8aa74cb638
The 0.2.0 release left wickra@npm stuck at 0.1.4 and never created a GitHub Release entry because the brand-new `wickra-win32-arm64-msvc` sub-package name was caught by npm's spam-detection filter on its first publish attempt (same situation that affected `wickra-win32-x64-msvc` through 0.1.4 until npm Support unblocked it). A support ticket is open; until it is resolved, ship 0.2.1 for the five platforms whose sub-packages are already on npm and re-add Windows ARM64 in a follow-up release. Changes for this cycle: - bindings/node/package.json: remove "wickra-win32-arm64-msvc" from optionalDependencies and "aarch64-pc-windows-msvc" from napi.triples.additional. - bindings/node/npm/win32-arm64-msvc/: removed (will be restored fresh once the npm name is unblocked). - .github/workflows/release.yml: comment out the aarch64-pc-windows-msvc entry of the node-build matrix with a TODO/restore note. - Bump every workspace and binding version to 0.2.1 (Cargo.toml, pyproject.toml, bindings/node/package.json, five npm/<target> templates, the wiki version table). Cargo.lock regenerated. - CHANGELOG: new [0.2.1] block consolidating every fix that has landed on main since 0.2.0 (HV epsilon, examples CI step, fuzz cargo-fuzz install, MSRV 1.85 -> 1.86 / 1.77 -> 1.88, criterion 0.5 -> 0.8, tokio-tungstenite 0.24 -> 0.29, tick_aggregator gap-fill cap, every GitHub Action SHA-pin bump). Compare-link added. The arm64 loader branch in bindings/node/index.js is left untouched: a Windows ARM64 user installing 0.2.1 will get the standard `Cannot find module 'wickra-win32-arm64-msvc'` error from the loader, which is accurate. PyPI's win-arm64 wheel is unaffected. Verified locally: cargo fmt/clippy/test --workspace --all-features -> 630 passed / 0 failed cargo build -p wickra-examples --bins -> clean cargo build -p wickra-node -> clean
19 KiB
19 KiB
Changelog
All notable changes to Wickra are documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
Unreleased
0.2.1 - 2026-05-23
Changed
- MSRV bumped. Workspace minimum supported Rust version is now 1.86
(was 1.75) and the Node binding (
wickra-node) is now 1.88 (was 1.77). The bumps are driven by transitive-dependency floors that were lifted in recent updates:criterion 0.8.2(the bench dev-dep) requires Rust 1.86, andnapi-build >= 2.3.2requires Rust 1.88. Pinning those deps to the older versions would have frozen us out of future security fixes from those upstreams, so lifting the MSRV is the cleaner path for a young 0.x library. Downstream consumers on older Rust toolchains can stay on Wickra 0.2.0. - Bumped the bench dev-dep
criterionfrom 0.5 to 0.8 and migratedbindings/wickra/benches/indicators.rsfrom the deprecatedcriterion::black_boxre-export to the stablestd::hint::black_box. - Bumped
tokio-tungstenitefrom 0.24 to 0.29.WebSocketConfigbecame#[non_exhaustive]upstream, so the struct-literal construction incrates/wickra-data/src/live/binance.rsis rewritten to the builder-styleWebSocketConfig::default().max_message_size(..).max_frame_size(..). Same caps, same semantics, same default carry-over. - Bumped every committed CI/release GitHub Action to its latest pinned
SHA:
actions/checkout4 → 6,actions/setup-node4 → 6,actions/setup-python5 → 6,actions/upload-artifact4 → 7,actions/download-artifact4 → 8,softprops/action-gh-release2 → 3,codecov/codecov-action5 → 6,taiki-e/install-actionpatch.
Fixed
tick_aggregatorgap-fill no longer allocates an unbounded number of placeholder candles. The newMAX_GAP_FILL_CANDLES = 1_000_000cap surfaces an adversarial timestamp jump (e.g. a clock-glitch tick years in the future) asError::Malformedinstead of an OOM panic. Found by the newtick_aggregatorfuzz target.HistoricalVolatility::geometric_series_yields_zeronow uses an1e-6tolerance instead of1e-9. The mathematical result on a perfectly geometric price series is exactly zero, but the underlying1.01_f64.powi(i)+ log-return + std-dev cascade accumulates platform-sensitive FP drift on the order of 1e-7 on x86_64 Linux and macOS. The widened tolerance stays four decimal places below any realistic annualised volatility value while absorbing the drift across every supported platform.- Replaced every
(high + low) / 2.0test-helper and three real call sites (Ohlcv::median_price,Donchian.middle,EaseOfMovement.mid,SuperTrend.hl2) withf64::midpoint(high, low). The change satisfies clippy 1.95's newmanual_midpointlint without affecting values (f64::midpointmatches the naive average to better than 1 ULP for the inputs used here). - Replaced
i.is_multiple_of(2)(unstable on Rust 1.85) withi % 2 == 0in the SMA / Bollinger long-stream-drift tests so the workspace MSRV job builds cleanly on Rust 1.86. - The
Compile examplesCI step now invokescargo build -p wickra-examples --binsinstead of the now-deletedcargo build -p wickra --example backtest/-p wickra-data --example live_binance(the Z5 reorganisation moved every runnable example into the dedicatedwickra-examplescrate, but the CI step had not been updated). - The
Fuzz (smoke)CI job installscargo-fuzzfrom a prebuilt binary viataiki-e/install-actioninstead ofcargo install cargo-fuzz. The source install resolved againstrustix 0.36.5, which uses internal#[rustc_*]attributes the current nightly compiler rejects. - The fuzz targets now build with an explicit
--target x86_64-unknown-linux-gnu; cargo-fuzz was defaulting tox86_64-unknown-linux-musl, which is not installed on the standard GitHub-hosted Ubuntu runner.
Removed
wickra-win32-arm64-msvcis temporarily omitted from this release. The npm spam-detection filter blocks the first publish of this brand-new package name (same situation that affectedwickra-win32-x64-msvcthrough 0.1.4 until npm Support unblocked it). A support ticket is open; once the new name is unblocked theaarch64-pc-windows-msvctriple will be restored inbindings/node/package.json(napi.triples.additional+optionalDependencies), in therelease.ymlnode-buildmatrix, and as a freshbindings/node/npm/win32-arm64-msvc/template. Until then,npm install wickra@0.2.1on Windows ARM64 will surface the loader's standardCannot find module 'wickra-win32-arm64-msvc'error; every other platform (Linux x64 / Linux ARM64 / macOS x64 / macOS ARM64 / Windows x64) ships normally. The PyPI wheel for Windows ARM64 is unaffected and still published.
0.2.0 - 2026-05-23
Fixed
HistoricalVolatility::updateno longer substitutes a0.0log-return on non-positive prices (audit finding R13). Negative or zero prices are semantically invalid for a log-return calculation; silently treating them as "no movement" underreported realised volatility. They are now skipped — the previous valid value is returned and the indicator's state (prev_price, window, sums) is left untouched — matching how every other indicator handles invalid inputs.Tick::newnow returns the newError::InvalidTickvariant for negative volume instead ofError::InvalidCandle(audit finding R14). A tick is not a candle, and downstream tick-stream pipelines should be able to match on a semantically-correct error. The Python binding'smap_errwas extended to forward the new variant as aValueError; the Node and WASM bindings format viaError::to_string()and pick the new variant up automatically.Psar::is_readynow matches the convention shared by every other indicator:is_ready() == trueiff a real value has been produced (audit finding R6). The previous implementation returnedself.initialised, which flipped totrueafter the seed candle even though the seed candle itself returnsNone. A streaming consumer that wroteif ind.is_ready() { use(ind.update(c)?) }would hit an unexpectedNoneon the first post-seed update. The fix introduces ahas_emittedgate set when the firstSomevalue is returned.Psar::resetnow restores the compute fields (prev_high,prev_low,sar,ep) tof64::NANsentinels instead of0.0(audit Opus-Bonus 1). The fields are gated byinitialisedtoday, so the0.0sentinel never leaked into output — but a future refactor that read them pre-init would have silently treated0.0as a real price. Adebug_assert!at the read site makes the invariant explicit.
Changed
SmaandBollingerBandsnow reseed their incrementalsum(andsum_sqfor Bollinger) from the live window every16 · periodfinite updates, capping floating-point drift on long-running streams (audit findings R7 and L2-Rust). Previously the incremental single-subtractsum -= oldcould accumulate catastrophic-cancellation error on streams with alternating large/small magnitudes; the misleadingsma.rscomment that claimed the drift was already bounded "by recomputing the sum after each pop" is replaced with an accurate description of the new reseed strategy. Amortised cost stays at O(1) (O(period)work amortised overO(period)updates), values are bit-identical on inputs that did not drift to begin with, and two newlong_stream_drift_stays_boundedtests stress the recompute by alternating1e9/1.0(SMA) and1e6/1.0(Bollinger) for several recompute cycles and verify the reported values track a fresh from-scratch computation over the live window.LinearRegression,LinRegSlopeandLinRegAngle(via composition overLinRegSlope) now run their rolling ordinary-least-squares fit incrementally in O(1) per update (audit finding R2). Previously every tick refit the line from scratch in O(period). The OLS denominators (ΣxandΣxx) depend only onperiod, so they were already precomputed; this release adds runningΣyandΣxyaccumulators and slides them in closed form via the identitynew_Σxy = old_Σxy − old_Σy + popped_y₀(thenΣxy += (n − 1) · new_valueandΣy += new_value). New per-bar equivalence tests compare the O(1) output against a fresh O(n) refit on noisy ramps, step functions, and constants — values agree to within 1e-9.- Fuzz suite expanded from 2 indicators to the full catalogue (audit finding
R9). The existing
indicator_updatetarget now exercises every scalar-input indicator (~33 classes including MACD and Bollinger Bands); a newindicator_update_candletarget exercises every candle-input indicator (~37 classes, including ATR, ADX, Stochastic, PSAR, Keltner, SuperTrend, ChandelierExit, AwesomeOscillator, OBV, MFI, VWAP, RollingVWAP, and the rest of the volume / volatility / trailing-stop / price-statistics families). Each iteration sweeps every indicator through both the streamingupdateloop and a fullbatchcall so any state-mutation bug surfaces on either path. CI gains afuzz-smokejob that runs each of the five targets for 30 s on every push and pull-request. UlcerIndex::updatenow tracks the trailing maximum with a monotonically- decreasing deque of(index, price)pairs instead of scanning the whole trailing window on every tick. The indicator now honours theIndicatortrait's O(1)-per-tick contract; values and warmup semantics are unchanged (verified by a new adversarial-input test that compares the deque output bar-by-bar against a naive O(n) trailing-max scan on strictly increasing, strictly decreasing, constant, and sawtooth inputs). The doc comment onwarmup_period()is also corrected: the two windows overlap by one bar, so the formula is2 * period - 1.
Added
RollingVWAPis now exposed in Python, Node and WASM under that name (previously the rolling-window VWAP existed only in the Rust core, even though the README's volume-family table already advertisedVWAP (cumulative + rolling)). All four bindings now ship the same cumulativeVWAPplus the finite-windowRollingVWAP(period). The wiki pageIndicator-Vwap.mdadds Python, Node and WASM examples and drops the "Rust-only" caveat.- WASM binding now exposes the streaming
update()method on every candle-input indicator:Adx,WilliamsR,Cci,Mfi,Psar,Keltner,Donchian,Vwap,AwesomeOscillator,Aroon,Stochastic, andObv. Multi-output indicators (Adx,Keltner,Donchian,Aroon,Stochastic) return a named JS object ({ plusDi, minusDi, adx },{ upper, middle, lower },{ up, down },{ k, d }) once warm, ornullduring warmup — matching the existingSuperTrendconvention. Each class also gainsreset(),isReady()andwarmupPeriod(), bringing the WASM surface to full parity with Python and Node so browser-side streaming code no longer has to replaybatch()on every tick.WasmKamagains the previously missingwarmupPeriod(). - New
wasm-bindgenintegration test exercisesupdate == batchplus the full lifecycle (reset/isReady/warmupPeriod) for all twelve newly wired classes against a deterministic 40-bar synthetic OHLCV stream.
Security
- Upgrade
pyo3(0.22 → 0.28) andnumpy(0.22 → 0.28) in the Python binding. Fixes RUSTSEC-2025-0020 — a buffer overflow inPyString::from_objectthat affected the published Python wheels. Thecargo-denyignore entry that previously suppressed the advisory has been removed;cargo deny checkis now clean without suppression. Migratedinto_pyarray_boundtointo_pyarray,downcast::<PyDict>tocast::<PyDict>, and opted every#[pyclass]out of the deprecated automaticFromPyObjectderive viaskip_from_py_object.
Added
- 46 new technical indicators, taking the library from 25 to 71 and
reorganising the catalogue into eight families, each with at least five
members. Every indicator is implemented once in the Rust core and wired
through the Python, Node and WASM bindings, with reference-value tests and a
dedicated wiki page:
- Moving Averages:
Smma,Trima,Zlema,T3,Vwma. - Momentum Oscillators:
Mom,Cmo,Tsi,Pmo,StochRsi,UltimateOscillator. - Trend & Directional:
AroonOscillator,Vortex,MassIndex,ChoppinessIndex,VerticalHorizontalFilter. - Price Oscillators:
Ppo,Dpo,Coppock,AcceleratorOscillator,BalanceOfPower. - Volatility & Bands:
Natr,StdDev,UlcerIndex,HistoricalVolatility,BollingerBandwidth,PercentB,TrueRange,ChaikinVolatility. - Trailing Stops:
SuperTrend,ChandelierExit,ChandeKrollStop,AtrTrailingStop. - Volume:
Adl,VolumePriceTrend,ChaikinMoneyFlow,ChaikinOscillator,ForceIndex,EaseOfMovement. - Price Statistics:
TypicalPrice,MedianPrice,WeightedClose,LinearRegression,LinRegSlope,ZScore,LinRegAngle.
- Moving Averages:
TickAggregator::with_gap_fill— opt-in mode that emits a flat placeholder candle for every empty bucket between two ticks, keeping the candle series evenly spaced for downstream indicators.- CSV reader: a leading UTF-8 byte-order mark is stripped, fields are trimmed, and the header is validated against the required OHLCV columns.
- CI: an
msrvjob that builds and tests the workspace on Rust 1.75 and the node binding on Rust 1.77. - Community health files:
CONTRIBUTING.md,SECURITY.md,CODE_OF_CONDUCT.md, issue / pull-request templates,CODEOWNERS, and a Dependabot configuration. - Seven example OHLCV datasets under
examples/data/, one per timeframe (1m / 5m / 15m / 1h / 12h / 1d / 1month), holding real BTCUSDT spot klines, alongside thefetch_btcusdtexample that regenerates them from the Binance REST API. Timeframe::minutes,Timeframe::hoursandTimeframe::daysconvenience constructors, each building on seconds with a checked-multiplication overflow guard.
Changed
- The indicator wiki is reorganised into eight family folders under
docs/wiki/indicators/(moving-averages/,momentum-oscillators/,trend-directional/,price-oscillators/,volatility-bands/,trailing-stops/,volume/,price-statistics/);Indicators-Overview.md,Home.mdand the README indicator table follow the same eight families. TickAggregator::pushreturnsResult<Vec<Candle>>(wasResult<Option<Candle>>) so a single tick can yield a closed bar plus gap fillers.Resampler::pushreturnsResult<Option<Candle>>: a candle in a bucket earlier than the open bar is now rejected as out of order.- Aggregated candles are finalised through the validating
Candle::new, so a volume that overflows to a non-finite value is surfaced as an error instead of producing a poisoned candle. - All GitHub Actions are pinned to commit SHAs; the four publish jobs run in a
protected
releaseenvironment. - The indicator benchmarks (
crates/wickra/benches/indicators.rs) now run against the checked-in real BTCUSDT 1-minute dataset instead of a synthetic price series. - Every language's examples now live under a uniform
examples/<lang>/tree: Rust moved into a newexamples/rust/workspace member crate (wickra-examples, run viacargo run -p wickra-examples --bin <name>), Node intoexamples/node/with its ownpackage.jsonlinkingwickraviafile:../../bindings/node, and the WASM browser demos intoexamples/wasm/. The bundled BTCUSDT datasets move alongside them atexamples/data/. Six new examples close the cross-language parity matrix: streaming demos for Python and Rust; multi-timeframe and parallel-assets demos for both Rust and Node. - Cross-language data-generator parity:
examples/python/fetch_btcusdt.py(stdlib only:urllib+json+csv) andexamples/node/fetch_btcusdt.js(Node 18+ built-infetch) mirror the Rustfetch_btcusdtbinary — byte-for-byte identical CSV output on the same Binance snapshot. - Four additional WebAssembly browser demos under
examples/wasm/alongside the originalindex.html:backtest.html(fetch + basket of indicators),live_trading.html(browser-nativeWebSocketto Binance),multi_timeframe.html(in-page resample) andparallel_assets.html+parallel_worker.js(module-Worker pool with serial-vs-parallel speedup). The cross-language matrix is now closed for every cell where the pattern makes sense. - Three new wiki pages:
TA-Lib-Migration.md(full mapping table fromtalib.X(...)calls to Wickra),Cookbook.md(seven concrete strategy recipes — RSI mean reversion, MACD crossover, Bollinger breakout, ADX-gated trend, multi-timeframe confirmation, SuperTrend, chained indicators) andFAQ.md. All three linked fromHome.md.
Fixed
Timeframe::floorno longer overflows for timestamps neari64::MIN.- The aggregator rejects same-bucket ticks that arrive out of order instead of silently overwriting the bar's close with a stale price.
- The Binance live stream reconnects with exponential backoff, skips non-kline frames, applies a read timeout and message-size limits, and tracks a closed flag.
- Example scripts:
live_trading.pyskips non-kline frames and validates the symbol/interval;backtest.pyandmulti_timeframe.pyreport clear errors for malformed CSV input.
0.1.4 - 2026-05-21
Added
- GitHub Release runs now attach every built artefact (wheels, sdist, native
Node binaries, npm-pack tarballs, cargo
.cratefiles) to the tag's release page.
0.1.3 - 2026-05-21
Fixed
- npm package ships the napi-generated loader and is built with
--platformso the per-platform binary is resolved correctly.
0.1.2 - 2026-05-21
Fixed
- Release pipeline: per-platform idempotent npm publishing with a spam-filter
retry, and committed
npm/<platform>/package templates.
0.1.1 - 2026-05-21
Fixed
- Node publish step and coordinated version bump across all bindings.
0.1.0 - 2026-05-21
Added
- Initial release: a streaming-first technical-analysis library with 25 indicators (SMA, EMA, WMA, DEMA, TEMA, HMA, KAMA, RSI, MACD, ROC, Stochastic, CCI, Williams %R, ADX, MFI, TRIX, Aroon, Awesome Oscillator, Bollinger Bands, ATR, Keltner Channels, Donchian Channels, Parabolic SAR, OBV, VWAP).
- Rust core (
wickra-core), umbrella crate (wickra), and a data layer (wickra-data) with a CSV reader, tick aggregator, resampler, and an optional Binance live feed. - Bindings for Python, Node.js, and WebAssembly.