* feat: broaden CPU and platform coverage across PyPI, nodes, and crates.io
Replace static SIMD with runtime CPU-feature dispatch and expand the release
wheel matrix so one set of artifacts runs on any target CPU and platform
without illegal-instruction crashes.
Rust core:
- Add multiversion runtime dispatch (crates/ferro_ta_core/src/simd.rs); drop
compile-time `wide`. `simd` feature is now default-on and forwarded through
the pyo3 crate, and stays compatible with #![forbid(unsafe_code)].
Packaging:
- abi3-py310: one cp310-abi3 wheel per platform (covers CPython 3.10+).
- CI matrix adds Linux aarch64 + musllinux (x86_64/aarch64) and Windows arm64.
Node/Docker + docs:
- api/Dockerfile: document baseline+dispatch (no target-cpu pin) and add a
fail-fast import check; aarch64 containers now install cleanly.
- Rewrite docs/guides/simd.md; fix stale `wide` mention in ADR 0003.
- Add ADR 0006 (CPU coverage strategy).
Also bundles in-flight release prep already staged in the tree (DTW exception
types, SBOM/provenance security, supporting docs).
* fix(ci): clear cargo-deny and pip-audit failures; apply dependency bumps
cargo-deny (advisories):
- Ignore pyo3 RUSTSEC-2026-0176 / RUSTSEC-2026-0177 in deny.toml with a
documented rationale: ferro-ta uses neither affected code path
(PyList/PyTuple nth iterators; PyCFunction::new_closure). Upstream fix
needs pyo3 >=0.29 (large API migration), tracked as a follow-up.
pip-audit:
- Bump dev lockfile idna 3.18, pytest 9.1.1, urllib3 2.7.0 to clear
PYSEC-2026-215, CVE-2025-71176, PYSEC-2026-141/142.
Dependency bumps (supersede open dependabot PRs; they auto-close on merge):
- cargo: log 0.4.32, serde_json 1.0.150, rayon 1.12.0
- api/requirements.txt: uvicorn>=0.49.0, pydantic>=2.13.4, ferro-ta>=1.1.4
- CI actions: deploy-pages v5, upload-pages-artifact v5, action-gh-release v3
The open `wide` 1.5.0 bump (PR #24) is obsolete — the crate is removed in
this branch.
* chore: address CodeRabbit review; remove docs/adr section
CodeRabbit findings:
- CI sbom job: add `attestations: write` so attest-build-provenance can run
(it had only contents:write + id-token:write).
- simd.rs: vectorize `wma_seed` with lane-local accumulators — it was scalar
behind the multiversion wrapper, adding dispatch overhead for no SIMD gain.
- CHANGELOG: consolidate the duplicate `### Changed` heading.
- python/ferro_ta/__init__.py: also re-export the `FerroTaError` alias.
- docs/guides/dtw.md: soften "byte-for-byte" parity to within-tolerance.
Remove docs/adr/ at maintainer request and clean up the ADR links in the
SIMD and DTW guides. The ADR files remain in commit 9506a30 if ever needed.
Prepare the first public 1.0.0 release and finish the remaining CI hardening work.
Highlights:
- align Python, Rust, WASM, Conda, API, MCP, and docs version metadata to 1.0.0
- promote package metadata to Production/Stable and update stability/versioning docs for the stable series
- move the accumulated Unreleased notes into a dated 1.0.0 changelog section and keep a fresh top-level Unreleased block
- strengthen the changelog checker so it validates a single top-level Unreleased section
- fix the CI/package support mismatch by declaring Python >=3.10 consistently and gating pandas-ta extras to Python 3.12+
- restore Sphinx autodoc compatibility for documented ferro_ta.<module> imports by registering module aliases
- make the TA-Lib benchmark guardrail less flaky by checking median and tail-percentile speedups instead of failing on a single mild outlier
- switch PyPI publishing to OIDC-only trusted publishing and wire the changelog check into the required CI gate
- apply the Ruff-driven cleanup across the Python and test tree and refresh uv/cargo lockfiles
Validated locally:
- python3 scripts/check_changelog.py
- uv run --with ruff ruff check python tests
- uv run --with ruff ruff format --check python tests
- uv lock --check
- sphinx-build -b html docs docs/_build -W --keep-going
- build/install the ferro_ta 1.0.0 wheel successfully