Compare commits

...

2 Commits

Author SHA1 Message Date
kingchenc ff268500ef release: bump 0.9.4 -> 0.9.5 (#329)
Maintenance release. The library API and every indicator are unchanged from
`0.9.4`; the only change that ships to users is the R package's build script.

### What's in 0.9.5
- **R package: retry the C ABI download** (`bindings/r/configure[.win]`). A freshly
  cut release can briefly 404 while assets propagate; the download is now retried
  with a ~2 min backoff instead of failing with `cannot open URL … 404`. Landed in
  #328; ships to r-universe / source installs with this release.
- The rest of #328 — CI/release-pipeline hardening (R/NuGet dependency caching,
  job timeouts 20→30 / release 45, network-install retries, wasm-publish cache) —
  is infrastructure and does not affect the published artifacts, but makes this
  release's own pipeline more robust.

Pure version-string bump on top — `bump_version.py` touched 19 files (Cargo +
Lock, pyproject, node package.json/locks + 6 platform stubs, pom + csproj +
DESCRIPTION, SECURITY, CHANGELOG `[0.9.5]` + compare URLs). `cargo fmt` clean.

Tag/publish waits for explicit GO (irreversible publish to crates.io / PyPI /
npm / NuGet / Maven / Go / r-universe).
2026-06-17 23:55:18 +02:00
kingchenc 929fc17127 ci: harden cache, timeouts and retries across CI and release (#328)
Hardens both workflows after the R-on-ubuntu job repeatedly hit the 20-minute
job cap and was cancelled (no R-package cache + no retry + a slow source build).
Each item below maps to the requested checklist.

### CI (`ci.yml`)
- **Timeouts 20 → 30 min** on every job (backstop only; real jobs finish well under).
- **R dependencies cached**: replace the manual `install.packages(testthat/knitr)`
  with `r-lib/actions/setup-r-dependencies` — restores a cached R library and pulls
  **RSPM binaries** instead of compiling from source (the slow/flaky path that blew
  the cap). This is the actual root-cause fix.
- **NuGet cache** for the C# job (`~/.nuget/packages`, keyed on the project files).
- **Retry** the network installs that had none — `npm ci`, `dotnet test`,
  `mvn install` — via `nick-fields/retry` (2–3 attempts, backoff). On top of the
  existing env-level retries (`CARGO_NET_RETRY`, `npm_config_fetch_retries`,
  `PIP_RETRIES`) and the setup-* CDN-flake retries.
- **Go stays `cache: false`** on purpose: the module has no `go.sum` / external
  deps, so there is nothing to cache (enabling it would only warn).

### Release (`release.yml`)
- **Per-job timeouts** added (there were none — only GitHub's 6h default): **45 min**,
  higher than CI's 30 because the wheel/build jobs compile from source incl.
  **vendored OpenSSL** and must not be killed mid-build.
- **wasm-publish** gets a `Swatinem/rust-cache` like the other Rust-build jobs.
- **Retry** the no-retry network installs (`npm ci` ×2, `dotnet pack`). The actual
  publish/deploy steps are left alone — they are already idempotent
  (skip-existing / skip-duplicate), so re-running the job is the safe recovery.

### R binding download (`bindings/r/configure[.win]`)
- A freshly cut release can 404 for 1–2 min while assets propagate, which broke
  the C ABI download (`cannot open URL … 404`). Add a `wickra_download` retry
  helper (6 × 20s ≈ 2 min backoff) for both the release-asset and wasm-source
  downloads. Note: the CI R job builds the C ABI **locally** (`WICKRA_*_DIR`), so
  it never downloads — this fix covers the real-world r-universe / end-user build.

This PR's own CI exercises the CI changes (the reworked R job, caches, retries,
timeouts) before merge; the release-only changes are validated on the next tag.
2026-06-17 23:42:06 +02:00
23 changed files with 237 additions and 102 deletions
+69 -24
View File
@@ -34,7 +34,7 @@ jobs:
rust:
name: Rust ${{ matrix.os }}
runs-on: ${{ matrix.os }}
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
strategy:
fail-fast: false
matrix:
@@ -105,7 +105,7 @@ jobs:
examples-smoke:
name: Examples (syntax smoke)
runs-on: ubuntu-latest
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
@@ -195,7 +195,7 @@ jobs:
clippy-bindings:
name: Clippy bindings
runs-on: ubuntu-latest
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
@@ -279,7 +279,7 @@ jobs:
msrv:
name: ${{ matrix.name }}
runs-on: ubuntu-latest
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
strategy:
fail-fast: false
matrix:
@@ -328,7 +328,7 @@ jobs:
coverage:
name: Coverage
runs-on: ubuntu-latest
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
@@ -370,7 +370,7 @@ jobs:
supply-chain:
name: Supply-chain (cargo-deny)
runs-on: ubuntu-latest
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
@@ -389,7 +389,7 @@ jobs:
fuzz-smoke:
name: Fuzz (smoke)
runs-on: ubuntu-latest
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
@@ -443,7 +443,7 @@ jobs:
python:
name: Python ${{ matrix.python-version }} on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
strategy:
fail-fast: false
matrix:
@@ -525,7 +525,7 @@ jobs:
wasm:
name: WASM build
runs-on: ubuntu-latest
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
@@ -575,7 +575,7 @@ jobs:
node:
name: Node ${{ matrix.node-version }} on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
strategy:
fail-fast: false
matrix:
@@ -622,9 +622,17 @@ jobs:
cache: npm
cache-dependency-path: bindings/node/package-lock.json
# npm's own fetch-retry (npm_config_fetch_retries) rides out per-request
# blips; wrap the whole `npm ci` once more so a longer registry hiccup
# retries the install instead of failing the job.
- name: Install Node dependencies
working-directory: bindings/node
run: npm ci
uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0
with:
timeout_minutes: 10
max_attempts: 3
retry_wait_seconds: 20
command: cd bindings/node && npm ci
shell: bash
- name: Build native module
working-directory: bindings/node
@@ -649,7 +657,7 @@ jobs:
c-abi:
name: C ABI on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
strategy:
fail-fast: false
matrix:
@@ -705,7 +713,7 @@ jobs:
csharp:
name: C# on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
strategy:
fail-fast: false
matrix:
@@ -723,6 +731,19 @@ jobs:
continue-on-error: true # cache is an optimisation; never block on a stuck/slow restore
timeout-minutes: 6
# Cache the restored NuGet packages so dotnet test/build resolve from the
# local store instead of hitting nuget.org every run. No packages.lock.json
# exists, so key on the project files; never block the job on a slow restore.
- name: Cache NuGet packages
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
continue-on-error: true
timeout-minutes: 6
with:
path: ~/.nuget/packages
key: ${{ runner.os }}-nuget-${{ hashFiles('**/*.csproj') }}
restore-keys: |
${{ runner.os }}-nuget-
# The binding links against the C ABI hub at runtime; build it first so the
# DllImportResolver finds target/release/wickra.{dll,so,dylib}. .NET 8 SDK is
# preinstalled on the GitHub runners, so no setup-dotnet step is needed.
@@ -732,8 +753,17 @@ jobs:
- name: .NET info
run: dotnet --info
# dotnet test restores from nuget.org first; retry so a transient restore
# blip retries instead of failing the job (the cached packages above make
# the retry cheap).
- name: Test the C# binding
run: dotnet test bindings/csharp/Wickra.Tests/Wickra.Tests.csproj -c Release
uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0
with:
timeout_minutes: 15
max_attempts: 2
retry_wait_seconds: 20
command: dotnet test bindings/csharp/Wickra.Tests/Wickra.Tests.csproj -c Release
shell: bash
- name: Build the C# examples
shell: bash
@@ -756,7 +786,7 @@ jobs:
go:
name: Go on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
strategy:
fail-fast: false
matrix:
@@ -879,7 +909,7 @@ jobs:
r:
name: R on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
strategy:
fail-fast: false
matrix:
@@ -912,10 +942,17 @@ jobs:
r-version: "release"
use-public-rspm: true
# Use the repos configured by setup-r (use-public-rspm) so Linux installs
# binary packages — building testthat's deps from source is slow and flaky.
- name: Install test dependency
run: Rscript -e 'install.packages("testthat")'
# Install the R dependencies via setup-r-dependencies: it restores a cached
# package library (actions/cache) and pulls RSPM *binaries* instead of
# compiling testthat / knitr and their deps from source — the slow, flaky
# path that previously blew past the job timeout on the ubuntu runner.
- name: Install R dependencies (cached binaries)
uses: r-lib/actions/setup-r-dependencies@a51a8012b0aab7c32ef9d19bf54da93f3254335e # v2
with:
working-directory: bindings/r
extra-packages: |
any::testthat
any::knitr
- name: Install and test the R binding
shell: bash
@@ -938,8 +975,8 @@ jobs:
# CRAN (with pandoc); this job only INSTALLs, so execute the vignette's R
# chunks here (knit, no pandoc needed) to catch a broken example before it
# reaches the published build.
# knitr is installed by the cached setup-r-dependencies step above.
run: |
Rscript -e 'install.packages("knitr", repos = Sys.getenv("RSPM", unset = "https://cloud.r-project.org"))'
Rscript -e 'knitr::knit("bindings/r/vignettes/getting-started.Rmd", output = tempfile(fileext = ".md"), quiet = TRUE); cat("vignette code OK\n")'
- name: Run the offline R examples
@@ -961,7 +998,7 @@ jobs:
java:
name: Java on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
timeout-minutes: 20 # backstop: cap a wedged job instead of GitHub's 6h default (slowest real job ~5 min)
timeout-minutes: 30 # backstop: cap a wedged job instead of GitHub's 6h default (headroom for slow registry/package installs)
strategy:
fail-fast: false
matrix:
@@ -1016,8 +1053,16 @@ jobs:
# `install` runs the archetype test suite (the real FFI boundary check) and
# installs the binding to the local repo so the examples can resolve it.
# Maven resolves plugins/deps from the network on a cache miss; retry so a
# transient Central blip retries instead of failing the job.
- name: Test and install the Java binding
run: mvn -B -f bindings/java install
uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0
with:
timeout_minutes: 20
max_attempts: 2
retry_wait_seconds: 20
command: mvn -B -f bindings/java install
shell: bash
- name: Build the Java examples
run: mvn -B -f examples/java compile
+43 -8
View File
@@ -36,6 +36,7 @@ jobs:
# --------------------------------------------------------------------------
cargo-publish:
name: Publish to crates.io
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
runs-on: ubuntu-latest
# The publish jobs run with long-lived registry tokens. Binding them to a
# protected GitHub environment lets the org require a reviewer to approve
@@ -139,6 +140,7 @@ jobs:
# --------------------------------------------------------------------------
python-wheels:
name: Build wheels (${{ matrix.target }}/${{ matrix.manylinux }} on ${{ matrix.os }})
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
strategy:
fail-fast: false
matrix:
@@ -209,6 +211,7 @@ jobs:
python-sdist:
name: Build Python sdist
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
@@ -228,6 +231,7 @@ jobs:
python-publish:
name: Publish to PyPI
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
needs: [python-wheels, python-sdist]
runs-on: ubuntu-latest
environment: release
@@ -251,6 +255,7 @@ jobs:
# --------------------------------------------------------------------------
node-build:
name: Node build (${{ matrix.target }})
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
strategy:
fail-fast: false
matrix:
@@ -296,8 +301,13 @@ jobs:
timeout-minutes: 6
- name: Install Node deps
working-directory: bindings/node
run: npm ci
uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0
with:
timeout_minutes: 10
max_attempts: 3
retry_wait_seconds: 20
command: cd bindings/node && npm ci
shell: bash
- name: Build native module
working-directory: bindings/node
@@ -312,6 +322,7 @@ jobs:
node-publish:
name: Publish to npm
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
needs: node-build
runs-on: ubuntu-latest
environment: release
@@ -351,8 +362,13 @@ jobs:
registry-url: "https://registry.npmjs.org"
- name: Install Node deps
working-directory: bindings/node
run: npm ci
uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0
with:
timeout_minutes: 10
max_attempts: 3
retry_wait_seconds: 20
command: cd bindings/node && npm ci
shell: bash
- name: Download all platform binaries
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
@@ -484,6 +500,7 @@ jobs:
# which requires the `id-token: write` permission set at the job level.
wasm-publish:
name: Publish wickra-wasm to npm
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
runs-on: ubuntu-latest
environment: release
# `id-token: write` lets npm publish embed a Sigstore provenance
@@ -523,6 +540,10 @@ jobs:
with:
targets: wasm32-unknown-unknown
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
continue-on-error: true # cache is an optimisation; never block on a stuck/slow restore
timeout-minutes: 6
- name: Install wasm-pack (latest, via prebuilt binary)
# See the matching note in ci.yml: jetli's default installs an old
# 0.10.x wasm-pack whose build subcommand rejects --features.
@@ -590,6 +611,7 @@ jobs:
# --------------------------------------------------------------------------
c-abi-build:
name: C ABI library (${{ matrix.target }})
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
strategy:
fail-fast: false
matrix:
@@ -645,6 +667,7 @@ jobs:
# workflow release.yml) exchanges the GitHub OIDC token for a short-lived key.
csharp-publish:
name: Publish to NuGet
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
needs: c-abi-build
runs-on: ubuntu-latest
environment: release
@@ -689,11 +712,18 @@ jobs:
echo "staged ${RID[$target]}:"; ls -l "$dest"
done
# dotnet pack restores from nuget.org first; retry so a transient restore
# blip retries instead of failing the release.
- name: Pack
shell: bash
run: |
version="${GITHUB_REF_NAME#v}"
dotnet pack bindings/csharp/Wickra/Wickra.csproj -c Release -p:Version="$version" -o nupkg
uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0
with:
timeout_minutes: 15
max_attempts: 2
retry_wait_seconds: 20
shell: bash
command: |
version="${GITHUB_REF_NAME#v}"
dotnet pack bindings/csharp/Wickra/Wickra.csproj -c Release -p:Version="$version" -o nupkg
# Exchange the GitHub OIDC token for a short-lived (~1h) NuGet API key.
# 'user' is the nuget.org profile name (the package owner), not an email.
@@ -728,6 +758,7 @@ jobs:
# match the release tag (kept in sync by the version-bump checklist).
java-publish:
name: Publish to Maven Central
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
needs: c-abi-build
runs-on: ubuntu-latest
environment: release
@@ -799,6 +830,7 @@ jobs:
# derived artifact, so its bot commit is intentionally unsigned.
go-mirror:
name: Mirror the Go module to wickra-go
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
needs: c-abi-build
runs-on: ubuntu-latest
steps:
@@ -882,6 +914,7 @@ jobs:
github-release:
name: Attach assets to the draft GitHub Release
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
needs: [cargo-publish, python-publish, node-publish, wasm-publish, c-abi-build]
runs-on: ubuntu-latest
permissions:
@@ -1007,6 +1040,7 @@ jobs:
# --------------------------------------------------------------------------
attestations:
name: Attest build provenance
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
needs: [cargo-publish, python-wheels, python-sdist, github-release]
runs-on: ubuntu-latest
# Signed SLSA build-provenance attestations for the published crates and
@@ -1090,6 +1124,7 @@ jobs:
# --------------------------------------------------------------------------
publish-release:
name: Publish the GitHub Release
timeout-minutes: 45 # backstop only: release build/publish jobs compile from source (vendored OpenSSL) and must not be killed mid-build; far above the ~10 min real runtime
needs: [github-release, attestations]
if: always() && needs.github-release.result == 'success'
runs-on: ubuntu-latest
+19 -1
View File
@@ -7,6 +7,23 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
## [Unreleased]
## [0.9.5] - 2026-06-17
Maintenance release. The library API and every indicator are unchanged from
`0.9.4`; the only change that ships to users is to the R package's build script.
The rest of the release is CI / release-pipeline hardening (dependency caching,
job timeouts, and network-install retries) that does not affect the artifacts.
### Fixed
- **R package: retry the C ABI download.** `configure` / `configure.win` fetch the
prebuilt `wickra-c-<triple>.tar.gz` from the matching GitHub release. A freshly
cut release can briefly return 404 while its assets propagate across the CDN
(and a transient network blip would also fail it), so the single-shot download
is now retried with a backoff (~2 min) before giving up. Fixes
`cannot open URL … 404 Not Found` on r-universe / source installs taken right
after a release.
## [0.9.4] - 2026-06-17
Packaging fix for the `0.9.3` data layer. The library is identical to `0.9.3` on
@@ -1836,7 +1853,8 @@ public API changes.
optional Binance live feed.
- Bindings for Python, Node.js, and WebAssembly.
[Unreleased]: https://github.com/wickra-lib/wickra/compare/v0.9.4...HEAD
[Unreleased]: https://github.com/wickra-lib/wickra/compare/v0.9.5...HEAD
[0.9.5]: https://github.com/wickra-lib/wickra/compare/v0.9.4...v0.9.5
[0.9.4]: https://github.com/wickra-lib/wickra/compare/v0.9.3...v0.9.4
[0.9.3]: https://github.com/wickra-lib/wickra/compare/v0.9.2...v0.9.3
[0.9.2]: https://github.com/wickra-lib/wickra/compare/v0.9.1...v0.9.2
Generated
+9 -9
View File
@@ -1785,7 +1785,7 @@ dependencies = [
[[package]]
name = "wickra"
version = "0.9.4"
version = "0.9.5"
dependencies = [
"approx",
"criterion",
@@ -1796,7 +1796,7 @@ dependencies = [
[[package]]
name = "wickra-bench"
version = "0.9.4"
version = "0.9.5"
dependencies = [
"criterion",
"kand",
@@ -1808,7 +1808,7 @@ dependencies = [
[[package]]
name = "wickra-c"
version = "0.9.4"
version = "0.9.5"
dependencies = [
"tokio",
"wickra-core",
@@ -1817,7 +1817,7 @@ dependencies = [
[[package]]
name = "wickra-core"
version = "0.9.4"
version = "0.9.5"
dependencies = [
"approx",
"proptest",
@@ -1827,7 +1827,7 @@ dependencies = [
[[package]]
name = "wickra-data"
version = "0.9.4"
version = "0.9.5"
dependencies = [
"approx",
"csv",
@@ -1846,7 +1846,7 @@ dependencies = [
[[package]]
name = "wickra-examples"
version = "0.9.4"
version = "0.9.5"
dependencies = [
"serde_json",
"tokio",
@@ -1856,7 +1856,7 @@ dependencies = [
[[package]]
name = "wickra-node"
version = "0.9.4"
version = "0.9.5"
dependencies = [
"napi",
"napi-build",
@@ -1868,7 +1868,7 @@ dependencies = [
[[package]]
name = "wickra-python"
version = "0.9.4"
version = "0.9.5"
dependencies = [
"bytemuck",
"pyo3",
@@ -1879,7 +1879,7 @@ dependencies = [
[[package]]
name = "wickra-wasm"
version = "0.9.4"
version = "0.9.5"
dependencies = [
"console_error_panic_hook",
"js-sys",
+3 -3
View File
@@ -14,7 +14,7 @@ members = [
exclude = ["fuzz"]
[workspace.package]
version = "0.9.4"
version = "0.9.5"
authors = ["kingchenc <support@wickra.org>"]
edition = "2021"
rust-version = "1.86"
@@ -26,8 +26,8 @@ keywords = ["finance", "trading", "indicators", "technical-analysis", "ta"]
categories = ["finance", "mathematics", "science"]
[workspace.dependencies]
wickra-core = { path = "crates/wickra-core", version = "0.9.4" }
wickra-data = { path = "crates/wickra-data", version = "0.9.4" }
wickra-core = { path = "crates/wickra-core", version = "0.9.5" }
wickra-data = { path = "crates/wickra-data", version = "0.9.5" }
thiserror = "2"
rayon = "1.10"
+3 -3
View File
@@ -2,13 +2,13 @@
## Supported versions
Wickra is pre-1.0. Security fixes are applied to the latest released `0.9.4`
Wickra is pre-1.0. Security fixes are applied to the latest released `0.9.5`
version only; please upgrade to the newest release before reporting an issue.
| Version | Supported |
| --- | --- |
| 0.9.4 (latest) | :white_check_mark: |
| < 0.9.4 | :x: |
| 0.9.5 (latest) | :white_check_mark: |
| < 0.9.5 | :x: |
## Reporting a vulnerability
+1 -1
View File
@@ -11,7 +11,7 @@
<!-- NuGet package metadata -->
<PackageId>Wickra</PackageId>
<Version>0.9.4</Version>
<Version>0.9.5</Version>
<Authors>kingchenc</Authors>
<Description>High-performance streaming technical-analysis indicators (514 indicators) for .NET, backed by the native Rust core via the Wickra C ABI.</Description>
<PackageLicenseExpression>MIT OR Apache-2.0</PackageLicenseExpression>
+2 -2
View File
@@ -30,14 +30,14 @@ Maven:
<dependency>
<groupId>org.wickra</groupId>
<artifactId>wickra</artifactId>
<version>0.9.4</version>
<version>0.9.5</version>
</dependency>
```
Gradle:
```kotlin
implementation("org.wickra:wickra:0.9.4")
implementation("org.wickra:wickra:0.9.5")
```
The native library ships prebuilt per platform (Linux, macOS, Windows — x64 and
+1 -1
View File
@@ -6,7 +6,7 @@
<groupId>org.wickra</groupId>
<artifactId>wickra</artifactId>
<version>0.9.4</version>
<version>0.9.5</version>
<packaging>jar</packaging>
<name>Wickra</name>
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "wickra-darwin-arm64",
"version": "0.9.4",
"version": "0.9.5",
"description": "Native binding for wickra (macOS Apple Silicon). Installed automatically as an optional dependency of wickra on matching platforms.",
"main": "wickra.darwin-arm64.node",
"files": [
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "wickra-darwin-x64",
"version": "0.9.4",
"version": "0.9.5",
"description": "Native binding for wickra (macOS Intel). Installed automatically as an optional dependency of wickra on matching platforms.",
"main": "wickra.darwin-x64.node",
"files": [
@@ -1,6 +1,6 @@
{
"name": "wickra-linux-arm64-gnu",
"version": "0.9.4",
"version": "0.9.5",
"description": "Native binding for wickra (linux arm64 GNU). Installed automatically as an optional dependency of wickra on matching platforms.",
"main": "wickra.linux-arm64-gnu.node",
"files": [
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "wickra-linux-x64-gnu",
"version": "0.9.4",
"version": "0.9.5",
"description": "Native binding for wickra (linux x64 GNU). Installed automatically as an optional dependency of wickra on matching platforms.",
"main": "wickra.linux-x64-gnu.node",
"files": [
@@ -1,6 +1,6 @@
{
"name": "wickra-win32-arm64-msvc",
"version": "0.9.4",
"version": "0.9.5",
"description": "Native binding for wickra (Windows arm64 MSVC). Installed automatically as an optional dependency of wickra on matching platforms.",
"main": "wickra.win32-arm64-msvc.node",
"files": [
@@ -1,6 +1,6 @@
{
"name": "wickra-win32-x64-msvc",
"version": "0.9.4",
"version": "0.9.5",
"description": "Native binding for wickra (Windows x64 MSVC). Installed automatically as an optional dependency of wickra on matching platforms.",
"main": "wickra.win32-x64-msvc.node",
"files": [
+20 -20
View File
@@ -1,12 +1,12 @@
{
"name": "wickra",
"version": "0.9.4",
"version": "0.9.5",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "wickra",
"version": "0.9.4",
"version": "0.9.5",
"license": "MIT OR Apache-2.0",
"devDependencies": {
"@napi-rs/cli": "^2.18.0"
@@ -15,12 +15,12 @@
"node": ">= 20"
},
"optionalDependencies": {
"wickra-darwin-arm64": "0.9.4",
"wickra-darwin-x64": "0.9.4",
"wickra-linux-arm64-gnu": "0.9.4",
"wickra-linux-x64-gnu": "0.9.4",
"wickra-win32-arm64-msvc": "0.9.4",
"wickra-win32-x64-msvc": "0.9.4"
"wickra-darwin-arm64": "0.9.5",
"wickra-darwin-x64": "0.9.5",
"wickra-linux-arm64-gnu": "0.9.5",
"wickra-linux-x64-gnu": "0.9.5",
"wickra-win32-arm64-msvc": "0.9.5",
"wickra-win32-x64-msvc": "0.9.5"
}
},
"node_modules/@napi-rs/cli": {
@@ -41,8 +41,8 @@
}
},
"node_modules/wickra-darwin-arm64": {
"version": "0.9.4",
"resolved": "https://registry.npmjs.org/wickra-darwin-arm64/-/wickra-darwin-arm64-0.9.4.tgz",
"version": "0.9.5",
"resolved": "https://registry.npmjs.org/wickra-darwin-arm64/-/wickra-darwin-arm64-0.9.5.tgz",
"integrity": "sha512-4eZiBR/yGUdr4nzhEUFy2i69XgNx64iI2ax/LPamsThgylC0KpHOZKK19QzJ2d9KbK4C8nMjME5FLuR+4GNEwQ==",
"cpu": [
"arm64"
@@ -57,8 +57,8 @@
}
},
"node_modules/wickra-darwin-x64": {
"version": "0.9.4",
"resolved": "https://registry.npmjs.org/wickra-darwin-x64/-/wickra-darwin-x64-0.9.4.tgz",
"version": "0.9.5",
"resolved": "https://registry.npmjs.org/wickra-darwin-x64/-/wickra-darwin-x64-0.9.5.tgz",
"integrity": "sha512-6hf8zI3QPjTFp4zCpmgUwDvNtu6jHqNUHKD5e55POo0CgA52HkpyxSPtVm8TGTIZDI7kPjlbOdBM8CJ76mmXwA==",
"cpu": [
"x64"
@@ -73,8 +73,8 @@
}
},
"node_modules/wickra-linux-arm64-gnu": {
"version": "0.9.4",
"resolved": "https://registry.npmjs.org/wickra-linux-arm64-gnu/-/wickra-linux-arm64-gnu-0.9.4.tgz",
"version": "0.9.5",
"resolved": "https://registry.npmjs.org/wickra-linux-arm64-gnu/-/wickra-linux-arm64-gnu-0.9.5.tgz",
"integrity": "sha512-kSe6y0xBMSiqdPLXNjwop5WZdHtvdBNKSEBCwZ4hFq33p4apW25/wrlzv9/oDuyD4kuPabJEhCCnFOplh58CUg==",
"cpu": [
"arm64"
@@ -89,8 +89,8 @@
}
},
"node_modules/wickra-linux-x64-gnu": {
"version": "0.9.4",
"resolved": "https://registry.npmjs.org/wickra-linux-x64-gnu/-/wickra-linux-x64-gnu-0.9.4.tgz",
"version": "0.9.5",
"resolved": "https://registry.npmjs.org/wickra-linux-x64-gnu/-/wickra-linux-x64-gnu-0.9.5.tgz",
"integrity": "sha512-tWBWS4qz7hxM4xnpFb59bhf6TaLwXq0Z3jEa/2l7r8PiHA94g8r8S53NRMiT+4yiL5hSWe/nUiC/YXdRrhEZ4g==",
"cpu": [
"x64"
@@ -105,8 +105,8 @@
}
},
"node_modules/wickra-win32-arm64-msvc": {
"version": "0.9.4",
"resolved": "https://registry.npmjs.org/wickra-win32-arm64-msvc/-/wickra-win32-arm64-msvc-0.9.4.tgz",
"version": "0.9.5",
"resolved": "https://registry.npmjs.org/wickra-win32-arm64-msvc/-/wickra-win32-arm64-msvc-0.9.5.tgz",
"integrity": "sha512-EXIckHxAtF75PUGDKRzXyqMe9ldP0JjSdu68WFN6iJfp+McYrGu6h40TEJlQ/oUEIoPqiZB/xhVyo/el5Lg7zw==",
"cpu": [
"arm64"
@@ -121,8 +121,8 @@
}
},
"node_modules/wickra-win32-x64-msvc": {
"version": "0.9.4",
"resolved": "https://registry.npmjs.org/wickra-win32-x64-msvc/-/wickra-win32-x64-msvc-0.9.4.tgz",
"version": "0.9.5",
"resolved": "https://registry.npmjs.org/wickra-win32-x64-msvc/-/wickra-win32-x64-msvc-0.9.5.tgz",
"integrity": "sha512-Yfsqq1Xwp6hdxMyLze411vNdo7BDwI6+lPSe7A9XdqyPecNDbtKwYLpsal2r8EHbNzqM+R8XnuRtUaEQS5VlUQ==",
"cpu": [
"x64"
+7 -7
View File
@@ -1,6 +1,6 @@
{
"name": "wickra",
"version": "0.9.4",
"version": "0.9.5",
"description": "Streaming-first technical indicators: incremental, fast, install-free. Node bindings powered by Rust.",
"author": "kingchenc <support@wickra.org>",
"main": "index.js",
@@ -47,12 +47,12 @@
"node": ">= 20"
},
"optionalDependencies": {
"wickra-linux-x64-gnu": "0.9.4",
"wickra-linux-arm64-gnu": "0.9.4",
"wickra-darwin-x64": "0.9.4",
"wickra-darwin-arm64": "0.9.4",
"wickra-win32-x64-msvc": "0.9.4",
"wickra-win32-arm64-msvc": "0.9.4"
"wickra-linux-x64-gnu": "0.9.5",
"wickra-linux-arm64-gnu": "0.9.5",
"wickra-darwin-x64": "0.9.5",
"wickra-darwin-arm64": "0.9.5",
"wickra-win32-x64-msvc": "0.9.5",
"wickra-win32-arm64-msvc": "0.9.5"
},
"scripts": {
"build": "napi build --platform --release",
+1 -1
View File
@@ -4,7 +4,7 @@ build-backend = "maturin"
[project]
name = "wickra"
version = "0.9.4"
version = "0.9.5"
description = "Streaming-first technical indicators: incremental, fast, install-free."
readme = "README.md"
license = "MIT OR Apache-2.0"
+1 -1
View File
@@ -1,7 +1,7 @@
Package: wickra
Type: Package
Title: Streaming-First Technical Indicators
Version: 0.9.4
Version: 0.9.5
Authors@R: person("Wickra contributors", role = c("aut", "cre"), email = "support@wickra.org")
Description: R bindings for the Wickra technical-analysis library over its C ABI
hub. Exposes 514 indicators, each an O(1) streaming state machine shared with
+22 -4
View File
@@ -14,6 +14,26 @@ set -e
inc=""
lib=""
# A freshly-cut GitHub release can briefly return 404 while its assets propagate
# across the CDN, and a transient network blip should not fail the build either.
# Retry base R's download.file with a backoff (~2 min total) instead of giving up
# on the first miss.
wickra_download() {
_url="$1"
_dest="$2"
_attempt=1
while [ "${_attempt}" -le 6 ]; do
if "${R_HOME}/bin/Rscript" -e "download.file('${_url}', '${_dest}', mode = 'wb', quiet = TRUE)"; then
return 0
fi
echo "wickra: download attempt ${_attempt}/6 failed (${_url}); the release asset may still be propagating — retrying in 20s..."
sleep 20
_attempt=$((_attempt + 1))
done
echo "wickra: failed to download ${_url} after 6 attempts"
return 1
}
# WebAssembly (r-universe / webR): there is no prebuilt wasm C ABI to download,
# but the build image ships cargo (/usr/local/cargo/bin) and emscripten
# (EMSDK on PATH), so build the C ABI staticlib from source for
@@ -26,8 +46,7 @@ if [ "$(uname -s)" = "Emscripten" ]; then
echo "wickra: building C ABI from source for wasm32-unknown-emscripten (v${version})"
build=$(mktemp -d)
url="https://github.com/wickra-lib/wickra/archive/refs/tags/v${version}.tar.gz"
"${R_HOME}/bin/Rscript" -e "download.file('${url}', '${build}/src.tar.gz', mode = 'wb', quiet = TRUE)" \
|| { echo "wickra: failed to download source ${url}"; exit 1; }
wickra_download "${url}" "${build}/src.tar.gz" || exit 1
"${R_HOME}/bin/Rscript" -e "untar('${build}/src.tar.gz', exdir = '${build}')"
root="${build}/wickra-${version}"
rustup target add wasm32-unknown-emscripten 2>/dev/null || true
@@ -73,8 +92,7 @@ else
esac
url="https://github.com/wickra-lib/wickra/releases/download/v${version}/wickra-c-${triple}.tar.gz"
echo "wickra: downloading C ABI ${triple} for v${version}"
"${R_HOME}/bin/Rscript" -e "download.file('${url}', 'src/wickra-c.tar.gz', mode = 'wb', quiet = TRUE)" \
|| { echo "wickra: failed to download ${url}"; exit 1; }
wickra_download "${url}" "src/wickra-c.tar.gz" || exit 1
"${R_HOME}/bin/Rscript" -e "untar('src/wickra-c.tar.gz', exdir = 'src/wickra-c')"
inc="src/wickra-c/wickra-c-${triple}/include"
lib="src/wickra-c/wickra-c-${triple}/lib"
+21 -2
View File
@@ -10,6 +10,26 @@
# WICKRA_LIB_DIR to build against a locally built C ABI instead (dev override).
set -e
# A freshly-cut GitHub release can briefly return 404 while its assets propagate
# across the CDN, and a transient network blip should not fail the build either.
# Retry base R's download.file with a backoff (~2 min total) instead of giving up
# on the first miss.
wickra_download() {
_url="$1"
_dest="$2"
_attempt=1
while [ "${_attempt}" -le 6 ]; do
if "${R_HOME}/bin/Rscript" -e "download.file('${_url}', '${_dest}', mode = 'wb', quiet = TRUE)"; then
return 0
fi
echo "wickra: download attempt ${_attempt}/6 failed (${_url}); the release asset may still be propagating — retrying in 20s..."
sleep 20
_attempt=$((_attempt + 1))
done
echo "wickra: failed to download ${_url} after 6 attempts"
return 1
}
if [ -n "${WICKRA_INCLUDE_DIR}" ] && [ -n "${WICKRA_LIB_DIR}" ]; then
echo "wickra: using C ABI from WICKRA_INCLUDE_DIR / WICKRA_LIB_DIR (dev override)"
inc="${WICKRA_INCLUDE_DIR}"
@@ -24,8 +44,7 @@ else
esac
url="https://github.com/wickra-lib/wickra/releases/download/v${version}/wickra-c-${triple}.tar.gz"
echo "wickra: downloading C ABI ${triple} for v${version}"
"${R_HOME}/bin/Rscript" -e "download.file('${url}', 'src/wickra-c.tar.gz', mode = 'wb', quiet = TRUE)" \
|| { echo "wickra: failed to download ${url}"; exit 1; }
wickra_download "${url}" "src/wickra-c.tar.gz" || exit 1
"${R_HOME}/bin/Rscript" -e "untar('src/wickra-c.tar.gz', exdir = 'src/wickra-c')"
inc="src/wickra-c/wickra-c-${triple}/include"
lib="src/wickra-c/wickra-c-${triple}/lib"
+2 -2
View File
@@ -6,7 +6,7 @@
<groupId>org.wickra.examples</groupId>
<artifactId>wickra-examples</artifactId>
<version>0.9.4</version>
<version>0.9.5</version>
<packaging>jar</packaging>
<name>Wickra Java examples</name>
@@ -21,7 +21,7 @@
<dependency>
<groupId>org.wickra</groupId>
<artifactId>wickra</artifactId>
<version>0.9.4</version>
<version>0.9.5</version>
</dependency>
</dependencies>
+7 -7
View File
@@ -14,7 +14,7 @@
},
"../../bindings/node": {
"name": "wickra",
"version": "0.9.4",
"version": "0.9.5",
"license": "MIT OR Apache-2.0",
"devDependencies": {
"@napi-rs/cli": "^2.18.0"
@@ -23,12 +23,12 @@
"node": ">= 20"
},
"optionalDependencies": {
"wickra-darwin-arm64": "0.9.4",
"wickra-darwin-x64": "0.9.4",
"wickra-linux-arm64-gnu": "0.9.4",
"wickra-linux-x64-gnu": "0.9.4",
"wickra-win32-arm64-msvc": "0.9.4",
"wickra-win32-x64-msvc": "0.9.4"
"wickra-darwin-arm64": "0.9.5",
"wickra-darwin-x64": "0.9.5",
"wickra-linux-arm64-gnu": "0.9.5",
"wickra-linux-x64-gnu": "0.9.5",
"wickra-win32-arm64-msvc": "0.9.5",
"wickra-win32-x64-msvc": "0.9.5"
}
},
"node_modules/wickra": {