The fuzz suite previously covered only `Rsi(14)` and `Ema(20)` — 2 of
71 indicators, no OHLCV coverage at all. Audit finding R9 asked for
ATR/ADX/Stochastic/PSAR as a minimum; this commit goes further and
brings every indicator under fuzz.
- `indicator_update` (rewritten): drives every scalar-input indicator
through one streaming pass + one batch call per iteration. Covers
SMA, EMA, WMA, RSI, DEMA, TEMA, HMA, ROC, TRIX, SMMA, TRIMA, ZLEMA,
KAMA, T3, MOM, CMO, TSI, PMO, StochRSI, DPO, PPO, Coppock, StdDev,
UlcerIndex, HistoricalVolatility, LinearRegression, LinRegSlope,
LinRegAngle, VHF, ZScore, MACD, BollingerBands. A `drive` helper
marked `#[inline(never)]` keeps each indicator on its own panic
backtrace frame.
- `indicator_update_candle` (new): chunks the fuzz `f64` stream into
`[open, high, low, close, volume]` tuples, builds candles via
`Candle::new` (skipping ones that fail OHLCV validation — that path
is fuzz-tested separately), then drives every candle-input indicator
through streaming + batch. Covers ATR, NATR, TrueRange,
ChaikinVolatility, Keltner, Donchian, PSAR, SuperTrend,
ChandelierExit, ChandeKrollStop, ATRTrailingStop, ADX, Aroon,
AroonOscillator, Vortex, MassIndex, ChoppinessIndex, CCI, WilliamsR,
AwesomeOscillator, AcceleratorOscillator, UltimateOscillator,
BalanceOfPower, OBV, MFI, VWAP, RollingVWAP, VWMA, ADL, VPT, CMF,
ChaikinOscillator, ForceIndex, EaseOfMovement, TypicalPrice,
MedianPrice, WeightedClose, Stochastic.
- `fuzz/Cargo.toml` registers the new target; `fuzz/README.md`
describes both expanded targets.
- A `fuzz-smoke` CI job runs each of the five targets for 30 s on
every push and pull-request — enough to catch a regression in the
harness without slowing CI to a crawl. Long fuzz campaigns belong
on dedicated infrastructure with persistent corpora.
CI had no coverage measurement, and although .gitignore listed coverage
artefacts nothing produced them.
Add a `coverage` job that runs cargo-llvm-cov over the three pure-Rust
crates (with wickra-data's live-binance feature so the Binance parser
tests count), emits lcov, and uploads to Codecov. The Codecov upload
uses fail_ci_if_error: false so a Codecov outage cannot break CI. Both
new actions (taiki-e/install-action, codecov/codecov-action) are
SHA-pinned. Add a coverage badge to the README.
The repository had no supply-chain auditing — no deny.toml and no CI
job to catch vulnerable, unmaintained, wrongly-licensed, or
unexpectedly-sourced dependencies.
Add deny.toml covering advisories, bans, licenses and sources:
- licenses: an allow-list of the permissive licenses the dependency
tree actually uses, plus the workspace's own PolyForm-Noncommercial
license and a scoped LLVM-exception for target-lexicon.
- bans: warn on duplicate versions, deny external wildcard deps
(internal path deps are allowed).
- sources: only crates.io.
- advisories: RUSTSEC-2025-0020 (pyo3 0.22) is ignored with a documented
reason — it is reachable only through bindings/python and the pyo3
upgrade is tracked separately; the published crates do not use pyo3.
Add a `supply-chain` CI job running cargo-deny-action (SHA-pinned).
`cargo deny check` passes locally: advisories/bans/licenses/sources ok.
Every CI job used dtolnay/rust-toolchain on stable, so the declared
minimum supported Rust version was never exercised — an accidental use
of a newer API would only break for downstream users on an older
compiler.
Add an `msrv` job with a two-row matrix: the workspace crates
(wickra-core, wickra, wickra-data) build and test on Rust 1.75, and the
node binding on Rust 1.77, matching the rust-version each manifest
declares. Both rows use the SHA-pinned toolchain action.
Every action in ci.yml and release.yml was pinned to a movable tag
(actions/checkout@v4, dtolnay/rust-toolchain@stable, ...). A compromised
upstream tag would run with access to the crates.io / PyPI / npm
publish tokens.
Pin every `uses:` to the full 40-character commit SHA the referenced
ref currently resolves to, with the human-readable version kept as a
trailing comment so Dependabot can still bump them:
actions/checkout v4.3.1
actions/setup-python v5.6.0
actions/setup-node v4.4.0
actions/upload-artifact v4.6.2
actions/download-artifact v4.3.0
dtolnay/rust-toolchain stable branch @ 2026-03-27
Swatinem/rust-cache v2
jetli/wasm-pack-action v0.4.0
PyO3/maturin-action v1.51.0
softprops/action-gh-release v2.6.2
SHAs were resolved against the GitHub API. The github-actions Dependabot
ecosystem that keeps these pins current is added with E3.
The WASM binding had no tests; CI only checked that artefacts existed.
Adds a wasm-bindgen-test suite covering SMA reference values, EMA
batch==streaming equivalence, RSI pure-uptrend behaviour, fallible
constructors returning JsError, and the unequal-length batch guards from
B3. Wires wasm-pack test --node into the CI wasm job. The suite
type-checks on the host; it executes under wasm-pack in CI (the local
environment is a non-rustup Rust install without the wasm32 target).
The Windows Node 18 and Node 20 CI jobs failed because:
- ci.yml ran 'napi build --release' (no --platform), which produces a
filename without the target triple ('wickra.node').
- The committed loader at bindings/node/index.js looked for the
triple-suffixed file ('wickra.win32-x64-msvc.node') and then for the
per-platform npm subpackage as a fallback.
- 'wickra-win32-x64-msvc' isn't on npm yet (blocked by the spam filter),
so Windows had nothing to load. Linux and macOS passed only because
their optionalDependencies do exist on npm and got fetched.
Two-part fix:
- ci.yml now runs 'napi build --platform --release', matching release.yml.
--platform encodes the target triple in the filename, so the loader's
primary lookup always finds the freshly built binary on every host.
- bindings/node/index.js is now the canonical napi-rs auto-generated
loader (it gets regenerated by 'napi build'). It covers all the platforms
napi knows about (linux glibc/musl, Android, FreeBSD, ARM, etc.) rather
than just the four we publish, so unsupported platforms get a clear
'this binding isn't built for your system' error instead of a confusing
ENOENT.
Local sanity: 'npx napi build --platform --release' then 'node --test
__tests__/' succeeds end to end on Windows; the eight existing tests
pass.
Two unrelated failures in the post-release CI run:
- Python jobs: `maturin develop` requires an activated virtualenv on
CI runners that don't have a system Python set up that way. Switch
to `maturin build --release --out dist` followed by `pip install
--find-links dist`, which is venv-agnostic and OS-portable.
- WASM job: the wasm-opt bundled with wasm-pack is older than the WASM
features rustc 1.92 enables by default. The fix is to opt every feature
in explicitly via the package metadata — reference-types, multivalue,
bulk-memory, sign-ext, mutable-globals, nontrapping-float-to-int — so
wasm-opt accepts the input.
Same code as before; only the build steps and the wasm-opt config changed.
A multi-language technical analysis library: 25 indicators across trend,
momentum, volatility, and volume families, every one a state machine with
O(1) per-tick updates. Batch evaluation is provided by a blanket extension
trait over the streaming primitive, so live trading bots and historical
backtests run the same code path.
What ships in this initial drop:
crates/wickra-core - 25 indicators, Indicator/BatchExt/Chain traits,
OHLCV types with validation; 171 unit tests,
property tests, Wilder/Bollinger textbook tests.
crates/wickra - top-level facade + criterion benches for every
indicator at 1K/10K/100K series sizes.
crates/wickra-data - streaming CSV reader, tick-to-candle aggregator,
multi-timeframe resampler, Binance Spot kline
WebSocket adapter behind feature live-binance;
11 unit + 1 doctest.
bindings/python - PyO3 + maturin, NumPy I/O, type stubs (.pyi),
56 pytest tests including streaming==batch
equivalence, Wilder reference values, lifecycle.
bindings/node - napi-rs native module, TypeScript .d.ts
auto-generated, 7 node --test cases.
bindings/wasm - wasm-bindgen ES module for browser/bundler/Node;
interactive HTML demo at examples/index.html.
examples/ - Python and Rust scripts: backtest, live trading,
parallel multi-asset, multi-timeframe, Binance.
benchmarks/ - cross-library comparison against TA-Lib,
pandas-ta, finta, talipp; Wickra wins every
category by 11-1030x (batch) and 17x+ streaming.
.github/workflows/ - CI matrix (Rust + Python + Node + WASM on
Linux/macOS/Windows), release pipeline for
PyPI wheels and npm.
Indicators (25):
Trend SMA EMA WMA DEMA TEMA HMA KAMA
Momentum RSI MACD Stochastic CCI ROC WilliamsR ADX MFI TRIX
AwesomeOscillator Aroon
Volatility BollingerBands ATR Keltner Donchian PSAR
Volume OBV VWAP (cumulative + rolling)
cargo clippy --workspace --all-targets -D warnings is clean. License: Apache-2.0.