26.4). It also configures the web view with non-persistent data stores, inline media playback, and HTTPS upgrades, serving as the concrete implementation for the legacy web browsing interface.

focus-ios/Blockzilla/Modules/WebView · high confidence

Introduction of SampleBrowser as a WebEngine Technology Preview

A new SampleBrowser application has been added to the repository, serving as a reference implementation and technology preview for the WebEngine package rather than a consumer-facing product. This Xcode project integrates the WebEngine and ToolbarKit frameworks and includes the necessary application infrastructure (AppDelegate, SceneDelegate) to initialize the engine, along with UI components for browsing, search, settings, and error handling to demonstrate WebEngine capabilities.

SampleBrowser · high confidence

Introduction of the new Sync module framework

A new Sync module has been added to the application, introducing the core infrastructure for the Rust-based sync manager. This includes the RustSyncManagerAPI class, which exposes the SyncManagerComponent from MozillaAppServices to handle synchronization operations, engine toggling (tabs, passwords, bookmarks, history, credit cards, and addresses), and telemetry reporting. The module also provides SyncConstants for managing sync timing delays and necessary bridging headers to integrate with the existing iOS codebase.

firefox-ios/Sync · high confidence

MLPAKit introduces App Attest-based request authentication

The MLPAKit package now includes core infrastructure for securing outgoing requests using Apple's App Attest. This change adds an authentication pipeline (\AppAttestRequestAuth\) that generates signed assertions via the device's Secure Enclave and attaches them as Bearer tokens in HTTP headers. It also introduces the server-side communication layer (\MLPAAppAttestServer\) to handle challenge fetching and attestation registration, along with JWT payload encoding (\MLPAJWTPayload\) and service type definitions (\MLPAServiceType\) for Quick Answers and server-to-server interactions. This enables the Quick Answers feature to verify device integrity and establish trust with the Mozilla LLM Proxy.

BrowserKit/Sources/MLPAKit · high confidence

Merino provider now supports categorized news feeds

The Merino provider in Firefox iOS has been refactored to support the new 'Homepage Story Categories' feature. When the \homepageStoryCategories\ feature flag is enabled, the provider fetches and caches curated recommendations organized into sections (such as Travel, Technology, and Science) rather than a flat list. This change introduces a new \MerinoFeedFetcher\ that conditionally requests the \sections\ feed from the Merino API, updates the caching logic to handle this structured data, and provides mock test data that mirrors the new categorized response format for development and testing.

firefox-ios/Providers/Merino · high confidence

New Account framework module for Firefox iOS

A new Account framework module has been introduced to the Firefox iOS project. This module includes a bridging header to expose Objective-C interfaces, an Info.plist defining the framework bundle (version 18.0), and a Swift implementation (FxAPushMessageHandler) that handles Firefox Account push messages, such as remote tab commands and device connection events.

firefox-ios/Account · high confidence

New BottomSheet component with iOS 26 glass effect support

The ComponentLibrary now includes a new BottomSheetViewController and BottomSheetViewModel. This reusable UI component presents a modal sheet with configurable corner radius, shadow, and animation behavior. On iOS 26 and later, the sheet automatically applies a glass visual effect to its content view, while earlier iOS versions use a solid background color. The component supports a dimmed background overlay, a close button with accessibility labels, and dismissal via pan gestures or tapping outside the sheet.

BrowserKit/Sources/ComponentLibrary/BottomSheet · high confidence

New CI/CD automation scripts and test fixtures for Firefox iOS

This change introduces a suite of new automation scripts and test fixtures to the \test-fixtures\ directory. It adds \convert\_junit\_to\_markdown.py\ to transform JUnit XML test results into Slack and GitHub Markdown formats, including logic to distinguish between flaky tests and failures in smoke tests. It includes \get-next-pr-version\ to automatically calculate the next release version from Git branches, \uri\_update.py\ to sync permanent URI schemes from IANA into the iOS codebase, and \generate-test-db.py\ to create simulated SQLite databases for testing history and bookmarks. Additionally, it provides \generate-metrics.sh\ for warning threshold checks, \perfTestTransform.py\ for performance test data formatting, and various shell scripts (\tabs-archive-maker.sh\, \read-rust-component-tag.sh\) and static assets (HTML login forms, tab state archives) to support automated testing and CI workflows.

test-fixtures · high confidence

New Common Utilities package in BrowserKit

BrowserKit now includes a new Common/Utilities module providing shared infrastructure for the application. This adds \AppInfo\ for retrieving bundle and version details (including extension-aware logic), \DeviceInfo\ for simulator detection, and \Bytes\ for secure random data generation. It introduces \DynamicFont\ and \DynamicFontHelper\ to standardize dynamic type scaling across UIKit and SwiftUI, along with \FXFontStyles\ and \TextStyling\ to enforce a consistent design system. Additionally, it provides \Notifiable\ and \NotificationProtocol\ to safely manage \NSNotificationCenter\ observers with thread-safety guarantees, \DispatchQueueInterface\ and \DispatchSourceInterface\ to abstract concurrency primitives for testability, and \UserDefaultsInterface\ to abstract persistent storage.

BrowserKit/Sources/Common/Utilities · high confidence

New Component Library UI elements: buttons, switches, and activity indicators

The Component Library now includes a suite of new, themeable UI components to standardize the app's interface. This adds a \ChipButton\ for capsule-style selections, a \CloseButton\ with dynamic font scaling and iOS 26 glass styling, and a \LinkButton\ with optional underlining. Several button variants have been introduced or updated: \PrimaryRoundedButton\ and \SecondaryRoundedButton\ (the latter now featuring an integrated \ArcActivityIndicatorView\ spinner), \RoundedButtonWithImage\ (with rotating icon animation), and \PrimaryRoundedGlassButton\ for iOS 26. Additionally, a \PaddedSwitch\ wrapping a \ThemedSwitch\ provides consistent toggle styling. All components support theming and accessibility features like dynamic type scaling.

BrowserKit/Sources/ComponentLibrary/Buttons · high confidence

New Content Blocking Generator tool in BrowserKit

A new executable tool has been added to the BrowserKit package to generate content-blocking lists for Enhanced Tracking Protection. This generator reads tracking lists from the shavar-prod-lists directory and produces WebKit-compatible JSON files in the ContentBlockingLists directory, supporting both full blocking and cookie-blocking actions across categories like advertising, analytics, social, cryptomining, and fingerprinting.

BrowserKit/Sources/ContentBlockingGenerator · high confidence

New ContextualHintView component for displaying contextual hints

A new ContextualHintView component has been added to the ComponentLibrary, providing a reusable UI element for displaying contextual hints (such as CFRs) with a title, description, and close button. The view supports dynamic font scaling for accessibility, theming via the Nova gradient token, and configurable arrow directions, allowing product teams to consistently present contextual information across the browser.

BrowserKit/Sources/ComponentLibrary/ContextualHintView · high confidence

New HeaderView and NavigationHeaderView components for consistent UI and accessibility

Added HeaderView and NavigationHeaderView to the ComponentLibrary. HeaderView provides a structured layout for site titles, subtitles, and favicons with support for accessibility text scaling and icon masking. NavigationHeaderView offers a centered title with back and close buttons, including theme-aware styling and animated header line visibility. Both components ensure proper accessibility labels and identifiers are configurable.

BrowserKit/Sources/ComponentLibrary/Headers · high confidence

New Rust-based storage wrappers for Autofill, Logins, Places, and Firefox Suggest

This change introduces a new set of Swift wrappers in the \firefox-ios/Storage/Rust\ directory that bridge the iOS app to Mozilla Application Services (Rust) components. Specifically, it adds \RustAutofill\ for managing encrypted credit cards and addresses, \RustLogins\ for handling saved passwords, \RustPlaces\ for bookmarks and history, \RustRemoteTabs\ for synced tabs, and \RustFirefoxSuggest\ for search suggestions. These files replace or supplement previous implementations by providing a modern, async-friendly interface to the underlying Rust storage engines, including specific support for autofill encryption keys and telemetry tracking for suggestions.

firefox-ios/Storage/Rust · high confidence

New SiteImageView component for favicons and hero images

BrowserKit now includes a new SiteImageView package that provides FaviconImageView and HeroImageView components for displaying site icons and cover images. The FaviconImageView handles favicon retrieval and caching, while the HeroImageView supports hero images with automatic fallback to favicons if the hero image is unavailable or square. Both components use a shared SiteImageHandler for managing image requests, memory/disk caching, and request queuing to prevent duplicate network calls.

BrowserKit/Sources/SiteImageView · high confidence

New SwiftUI component library for onboarding UI

The ComponentLibrary now includes a suite of new SwiftUI views to support the redesigned onboarding experience. This adds a customizable PagingCarousel with smooth swipe gestures and accessibility support, themed Primary and Secondary button styles, and a theme-aware CustomPageControl for pagination indicators. It also introduces AttributedLinkText for accessible, styled links, a LinkButtonView for full-width link actions, a NoHighlightButtonStyle for subtle interactions, and a PortraitOnlyHostingController to enforce orientation constraints during onboarding flows.

BrowserKit/Sources/ComponentLibrary/SwiftUI · high confidence

New Terms of Use onboarding screen with responsive layouts

Users will now see a dedicated Terms of Use view during onboarding that adapts to device size. The screen features a regular layout for wider screens (like iPads) and a compact, scaled layout for narrower screens (like iPhones), ensuring consistent presentation of the terms text, images, and action buttons across different devices.

BrowserKit/Sources/OnboardingKit/Views/TermsOfUse · high confidence

New TestKit library with mocks and test helpers

A new TestKit library has been added to BrowserKit to centralize testing utilities. It includes mock implementations for App Attest services (AppAttestKeyIDStore, AppAttestRemoteServer, AppAttestService) and a MockURLSession for network testing, along with a MockLogger. The library also provides a SwiftTestingHelper for memory leak detection in Swift Testing suites and extends XCTestCase with helpers for memory leak tracking, async unwrapping, and async error assertion.

BrowserKit/Sources/TestKit · high confidence

New URL and text extraction logic for the Share extension

The ActionExtensionKit now includes new source files (ActionShareItem.swift and FirefoxURLBuilding.swift) that define the core data structures and logic for handling shared content. This introduces the ActionShareItem and ExtractedShareItem types to represent URLs and raw text, along with extensions on NSItemProvider to safely load URL and text attachments. It also provides the FirefoxURLBuilder implementation, which extracts URLs or text from share items, converts plain text into URLs when possible, and constructs internal Firefox deep links (using the mozInternalScheme) to open content in the browser.

BrowserKit/Sources/ActionExtensionKit · high confidence

New URL formatting and popup throttling utilities in WebEngine

This change introduces two new utility components to the WebEngine layer. The DefaultURLFormatter handles user input from the address bar, applying specific logic for localhost, scheme validation, and character encoding; notably, it implements manual percent-encoding for URLs lacking a scheme on iOS versions prior to 17 to ensure correct navigation, while relying on native iOS 17+ parsing for newer systems. Additionally, the DefaultPopupThrottler is added to monitor and limit the frequency of JavaScript alerts, popup windows, and external scheme navigations, helping to prevent abuse or denial-of-service conditions by resetting counts after defined time intervals.

BrowserKit/Sources/WebEngine/Utilities · high confidence

New WidgetKit extension with Quick Actions, Open Tabs, and Download Live Activities

Firefox now includes a dedicated WidgetKit extension that adds several new widgets to the iOS home screen and lock screen. Users can now use the 'Quick Actions' widget (in small and medium sizes) to perform common tasks like searching, opening copied links, or closing private tabs directly from the home screen. The 'Quick View' widget displays a list of open tabs with favicons, allowing quick navigation back to them. Additionally, a new Download Live Activity provides real-time progress updates for file downloads on the lock screen and in the Dynamic Island, including the ability to stop downloads directly from the activity view.

firefox-ios/WidgetKit · high confidence

New accessibility action helper and window UUID utilities in Common

The Common module now includes Accessibility.swift, which provides the AccessibleAction class and AccessibilityActionsSource protocol to simplify creating custom accessibility actions on iOS views, and WindowUUID+Extensions.swift, which defines the WindowUUID type alias, ReservedWindowUUID struct, and sentinel UUIDs (unavailable, XCTestDefaultUUID, DefaultUITestingUUID) along with notification userInfo helpers to support multi-window scenarios on iPad.

BrowserKit/Sources/Common · high confidence

New automation scripts for nightly builds, TestFlight, and release notes

The scripts directory now includes several new tools to automate the nightly build and release pipeline. The \update\_from\_application\_services.py\ script automates the process of pulling the latest Rust components from application-services, updating the local Swift package, and creating a pull request to merge the changes. The \nightly\_testflight\_add\_group.py\ script uses the App Store Connect API to automatically add a TestFlight group to nightly builds and submit them for beta testing. Additionally, \update\_release\_notes.py\ and its test suite \test\_update\_release\_notes.py\ automate the process of updating 'What's New' release notes across all locales in the App Store. Finally, \install-swiftlint.sh\ provides a standardized way to install a pinned version of SwiftLint, ensuring consistent linting across all workflows.

scripts · high confidence

New common utility extensions for UI, data, and URL handling

BrowserKit now includes a suite of new extension methods in its Common module to streamline development and improve consistency. For UI, \UIView\ gains a \build\ helper for cleaner view initialization, \pinToSuperview\ for auto-layout, and \applyShadow\/\applyScreenCornerRadius\ for styling; \UILabel\ supports shimmer animations; \UIStackView\ offers animated arrangement methods; and \UIColor\ provides hex/string conversion, SwiftUI interoperability, and adaptive theme-aware colors. Data handling is enhanced with \Data.sha1\ hashing, \Data.hexEncodedString\, \Dictionary.merge\, and \Dictionary.asString\. String utilities include word counting, HTML entity encoding, and leading character trimming. URL handling features robust domain normalization, public suffix extraction, and safe base-URL construction. Finally, \UIPasteboard\ provides a non-blocking async string reader, and \VerticalAlignment\ adds a SwiftUI alignment ID for icon/label centering.

BrowserKit/Sources/Common/Extensions · high confidence

New image processing pipeline for favicons and hero images

The SiteImageView package now includes a new ImageHandler and LetterImageGenerator to manage how site icons are retrieved and displayed. The ImageHandler implements a unified fetching strategy that attempts to load favicons and hero images from cache first, then from the network, and finally falls back to generated letter icons or bundled defaults if retrieval fails. The LetterImageGenerator creates these fallback icons by rendering the first letter of the domain name using the current theme's color palette, ensuring consistent visual styling even when no actual site image is available.

BrowserKit/Sources/SiteImageView/ImageProcessing · high confidence

New onboarding launch screen with video intro and loader

The onboarding flow now includes a dedicated launch screen that displays an animated Firefox loader while a muted intro video plays in the background. Users see a 'Continue' button at the bottom of the screen; once the video finishes, it loops automatically, and tapping the button dismisses the intro to proceed to the next step. This view supports theming and is restricted to portrait orientation.

BrowserKit/Sources/OnboardingKit/Views/LaunchScreen · high confidence

New onboarding model layer introduces structured flow, card, and terms-of-use handling

The OnboardingKit Models directory now contains a complete set of new types that define the structure and behavior of the onboarding experience. This includes OnboardingFlowViewModel and TermsOfUseFlowViewModel to manage navigation, skip actions, and user interactions (such as accepting terms or opening privacy notices), and OnboardingCardInfoModelProtocol to standardize card data (title, body, buttons, multiple-choice options, and embedded links). Supporting types like OnboardingVariant (with base, japan, and brandRefresh options), OnboardingCardType, EmbeddedLink, and TermsOfUseAction provide the necessary configuration and semantic structure for these flows. This change establishes the foundational data models and view-models for the onboarding UI, separating the logic for card progression and terms-of-use handling from the presentation layer.

BrowserKit/Sources/OnboardingKit/Models · high confidence

New persistent favicon URL cache with 30-day expiration

The SiteImageView component now uses a dedicated, persistent cache to store resolved favicon URLs. This cache is stored in the app's caches directory and automatically expires entries older than 30 days, ensuring that stale URL mappings are refreshed while maintaining performance for frequently visited sites.

BrowserKit/Sources/SiteImageView/FaviconURLProcessing/Cache · high confidence

New reusable UI components added to the Component Library

The Component Library now includes several new reusable views to standardize UI across the app: ActionButton for styled buttons with configurable insets and accessibility identifiers; ChipPickerView and ChipPickerItem for horizontally scrolling, themeable chip selection lists; CollapsibleCardView and ShadowCardView for cards with expand/collapse functionality and consistent shadow styling; FadeScrollView for scroll views with top/bottom fade masks; GradientView for views backed by CAGradientLayer; and TextField with a built-in clear button and accessibility support.

BrowserKit/Sources/ComponentLibrary · high confidence

New search engine selection UI components in UnifiedSearchKit

Added the \SearchEngineCell\, \SearchEngineElement\, \SearchEngineSection\, and \SearchEngineTableView\ classes to BrowserKit. These components provide the underlying table view infrastructure and data models required to display a list of search engines with icons, titles, and accessibility labels, supporting theme application and row selection actions.

BrowserKit/Sources/UnifiedSearchKit · high confidence

New shared date utilities and provider protocol

Added a new \DateProvider\ protocol and \SystemDateProvider\ implementation to allow injecting a customizable date source, which facilitates unit testing by decoupling logic from the system clock. Additionally, introduced \TimeConstants.swift\ containing timestamp type aliases, time duration constants, and extension methods for \Date\, \TimeInterval\, and \Timestamp\ to handle conversions (e.g., milliseconds, microseconds), date differences, and relative date calculations (e.g., yesterday, tomorrow, noon).

BrowserKit/Sources/Shared/Date · high confidence

New shared onboarding UI components and theming support

This change introduces a suite of new shared views and utilities within the OnboardingKit to support the brand refresh and responsive layout requirements. Key additions include AnimatedGradientRenderer and ImageBackgroundView for dynamic, theme-aware backgrounds that switch between animated gradients and static images based on the onboarding variant. SheetSizedCard provides responsive sizing for content cards, while OnboardingSegmentedControl handles multi-choice selections with proper accessibility traits. The UX enum centralizes layout constants, font definitions, and locale-specific logic (such as Japanese text alignment), and OnboardingImageIdentifiers defines asset names for the new brand assets. These components collectively enable the visual updates and responsive behavior seen in the onboarding flow.

BrowserKit/Sources/OnboardingKit/Views/Shared · high confidence

New shared utility extensions for collections, data, strings, and web views

This change introduces a new set of Swift extensions in the BrowserKit Shared package to provide common utility methods across the application. For collections, it adds methods to check for identical elements, perform custom contains checks, compute unions and unique values, and retrieve tail elements or safe indexed access. Data handling is enhanced with SHA-256 and HMAC-SHA256 hashing, UTF-8 string conversion, byte manipulation, and random data generation, alongside hex decoding and base64 encoding for strings. String utilities include URL parsing, escaping, regex matching, and dictionary parsing. UI-related extensions provide CGRect convenience initializers, image tinting and scaling, GIF detection, and transparency analysis. Web view interactions are standardized through extensions that allow JavaScript evaluation in specific content worlds (default or custom) and simplified script message handler registration, supporting both iOS 14+ sandboxed worlds and legacy environments.

BrowserKit/Sources/Shared/Extensions · high confidence

Quick Answers UI: New presentation, error handling, and source display components

The Quick Answers module now includes a custom cross-dissolve presentation animation that zooms the interface from the source button, alongside a dedicated error handler that displays specific alerts for microphone and speech recognition permission denials, daily rate limits, and other service failures. The user interface features an initial Opt-In consent view, a content area with an animated audio waveform for voice recording feedback, and a new source view that displays search results with thumbnails and correctly resolved favicons.

BrowserKit/Sources/QuickAnswersKit/UI · high confidence

Reader mode now caches parsed content and serves it via a custom scheme

Reader mode now persists parsed article content to disk (or memory in private tabs) and serves the final HTML through an internal web server using a custom scheme. This allows the browser to display readerized pages even if the original page is no longer available, and enables background processing of readability results without blocking the UI.

BrowserKit/Sources/WebEngine/WKWebview/Scripts/ReaderMode · high confidence

Architecture

Centralize app constants and configuration in BrowserKit

The app's configuration constants have been consolidated into the BrowserKit package to improve shared access and maintainability. This change introduces a new \AppBuildChannel\ enum (release, beta, developer, other) and an \AppConstants\ class that exposes build channel detection, test environment flags (unit, UI, performance), and critical settings like the daily usage ping preference and IDN support. A new \BrowserKitInformation\ singleton allows other components to inject and access these shared values, while \LaunchArguments\ centralizes test-specific flags (e.g., session restore, skip onboarding) and \StandardImageIdentifiers\ provides a unified registry for all app icons. Additionally, \NotificationConstants\ and \EffectiveTLDNames\ are now part of this shared constants module.

BrowserKit/Sources/Common/Constants · high confidence

Introduces abstraction layer for logging and crash reporting

This change adds new wrapper files (SentryWrapper.swift and SwiftyBeaverWrapper.swift) that define protocols and default implementations for the Sentry crash-reporting SDK and the SwiftyBeaver logging library. By introducing these abstractions, the codebase now decouples its internal logging and error-handling logic from the specific third-party libraries, allowing for easier configuration (such as setting up console and file destinations with specific formats and levels) and potential future swapping of underlying implementations without affecting the rest of the application.

BrowserKit/Sources/Common/Logger/Wrapper · high confidence

New abstraction protocols for application, device, file management, and UI reuse

This change introduces four new protocols in BrowserKit to decouple core system dependencies from the application logic. The \Application\ protocol abstracts URL opening capabilities, \DeviceTypeProvider\ isolates device interface idiom checks, and \FileManagerProtocol\ provides a concurrency-safe (\Sendable\) abstraction for file system operations, addressing Swift 6 migration requirements. Additionally, the \ReusableCell\ protocol and its extensions on \UICollectionView\ and \UITableView\ standardize cell registration and dequeuing by automatically deriving cell identifiers from type names, reducing boilerplate and potential errors in UI code.

BrowserKit/Sources/Common/Protocols · high confidence

Refactored address bar into modular LocationView components

The address bar's UI logic has been restructured into a new, modular component hierarchy within BrowserKit. This change introduces dedicated files for the address bar's core behavior and appearance: \LocationView\ (the main container), \LocationTextField\ (handling text input, autocomplete, and keyboard interactions), \LocationContainer\ (managing shadow and theme application), and supporting types like \LocationViewState\ (configuration) and \LocationViewDelegate\ (event handling). This refactoring isolates the address bar's view logic, improving maintainability and separating concerns between the toolbar layout and the address field's specific interactions.

BrowserKit/Sources/ToolbarKit/AddressToolbar/LocationView · high confidence

Behavioural changes

Add Swift concurrency-safe Deferred and supporting types to BrowserKit

The Shared framework's Deferred implementation and its supporting types (LockProtected, ReadWriteLock, Result, Reachability) have been moved to BrowserKit and updated to support Swift 6 concurrency. The Deferred class now requires its generic type to be Sendable and uses LockProtected with a CASSpinLock for thread safety, while the \all()\ function and \value\ property use DispatchGroups to manage synchronization safely. This change provides a concurrency-safe foundation for asynchronous operations within the BrowserKit module.

BrowserKit/Sources/Shared/Deferred · high confidence

Add placeholder source file for Danger dependencies

A new Swift source file, Fake.swift, has been added to the Sources/DangerDependencies module. This file currently contains only a license header and an import statement, serving as a minimal placeholder within the project structure.

Sources · low confidence

Added Xcode workspace check configuration

An IDE workspace check configuration file has been added to the BrowserKit Swift package workspace. This file ensures that Xcode verifies the workspace structure is consistent and up-to-date, preventing issues related to missing or outdated workspace schemes.

BrowserKit/.swiftpm/xcode/package.xcworkspace · medium confidence

Adds font and image utility extensions for the credential provider UI

The credential provider extension now includes helper utilities for consistent UI styling. UIFontExtension provides static methods to retrieve navigation bar button and title fonts that are locked to the 'large' content size category, ensuring they do not scale with user dynamic type settings. UIImageExtension adds a tinting method to apply a specific color to image assets, supporting the updated visual style.

firefox-ios/CredentialProvider/Extensions · high confidence

Autopush connection verification and subscription management

The Firefox iOS app now includes logic to verify active push subscriptions and automatically re-subscribe any that were dropped by the push servers. This ensures that the device maintains a valid connection for receiving notifications, with the verification process respecting rate limits and storing timestamps to avoid excessive checks. The implementation also handles updating the APNS token, subscribing/unsubscribing to specific scopes, and decrypting incoming push payloads.

firefox-ios/Push · high confidence

Cached favicon URL retrieval with fallback handling

The SiteImageView component now uses a dedicated handler to retrieve favicon URLs, introducing a caching layer that stores resolved URLs to avoid repeated network requests. When a cached URL is unavailable, the system attempts to fetch the favicon from the webpage metadata; if this fetch fails due to a non-client error, it falls back to a default favicon URL derived from the site's domain before ultimately reporting that no favicon was found. Internal URLs are explicitly excluded from fetching to prevent unnecessary network errors.

BrowserKit/Sources/SiteImageView/FaviconURLProcessing · high confidence

Enforce SwiftLint checks and block direct pushes to main

The repository now includes a pre-push hook that automatically runs SwiftLint with strict and quiet modes before allowing a push. If violations are found, the push is blocked until issues are fixed. Additionally, direct pushes to the 'main' branch on the official Mozilla Firefox iOS remote are prohibited to enforce proper code review workflows; pushes must go through forks or pull requests.

.githooks · high confidence

Firefox iOS build process now imports and syncs external build tools

The Firefox iOS build pipeline has been restructured to automatically fetch the \firefox-ios-build-tools\ repository and synchronize its scripts, Fastlane configuration files (Appfile, Snapfile), and helper code (SnapshotHelper.swift) into the project. This change introduces a new \import\_build\_tools\ action to manage the repository checkout and uses rsync to ensure local copies of the build infrastructure are kept in sync, centralizing the build logic outside the main application source tree.

firefox-ios/fastlane · high confidence

Firefox iOS project structure and configuration updates

The Firefox iOS project has been reorganized with new configuration files and documentation. A new \.periphery.yml\ file configures the Periphery static analysis tool to exclude generated sources and specific projects like WebEngine. Entitlements files for Fennec, FennecEnterprise, Firefox, and FirefoxBeta have been added to define application groups and keychain access. A \PrivacyInfo.xcprivacy\ file declares API usage for user defaults and file timestamps. The \README.md\ has been updated with build instructions, including Node.js setup and Xcode macro approval. New scripts \import-strings.sh\ and \l10n-screenshots.sh\ support localization workflows. A \RustMozillaAppServices-Info.plist\ defines the Rust component framework metadata. Finally, \nimbus.fml.yaml\ centralizes feature flags for various capabilities like ad blocking, summarizer, and privacy dashboard.

firefox-ios · high confidence

Focus iOS now automatically dismisses the screen after adding a site to Siri shortcuts

When you add a favorite site to Siri shortcuts, the interface now closes automatically, removing the need to manually dismiss the screen to return to the main view.

focus-ios · high confidence

Improved favicon matching for domains with prefixes or TLDs

The site image view now uses a new BundleDomainBuilder to generate multiple domain variations (short display, absolute URL without scheme, and base domain) when looking up bundled favicons. This ensures that sites with subdomains (like m.facebook) or different top-level domains (like amazon.de) correctly match their bundled favicon assets, which are stored under a canonical name (e.g., 'amazon' or 'facebook').

BrowserKit/Sources/SiteImageView/ImageProcessing/BundleImageFetcher · high confidence

Improved favicon retrieval with HTML scraping and robust network handling

The favicon fetching mechanism now scrapes the site's HTML to locate icon references, including support for HTTP meta-refresh redirects, and falls back to the root domain if no explicit link is found. To ensure compatibility with servers that require specific headers, the underlying network request now includes an Accept header and uses an ephemeral session with a 5-second timeout. Additionally, Multipath TCP (MPTCP) handover support is enabled for the network connection to improve reliability on mobile networks.

BrowserKit/Sources/SiteImageView/FaviconURLProcessing/URLFetcher · high confidence

Introduce BrowserKit Logger with Sentry integration and structured categories

The logging system in BrowserKit has been refactored to use a new \DefaultLogger\ implementation backed by SwiftyBeaver for local console/file logs and Sentry for remote error reporting. This change introduces a structured \LoggerCategory\ enum (covering areas like autofill, homepage, telemetry, and webview) and a \LoggerLevel\ enum (debug, info, warning, fatal) to standardize log output. Crash reporting is now managed via \CrashManager\, which configures Sentry options such as disabling network breadcrumbs and enabling app hang tracking on Beta builds, while ensuring user privacy by respecting the \sendCrashReports\ preference. The \LoggerFileManager\ handles local log storage, including copying logs to the Documents folder for user retrieval and deleting cached files.

BrowserKit/Sources/Common/Logger · high confidence

Introduce animated tab-snapshot transition and error/info states for the Summarize view

The SummarizeKit UI now features a dedicated animation controller that smoothly transitions the tab snapshot into the summary, info, and dismiss states, including haptic feedback and a blurred border overlay during loading. A new SnapshotLayoutCalculator handles layout transforms for both portrait and landscape orientations, ensuring the snapshot moves correctly during rotation. Additionally, the view now supports an InfoView for displaying terms of service or error messages, with a formatter that renders Markdown content and handles localized error descriptions and accessibility labels.

BrowserKit/Sources/SummarizeKit/UI · high confidence

Introduce new Site data model and type system

The Storage/Sites module now uses a new \Site\ struct and \SiteType\ enum to represent bookmarks, suggested sites, sponsored tiles, and pinned sites. This change introduces specific info structs (\PinnedSiteInfo\, \SponsoredSiteInfo\, \SuggestedSiteInfo\) to hold metadata for each site type, replacing the previous implementation. The \Site\ model now supports encoding for widget extensions and includes helper methods for creating different site variants, while removing the \Identifiable\ protocol requirement.

firefox-ios/Storage/Sites · high confidence

Introduce new credential provider UI and presenter logic

The CredentialProvider extension now uses a new set of view controllers and cells to manage the user experience. A welcome screen (CredentialWelcomeViewController) and a passcode requirement screen (CredentialPasscodeRequirementViewController) handle initial setup and device authentication. When credentials are available, a new CredentialListViewController presents a searchable list of saved logins using custom cells (ItemListCell, EmptyPlaceholderCell, NoSearchResultCell, SelectPasswordCell), managed by a new CredentialListPresenter. The main extension entry point (CredentialProviderViewController) coordinates these flows and handles the underlying credential provisioning logic via CredentialProviderPresenter, including retry mechanisms for failed retrievals.

firefox-ios/CredentialProvider · high confidence

Introduce structured SummaryView with title, brand, and text cells

The SummaryView component has been refactored to use a dedicated UITableView-based layout that displays the summary content in three distinct sections: a title, a brand identifier with logo, and the main summary text. This change introduces specific cell types (SummaryTitleCell, SummaryBrandCell, SummaryTextCell) and a corresponding view model to manage the data, enabling consistent theming and accessibility identifiers for each section. The view also includes logic to dynamically adjust the visibility of the title cell based on scroll position, providing a smoother user experience when viewing summarized content.

BrowserKit/Sources/SummarizeKit/UI/SummaryView · high confidence

Introduces modular WebKit navigation policy deciders

The WebEngine now uses a chain of specialized policy deciders to handle navigation requests, replacing the previous monolithic approach. This change introduces distinct handlers for app launches (supporting schemes like tel, sms, facetime, and app store links), data URLs (allowing images, video, PDFs, JSON, and plain text), HTTP/HTTPS schemes, and internal privileged requests. Users will see more consistent handling of external app intents and embedded data resources, with popups and navigations routed through this new, extensible decision chain.

BrowserKit/Sources/WebEngine/WKWebview/Policy · high confidence

Migrate sync and provider infrastructure to Rust-based App Services

The Providers module has been refactored to replace legacy sync and data management with Rust-based App Services components. This introduces a new RustSyncManager to handle synchronization logic, new provider protocols (LoginProvider, AutofillProvider, PlacesProvider, TabsProvider) to interface with Rust storage, and a new TopSitesProviderImplementation for fetching top sites. The Profile now exposes these Rust-backed services, and credential identity synchronization is updated to use the new login provider. This change shifts the underlying implementation of sync, login storage, autofill, and history providers to Rust, improving performance and consistency while maintaining the same public API surface for the rest of the application.

firefox-ios/Providers · high confidence

Move app container into BrowserKit

The concrete dependency container (AppContainer) and its protocol (ServiceProvider) have been moved into the BrowserKit Common package. This change centralizes the core dependency injection infrastructure, allowing client applications to resolve and register services using the shared container without needing to duplicate or tightly couple to the specific implementation details previously located elsewhere.

BrowserKit/Sources/Common/DependencyInjection · high confidence

Native handling for internal browser pages (home and error states)

The WebEngine now intercepts and serves internal browser pages, such as the home panel and error states, using a custom 'internal' URL scheme. This change introduces a dedicated scheme handler that routes requests for paths like 'about/home' and error pages to native responders, which return blank HTML placeholders to prevent visual flicker while the actual native UI panels load. This mechanism allows the browser to manage these specific internal navigation states directly within the WebKit layer rather than relying on external web resources.

BrowserKit/Sources/WebEngine/WKWebview/Internal · high confidence

New URL navigation security checks in WebEngine

The WebEngine now includes a SecurityManager that validates URLs before navigation. It distinguishes between internal and external browsing contexts: internal navigation is permitted only for schemes on the official permanent URI list (plus the internal scheme) and ensures the URL is not just a scheme prefix, while external navigation is restricted to standard web schemes (http, https, data, etc.). This change introduces the underlying security logic for URL validation within the browser engine.

BrowserKit/Sources/WebEngine/Security · high confidence

New navigation toolbar implementation with translucency support

The navigation toolbar has been replaced with a new implementation that supports configurable translucency, allowing the toolbar background to become clear when enabled. It also introduces a toggleable top border, caches toolbar buttons to avoid redundant view rebuilds during state updates, and enables large content viewers for improved accessibility on high-resolution displays.

BrowserKit/Sources/ToolbarKit/NavigationToolbar · high confidence

New protocols and types for JavaScript alert handling

A new file defining the core protocols and types for JavaScript alerts has been added. This introduces \JavaScriptAlertType\ to distinguish between alert, confirm, and text input prompts, along with \JavaScriptAlertInfo\ and \JavaScriptPromptAlertController\ protocols to manage alert lifecycle and dismissal results. These interfaces provide the structural foundation for handling JavaScript alerts within the web engine.

BrowserKit/Sources/WebEngine/WKWebview/Alerts · high confidence

Onboarding flow adopts responsive layouts and iOS 26 glass styling

The onboarding views have been refactored to support a unified, responsive design that adapts to screen size and iOS version. On compact devices, the flow now uses a bottom-sheet presentation with a custom detent height, while regular-width layouts display a centered card with a skip button. The UI styling has been updated to use iOS 26's glass button effects and background materials where available, falling back to standard borderless styles on earlier versions. Additionally, the multiple-choice card now utilizes a segmented control for selection, and the entire flow supports dynamic theme changes and accessibility announcements.

BrowserKit/Sources/OnboardingKit/Views/OnboardingFlow · high confidence

Redux library introduces ModernAction migration and main-thread isolation

The Redux library in BrowserKit now provides a dual-path architecture for actions, reducers, and middleware, allowing developers to migrate from the legacy Action protocol to the new ModernAction protocol. This change introduces ModernAction with automatic debug description generation and updates the Store, DispatchStore, and Middleware types to support both legacy and modern implementations. Additionally, the entire Redux system is now isolated to the main actor to prevent race conditions and ensure thread safety, with the Store class and its core methods explicitly marked for main-thread execution.

BrowserKit/Sources/Redux · high confidence

Replaced legacy SQLite wrapper with new SwiftData implementation

The Storage layer now uses a new, heavily modified version of SwiftData.swift to handle SQLite interactions. This change introduces a connection-based API where callers must explicitly request a connection before executing commands, replacing the previous implicit handling. It also adds support for streaming results via Cursors, correct parameter binding to fix memory leaks with String values, and improved concurrency safety through deferred operations and dispatch queues.

firefox-ios/Storage/ThirdParty · high confidence

SQLite storage layer refactored for Swift 6 concurrency and simplified deferred operators

The SQLite storage implementation in firefox-ios/Storage/SQL has been updated to support Swift 6 strict concurrency by marking core database classes (BrowserDB, BrowserDBSQLite, SQLiteReadingList) as Sendable and introducing async/await methods for operations like removing pinned sites. The codebase also removes the monadic Deferred operators (\>\>==) in favor of standard Swift concurrency patterns and simplifies the database initialization flow. Additionally, the Site model no longer conforms to Identifiable, and the default background tab loader has been adjusted to handle queued tabs without requiring a title.

firefox-ios/Storage/SQL · high confidence

Search engine icon in the address bar now features a dropdown arrow and tap interaction

The search engine icon in the toolbar has been updated to include a dropdown chevron, indicating that it is now an interactive element. Tapping the icon will trigger a dropdown action (handled by the new DropDownSearchEngineView), allowing users to select a different search engine. The icon itself now has rounded corners (4dp on older iOS versions, 12dp on iOS 26+), and the view supports theming for background and icon colors. A plain, non-interactive variant (PlainSearchEngineView) is also available for contexts where the dropdown is not needed.

BrowserKit/Sources/ToolbarKit/AddressToolbar/LocationView/SearchEngineView · high confidence

ShareTo extension rewritten with new UI and Rust integration

The ShareTo extension has been completely rewritten to provide a modern, responsive popup interface for sharing content to Firefox. The new implementation introduces a dedicated EmbeddedNavController to manage the popup's layout and height constraints, ensuring proper behavior across different screen sizes and orientations (including landscape mode on small screens). It integrates with MozillaAppServices and Viaduct for networking and Rust-based components, initializing these services within the extension context. The UI now features a theme-aware design using StandardImageIdentifiers, supports actions like 'Open in Firefox', 'Load in Background', 'Bookmark', 'Add to Reading List', and 'Send to Device', and includes improved error handling and telemetry reporting for share actions.

firefox-ios/Extensions/ShareTo · high confidence

Swift 6 migration enabled at project level

The Firefox iOS project has enabled Swift 6 strict concurrency checking at the project level. This change enforces modern concurrency safety rules across the codebase, requiring developers to resolve data-race warnings and migrate existing code to be fully Sendable-compatible.

firefox-ios/Client.xcodeproj · high confidence

Updated monorepo migration regexes for Firefox iOS issue references

The monorepo-migration tool now uses an expanded set of regular expressions in \data/message-expressions.txt\ to correctly identify and rewrite references to Firefox iOS issues (e.g., \\#12345\) into their corresponding GitHub URLs. This update extends the range of supported issue numbers, ensuring that a broader set of historical and recent issue references are properly migrated during the monorepo transition.

monorepo-migration · high confidence

Xcode workspace and scheme configuration updates

The Xcode project workspace now includes shared configuration files, such as IDE template macros for standard MPL headers and workspace settings. New or updated build schemes (including Firefox, FirefoxBeta, Fennec, and Enterprise variants) define specific build targets, test plans, and skipped tests, while performance baselines for storage and history tests are added to track wall-clock time metrics.

firefox-ios/Client.xcodeproj/xcshareddata · high confidence

Fixes

Fixes for tab tray thumbnail display and title text issues

Resolves two bugs in the tab tray: thumbnails that failed to appear after the app was in the background for an extended period are now displayed correctly, and tab titles that were showing incorrect text have been fixed.

firefox-ios/Client · high confidence

Test coverage

Add Experiment Integration Test Suite for iOS; Added DependencyHelperMock for test isolation; Added L10n snapshot tests for Firefox iOS; Added MockState test double for Redux testing; Added Nimbus onboarding test configuration utility; Added UI tests for authentication, login management, and private data clearing; Added accessibility audit tests for key app screens; Added coordinator and middleware test mocks; Added mock implementations and tests for Microsurvey middleware; Added mock implementations for Quick Answers testing; Added mock implementations for WebEngine test infrastructure; Added mock implementations for homepage manager and telemetry interfaces; Added mock implementations for tab management test infrastructure; Added mock implementations for wallpaper networking and manager tests; Added mock providers for credit card and login autofill tests; Added mock utilities for Nimbus JEXL evaluation in onboarding tests; Added telemetry tests for the app icon selection screen; Added test coverage for Redux ModernAction and Store dispatch behavior; Added test coverage for Summarizer language and configuration logic; Added test coverage for the Unified Ads homepage component; Added test mocks for SummarizeKit components; Added test utilities and coverage for WebEngine components; Added test utilities for Redux legacy and modern action patterns; Added tests for App Attest client and LLMKit components; Added tests for DynamicFontHelper utility; Added tests for Nimbus targeting context and localization integration; Added tests for Nova theming, missing token handling, and WidgetKit theme management; Added tests for Quick Answers results service and configuration; Added tests for Quick Answers telemetry, middleware, and remote configuration; Added tests for Remote Settings integration and search engine preferences; Added tests for WebEngine popup navigation policy deciders; Added tests for contextual hint eligibility and configuration; Added tests for security manager navigation rules; Added unit tests for AI Controls settings and model logic; Added unit tests for ActionExtensionKit URL building and item extraction; Added unit tests for Autofill components; Added unit tests for Autopush connection verification logic; Added unit tests for BrowserViewController behavior and state management; Added unit tests for BrowserViewController layout constraints; Added unit tests for Common library extensions; Added unit tests for ComponentLibrary views and view models; Added unit tests for ContentBlockingGenerator parsing and generation; Added unit tests for Enhanced Tracking Protection components; Added unit tests for FxA WebView telemetry flows; Added unit tests for Google Lens image processing and request building; Added unit tests for GradientProgressBar RTL support and animation behavior; Added unit tests for Homepage Context Menu configuration and coordinator; Added unit tests for Homepage Redux state and middleware; Added unit tests for JWTKit components; Added unit tests for JumpBackInViewModel; Added unit tests for LaunchView coordinators and view models; Added unit tests for Library coordinators; Added unit tests for Library panel components; Added unit tests for MLPAKit App Attest authentication and JWT handling; Added unit tests for MenuKit components; Added unit tests for Merino category and provider logic; Added unit tests for NotificationSurfaceManager; Added unit tests for OnboardingKit components; Added unit tests for OneLineTableViewCell layout and configuration; Added unit tests for Password Generator state, telemetry, and view controller; Added unit tests for Quick Answers Kit; Added unit tests for Quick Answers settings UI; Added unit tests for Quick Answers speech service components; Added unit tests for SKAdNetwork conversion tracking components; Added unit tests for Shared framework utilities; Added unit tests for Shortcuts Library Redux logic; Added unit tests for ShortcutsLibraryViewController lifecycle actions; Added unit tests for SiteImageView components; Added unit tests for SiteImageView image processing components; Added unit tests for StartAtHome logic and middleware; Added unit tests for SummarizeKit components; Added unit tests for Sync module cryptography and Rust API; Added unit tests for Tab Tray Redux state management; Added unit tests for Tab Tray coordinators; Added unit tests for TabDataStore and TabFileManager; Added unit tests for Themeable subview and theme application logic; Added unit tests for ToolbarKit components; Added unit tests for WebCompatReporterKit UI components; Added unit tests for WebEngine components; Added unit tests for WebEngine content scripts and managers; Added unit tests for WebView data scheme filtering; Added unit tests for application startup, authentication, and deeplink handling; Added unit tests for background tab loading, telemetry uploaders, and utility classes; Added unit tests for client helper components; Added unit tests for credit card autofill components; Added unit tests for favicon URL processing components; Added unit tests for frontend components and history recording; Added unit tests for search components and telemetry; Added unit tests for search engine selection and management; Added unit tests for telemetry across multiple Firefox iOS features; Added unit tests for the Coordinator architecture; Added unit tests for the Launch Coordinator and Launch Type logic; Added unit tests for the Logger subsystem; Added unit tests for the Native Error Page feature; Added unit tests for the Summarizer middleware; Added unit tests for the Survey Surface Manager and ViewModel; Added unit tests for the Tab Tray feature area; Added unit tests for the Terms of Use feature; Added unit tests for the Toolbar subsystem; Added unit tests for the Translations feature; Added unit tests for the Wallpaper feature; Added unit tests for the Web Compat Reporter data collection and submission flow; Added unit tests for the custom Reader Mode scheme handler and caching logic; Added unit tests for the iOS download subsystem; Added unit tests for the iOS sharing infrastructure; Added unit tests for the messaging system; Added unit tests for the modern onboarding flow; Added unit tests for the new Bookmarks UI components; Added unit tests for the new Homepage UI components and layout logic; Added unit tests for the redesigned main menu; Added unit tests for utility and UI extension methods; Added wallpaper metadata test fixtures and providers; Expanded unit test coverage for Firefox iOS core components; Expanded unit test coverage for tab management and swipe-up gestures; Initial Sync Integration Test Suite for Firefox iOS; New UI test selectors for Autofill, Credit Cards, and Browser components; New test infrastructure and unit tests for markup parsing; New test mocks for database lifecycle, authentication, and browser view controllers; New test page objects for AI Controls, Autofill, and Browser interactions; New test suite for Storage subsystem components.

Dependencies

Introduce BrowserKit Swift Package with resolved dependencies

The BrowserKit location now includes a Package.swift manifest and a Package.resolved lockfile, establishing it as a distinct Swift Package Manager package. This change pins specific dependency versions for the project, including Kingfisher 8.12.0, Sentry 9.10.0, Dip 7.1.1, SwiftyBeaver 2.1.1, SwiftDraw 0.29.0, Down 0.11.0, and the master branches of Fuzi and GCDWebServer, ensuring reproducible builds for the shared libraries defined in this package.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 32 → 49 (+17.2)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 32 → 36 (+4.4)
  • Architecture 97 → 98 (+1.0)
  • Maturity 49 → 74 (+24.9)
  • Readiness 17 → 55 (+37.2)
  • Security 52 → 59 (+7.4)
  • Accessibility 62 (new)

Resolved (120)

  • (anonymous) (cognitive 16) (firefox-ios/Client/Frontend/UserContent/UserScripts/MainFrame/AtDocumentStart/ReaderMode.js)
  • (anonymous) (cognitive 18) (firefox-ios/Client/Assets/CC_Script/translations-document.sys.mjs)
  • (anonymous) (cognitive 35) (focus-ios/Blockzilla/MetadataHelper.js)
  • (anonymous) (cognitive 45) (firefox-ios/Client/Assets/CC_Script/translations-document.sys.mjs)
  • (anonymous) (cyclomatic 20) (firefox-ios/Client/Assets/CC_Script/translations-document.sys.mjs)
  • Context is a single sentence ('We need to record the architectural decisions made on this project.') with no rationale and consequences are mostly positive benefits (one ADR per decision) without any trade-offs or opposing forces (adr/0000-use-markdown-architectural-decision-records.md)
  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • FileTooLong: CC_Script/PasswordRulesParser.sys.mjs (firefox-ios/Client/Assets/CC_Script/PasswordRulesParser.sys.mjs)
  • FileTooLong: CC_Script/translations-engine.worker.js (firefox-ios/Client/Assets/CC_Script/translations-engine.worker.js)
  • FindMetaDataForRegion (cognitive 26) (firefox-ios/Client/Assets/CC_Script/PhoneNumber.sys.mjs)
  • FormatNumber (cognitive 25) (firefox-ios/Client/Assets/CC_Script/PhoneNumber.sys.mjs)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 100 more

New (1563)

  • #submitForAttributeTranslation (cognitive 22) (firefox-ios/Client/Assets/CC_Script/translations-document.sys.mjs)
  • #submitForContentTranslation (cognitive 33) (firefox-ios/Client/Assets/CC_Script/translations-document.sys.mjs)
  • #submitForContentTranslation (cyclomatic 18) (firefox-ios/Client/Assets/CC_Script/translations-document.sys.mjs)
  • (anonymous) (cognitive 43) (focus-ios/Blockzilla/MetadataHelper.js)
  • (anonymous) (cyclomatic 20) (focus-ios/Blockzilla/MetadataHelper.js)
  • (anonymous) (cyclomatic 67) (firefox-ios/Client/Assets/CC_Script/PhoneNumber.sys.mjs)
  • (anonymous)::FindMetaDataForRegion (cognitive 26) (firefox-ios/Client/Assets/CC_Script/PhoneNumber.sys.mjs)
  • (anonymous)::FormatNumber (cognitive 28) (firefox-ios/Client/Assets/CC_Script/PhoneNumber.sys.mjs)
  • (anonymous)::_fillForm (cognitive 27) (firefox-ios/Client/Frontend/UserContent/UserScripts/AllFrames/AtDocumentStart/LoginsHelper.js)
  • (anonymous)::_fillForm (cyclomatic 27) (firefox-ios/Client/Frontend/UserContent/UserScripts/AllFrames/AtDocumentStart/LoginsHelper.js)
  • (anonymous)::_getFormFields (cognitive 20) (firefox-ios/Client/Frontend/UserContent/UserScripts/AllFrames/AtDocumentStart/LoginsHelper.js)
  • (anonymous)::onFocusIn (cyclomatic 16) (firefox-ios/Client/Frontend/UserContent/UserScripts/AllFrames/AtDocumentStart/LoginsHelper.js)
  • ASSearchEngineIconDataFetcher.populateEngineIconData (cognitive 20) (firefox-ios/Client/Application/RemoteSettings/Application Services/ASSearchEngineIconDataFetcher.swift)
  • ActionViewController.configurationItems (cognitive 23) (focus-ios/OpenInFocus/ActionViewController.swift)
  • AddressRecord.#computeTelFields (cognitive 27) (firefox-ios/Client/Assets/CC_Script/AddressRecord.sys.mjs)
  • AddressToolbarContainerModel.== (cognitive 27) (firefox-ios/Client/Frontend/Browser/Toolbars/Models/AddressToolbarContainerModel.swift)
  • AddressToolbarContainerModel.== (cyclomatic 28) (firefox-ios/Client/Frontend/Browser/Toolbars/Models/AddressToolbarContainerModel.swift)
  • AppDataUsageReportSetting.generateAppDataSummary (cognitive 38) (firefox-ios/Client/Frontend/Settings/Main/Debug/AppDataUsageReportSetting.swift)
  • AppDataUsageReportSetting.generateAppDataSummary (cyclomatic 16) (firefox-ios/Client/Frontend/Settings/Main/Debug/AppDataUsageReportSetting.swift)
  • Assertions commented out: testFetchMetadataGivenDidFinishNavigationThenFetchMetadata (BrowserKit/Tests/WebEngineTests/WKEngineSessionTests.swift)
  • …and 1543 more

Changes since last survey

  • 300 commits — 175 feature/other, 125 fixes

By area

  • firefox-ios/Client — 125 commits
  • firefox-ios/firefox-ios-tests — 54 commits
  • BrowserKit/Sources — 33 commits
  • (root) — 27 commits
  • MozillaRustComponents/Sources — 20 commits
  • firefox-ios/Shared — 18 commits
  • focus-ios/Blockzilla — 6 commits
  • firefox-ios/Client.xcodeproj — 5 commits
  • firefox-ios/nimbus-features — 5 commits
  • .github/workflows — 3 commits
  • BrowserKit/Tests — 1 commit
  • firefox-ios/README.md — 1 commit
  • firefox-ios/ThirdParty — 1 commit
  • firefox-ios/bin — 1 commit

Notable commits

  • fix: Add Bug-2062665 [Suggest] Add new suggestionId field on Suggestion.amp (#35272)
  • fix: Add FXIOS-16188 [WebCompat] VoiceOver fixes for the report sheet (#35345)
  • fix: Add MTE-5710 Add regression tag to all automated regression tests (#35377)
  • fix: Automatic version bump CLOSED TREE NO BUG a=release
  • fix: Automatic version bump CLOSED TREE NO BUG a=release
  • fix: Automatic version bump CLOSED TREE NO BUG a=release
  • fix: Automatic version bump CLOSED TREE NO BUG a=release
  • fix: Automatic version bump CLOSED TREE NO BUG a=release
  • fix: Automatic version bump CLOSED TREE NO BUG a=release
  • fix: Automatic version bump CLOSED TREE NO BUG a=release
  • fix: BugFix FXIOS-16667 [Acorn] Support ExtraExtraExtraLarge icon size in the Acorn updater (#35382)
  • fix: BugFix FXIOS-16777 [Quick Answers] Pass the source faviconURL as a SiteResource so favicons resolve correctly (#35570)
  • fix: BugFix FXIOS-16796 [WebEngine] Stop WKEngineWebViewTests hanging on network loads (#35610)
  • fix: BugFix FXIOS-16923 [Summarizer] Keep the summary navigation bar background full width on iOS 27+ (#35778)
  • fix: Bugfix #27439 [Print] Use page titles for PDF filenames (#35206)
  • fix: Bugfix FX-14729 Close Old Tabs skipping automatically selected tab (#35633)
  • fix: Bugfix FXIOS-11115 [Error page] Show guidance for restricted cellular data (#34690)
  • fix: Bugfix FXIOS-13424 [Swipe tabs] Hide preview at tab boundary (#35631)
  • fix: Bugfix FXIOS-13501 [OHTTP] Make OhttpManager an actor to fix key cache data race (#35245)
  • fix: Bugfix FXIOS-14272 - Private browsing mode's toolbar buttons intermittently have no icon symbols (#35138)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mozilla-mobile/firefox-ios was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5338f3c125931d1fe0cc0c4a3c890ebecf866902 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.