CI had no coverage measurement, and although .gitignore listed coverage
artefacts nothing produced them.
Add a `coverage` job that runs cargo-llvm-cov over the three pure-Rust
crates (with wickra-data's live-binance feature so the Binance parser
tests count), emits lcov, and uploads to Codecov. The Codecov upload
uses fail_ci_if_error: false so a Codecov outage cannot break CI. Both
new actions (taiki-e/install-action, codecov/codecov-action) are
SHA-pinned. Add a coverage badge to the README.
The repository had no supply-chain auditing — no deny.toml and no CI
job to catch vulnerable, unmaintained, wrongly-licensed, or
unexpectedly-sourced dependencies.
Add deny.toml covering advisories, bans, licenses and sources:
- licenses: an allow-list of the permissive licenses the dependency
tree actually uses, plus the workspace's own PolyForm-Noncommercial
license and a scoped LLVM-exception for target-lexicon.
- bans: warn on duplicate versions, deny external wildcard deps
(internal path deps are allowed).
- sources: only crates.io.
- advisories: RUSTSEC-2025-0020 (pyo3 0.22) is ignored with a documented
reason — it is reachable only through bindings/python and the pyo3
upgrade is tracked separately; the published crates do not use pyo3.
Add a `supply-chain` CI job running cargo-deny-action (SHA-pinned).
`cargo deny check` passes locally: advisories/bans/licenses/sources ok.
Every CI job used dtolnay/rust-toolchain on stable, so the declared
minimum supported Rust version was never exercised — an accidental use
of a newer API would only break for downstream users on an older
compiler.
Add an `msrv` job with a two-row matrix: the workspace crates
(wickra-core, wickra, wickra-data) build and test on Rust 1.75, and the
node binding on Rust 1.77, matching the rust-version each manifest
declares. Both rows use the SHA-pinned toolchain action.
Every action in ci.yml and release.yml was pinned to a movable tag
(actions/checkout@v4, dtolnay/rust-toolchain@stable, ...). A compromised
upstream tag would run with access to the crates.io / PyPI / npm
publish tokens.
Pin every `uses:` to the full 40-character commit SHA the referenced
ref currently resolves to, with the human-readable version kept as a
trailing comment so Dependabot can still bump them:
actions/checkout v4.3.1
actions/setup-python v5.6.0
actions/setup-node v4.4.0
actions/upload-artifact v4.6.2
actions/download-artifact v4.3.0
dtolnay/rust-toolchain stable branch @ 2026-03-27
Swatinem/rust-cache v2
jetli/wasm-pack-action v0.4.0
PyO3/maturin-action v1.51.0
softprops/action-gh-release v2.6.2
SHAs were resolved against the GitHub API. The github-actions Dependabot
ecosystem that keeps these pins current is added with E3.
The WASM binding had no tests; CI only checked that artefacts existed.
Adds a wasm-bindgen-test suite covering SMA reference values, EMA
batch==streaming equivalence, RSI pure-uptrend behaviour, fallible
constructors returning JsError, and the unequal-length batch guards from
B3. Wires wasm-pack test --node into the CI wasm job. The suite
type-checks on the host; it executes under wasm-pack in CI (the local
environment is a non-rustup Rust install without the wasm32 target).
The Windows Node 18 and Node 20 CI jobs failed because:
- ci.yml ran 'napi build --release' (no --platform), which produces a
filename without the target triple ('wickra.node').
- The committed loader at bindings/node/index.js looked for the
triple-suffixed file ('wickra.win32-x64-msvc.node') and then for the
per-platform npm subpackage as a fallback.
- 'wickra-win32-x64-msvc' isn't on npm yet (blocked by the spam filter),
so Windows had nothing to load. Linux and macOS passed only because
their optionalDependencies do exist on npm and got fetched.
Two-part fix:
- ci.yml now runs 'napi build --platform --release', matching release.yml.
--platform encodes the target triple in the filename, so the loader's
primary lookup always finds the freshly built binary on every host.
- bindings/node/index.js is now the canonical napi-rs auto-generated
loader (it gets regenerated by 'napi build'). It covers all the platforms
napi knows about (linux glibc/musl, Android, FreeBSD, ARM, etc.) rather
than just the four we publish, so unsupported platforms get a clear
'this binding isn't built for your system' error instead of a confusing
ENOENT.
Local sanity: 'npx napi build --platform --release' then 'node --test
__tests__/' succeeds end to end on Windows; the eight existing tests
pass.
Two unrelated failures in the post-release CI run:
- Python jobs: `maturin develop` requires an activated virtualenv on
CI runners that don't have a system Python set up that way. Switch
to `maturin build --release --out dist` followed by `pip install
--find-links dist`, which is venv-agnostic and OS-portable.
- WASM job: the wasm-opt bundled with wasm-pack is older than the WASM
features rustc 1.92 enables by default. The fix is to opt every feature
in explicitly via the package metadata — reference-types, multivalue,
bulk-memory, sign-ext, mutable-globals, nontrapping-float-to-int — so
wasm-opt accepts the input.
Same code as before; only the build steps and the wasm-opt config changed.
A multi-language technical analysis library: 25 indicators across trend,
momentum, volatility, and volume families, every one a state machine with
O(1) per-tick updates. Batch evaluation is provided by a blanket extension
trait over the streaming primitive, so live trading bots and historical
backtests run the same code path.
What ships in this initial drop:
crates/wickra-core - 25 indicators, Indicator/BatchExt/Chain traits,
OHLCV types with validation; 171 unit tests,
property tests, Wilder/Bollinger textbook tests.
crates/wickra - top-level facade + criterion benches for every
indicator at 1K/10K/100K series sizes.
crates/wickra-data - streaming CSV reader, tick-to-candle aggregator,
multi-timeframe resampler, Binance Spot kline
WebSocket adapter behind feature live-binance;
11 unit + 1 doctest.
bindings/python - PyO3 + maturin, NumPy I/O, type stubs (.pyi),
56 pytest tests including streaming==batch
equivalence, Wilder reference values, lifecycle.
bindings/node - napi-rs native module, TypeScript .d.ts
auto-generated, 7 node --test cases.
bindings/wasm - wasm-bindgen ES module for browser/bundler/Node;
interactive HTML demo at examples/index.html.
examples/ - Python and Rust scripts: backtest, live trading,
parallel multi-asset, multi-timeframe, Binance.
benchmarks/ - cross-library comparison against TA-Lib,
pandas-ta, finta, talipp; Wickra wins every
category by 11-1030x (batch) and 17x+ streaming.
.github/workflows/ - CI matrix (Rust + Python + Node + WASM on
Linux/macOS/Windows), release pipeline for
PyPI wheels and npm.
Indicators (25):
Trend SMA EMA WMA DEMA TEMA HMA KAMA
Momentum RSI MACD Stochastic CCI ROC WilliamsR ADX MFI TRIX
AwesomeOscillator Aroon
Volatility BollingerBands ATR Keltner Donchian PSAR
Volume OBV VWAP (cumulative + rolling)
cargo clippy --workspace --all-targets -D warnings is clean. License: Apache-2.0.