Files
wickra/bindings/java
kingchenc 8ccfd638b2 chore(supply-chain): osv-scanner suppressions, bump publishing plugin, track Maven in Dependabot (#272)
Follow-up to the Dependabot action-bump merges and the cargo-deny ignore (#271).
Three low-risk supply-chain housekeeping changes — config/docs only, no library
code, no runtime change.

## 1. `osv-scanner.toml` (new)

The OpenSSF Scorecard *Vulnerabilities* check runs OSV-Scanner over the repo and
was flagging five advisory IDs (`score is 5`). These reduce to three findings,
all assessed as not affecting Wickra:

| Advisory | Assessment |
|----------|------------|
| RUSTSEC-2026-0176 / GHSA-36hh-v3qg-5jq4 (pyo3) | Vulnerable API unused; fix is pyo3 0.29 but rust-numpy 0.28 pins pyo3 `^0.28` → upstream-blocked. Already in `deny.toml`. |
| RUSTSEC-2026-0177 / GHSA-chgr-c6px-7xpp (pyo3) | Same — `PyCFunction::new_closure` not called. Already in `deny.toml`. |
| GHSA-72hv-8253-57qq (jackson-core 3.x) | **Not a dependency of this project.** No manifest, Maven plugin, or the GitHub dependency-graph SBOM references `tools.jackson` 3.x; the only jackson present is `com.fasterxml.jackson.core:jackson-databind` 2.17.1. |

`osv-scanner.toml` records these as ignored-with-reason at the OSV layer,
mirroring `deny.toml` and the SECURITY.md VEX section. The Scorecard finding
also flip-flopped (fixed → reappeared) across unrelated release-bump commits,
confirming it is not a stable real exposure.

## 2. Bump `central-publishing-maven-plugin` 0.5.0 → 0.10.0

The Java binding pinned a publishing plugin five versions behind. Validated
locally with the JDK 22 toolchain (`mvn -Prelease validate`): the extension
loads, the existing `publishingServerId`/`autoPublish` config is compatible, and
all 14 binding tests pass. The actual `mvn deploy` upload path is only exercised
at release time (needs the Central token + GPG key), so it will be confirmed at
the next release.

## 3. Add a Maven ecosystem to Dependabot

The Java binding had no Dependabot coverage, which is why the stale 0.5.0 plugin
went unnoticed. Adds `package-ecosystem: maven` over `/bindings/java`,
`/bindings/java/benchmarks`, and `/examples/java` so plugin and dependency
updates (incl. the examples' jackson) are tracked going forward.
2026-06-12 23:15:56 +02:00
..
2026-06-11 22:44:47 +02:00

Wickra — Java

CI codecov Maven Central License: MIT OR Apache-2.0

Streaming-first technical indicators for the JVM, on the Java Foreign Function & Memory API — prebuilt native library, no JNI, no system dependencies.

Wickra is a multi-language technical-analysis library with a Rust core and bindings for Python, Node.js and WebAssembly, plus a C ABI for C/C++, C#, Go, Java, R and any other C-capable language. Every indicator is an O(1) streaming state machine, so live trading bots and historical backtests share the exact same implementation. This package is the Java binding; it consumes the C ABI hub through the Panama FFM API (java.lang.foreign) and exposes all 514 streaming-first indicators as idiomatic AutoCloseable classes.

Requirements

  • Java 22 or later (the FFM API is final since Java 22; no preview flag).
  • The FFM API is restricted: pass --enable-native-access=ALL-UNNAMED when you run your application to silence the native-access warning.

Install

Maven:

<dependency>
  <groupId>org.wickra</groupId>
  <artifactId>wickra</artifactId>
  <version>0.8.8</version>
</dependency>

Gradle:

implementation("org.wickra:wickra:0.8.8")

The native library ships prebuilt per platform (Linux, macOS, Windows — x64 and arm64) inside the jar and is extracted automatically on first use. There is nothing to compile.

Quick start

import org.wickra.Ema;
import org.wickra.Rsi;

// Batch: run an indicator over a whole series (NaN at warmup positions).
double[] prices = new double[1000];
for (int i = 0; i < prices.length; i++) {
    prices[i] = 100.0 + i * 0.1;
}
try (Ema ema = new Ema(20)) {
    double[] values = ema.batch(prices);
}

// Streaming: the same indicator, fed tick by tick in O(1).
try (Rsi rsi = new Rsi(14)) {
    for (double price : liveFeed) {
        double value = rsi.update(price); // NaN during warmup, no recomputation
        if (Double.isFinite(value) && value > 70) {
            System.out.println("overbought");
        }
    }
}

batch(prices) and feeding the same prices through update() produce identical values — the equivalence is enforced by the test suite. Multi-output indicators (MACD, Bollinger, ADX, …) return a record, null while warming up. Each indicator owns a native handle freed by a Cleaner; close() releases it eagerly (use try-with-resources).

Benchmark

benchmarks/ reports streaming and batch updates-per-second for SMA, ATR and MACD. It measures this binding's FFI overhead, not a cross-library ratio (the same Rust core runs under every binding) — see the repository BENCHMARKS.md §3.

cargo build -p wickra-c --release
mvn -q install -DskipTests
mvn -q -f benchmarks exec:exec -Dexec.mainClass=org.wickra.benchmarks.Throughput

Documentation

The full indicator catalogue, guides, quickstarts, and API reference live in the main repository and documentation site:

Wickra ships native bindings for Python, Node.js, WebAssembly and Rust, plus a C ABI hub that any C-capable language (C, C++, Go, C#, Java, R) links against — all exposing the same indicators from the shared, unsafe-forbidden Rust core.

Disclaimer

Wickra is an indicator toolkit, not a trading system. The values it computes are deterministic transforms of the input data — they are not financial advice and do not predict the market. Any use in a live trading context is at your own risk. The library is provided as is, without warranty of any kind.

License

Licensed under either of Apache-2.0 or MIT at your option.