Follow-up to the Dependabot action-bump merges and the cargo-deny ignore (#271). Three low-risk supply-chain housekeeping changes — config/docs only, no library code, no runtime change. ## 1. `osv-scanner.toml` (new) The OpenSSF Scorecard *Vulnerabilities* check runs OSV-Scanner over the repo and was flagging five advisory IDs (`score is 5`). These reduce to three findings, all assessed as not affecting Wickra: | Advisory | Assessment | |----------|------------| | RUSTSEC-2026-0176 / GHSA-36hh-v3qg-5jq4 (pyo3) | Vulnerable API unused; fix is pyo3 0.29 but rust-numpy 0.28 pins pyo3 `^0.28` → upstream-blocked. Already in `deny.toml`. | | RUSTSEC-2026-0177 / GHSA-chgr-c6px-7xpp (pyo3) | Same — `PyCFunction::new_closure` not called. Already in `deny.toml`. | | GHSA-72hv-8253-57qq (jackson-core 3.x) | **Not a dependency of this project.** No manifest, Maven plugin, or the GitHub dependency-graph SBOM references `tools.jackson` 3.x; the only jackson present is `com.fasterxml.jackson.core:jackson-databind` 2.17.1. | `osv-scanner.toml` records these as ignored-with-reason at the OSV layer, mirroring `deny.toml` and the SECURITY.md VEX section. The Scorecard finding also flip-flopped (fixed → reappeared) across unrelated release-bump commits, confirming it is not a stable real exposure. ## 2. Bump `central-publishing-maven-plugin` 0.5.0 → 0.10.0 The Java binding pinned a publishing plugin five versions behind. Validated locally with the JDK 22 toolchain (`mvn -Prelease validate`): the extension loads, the existing `publishingServerId`/`autoPublish` config is compatible, and all 14 binding tests pass. The actual `mvn deploy` upload path is only exercised at release time (needs the Central token + GPG key), so it will be confirmed at the next release. ## 3. Add a Maven ecosystem to Dependabot The Java binding had no Dependabot coverage, which is why the stale 0.5.0 plugin went unnoticed. Adds `package-ecosystem: maven` over `/bindings/java`, `/bindings/java/benchmarks`, and `/examples/java` so plugin and dependency updates (incl. the examples' jackson) are tracked going forward.
Wickra — Java
Streaming-first technical indicators for the JVM, on the Java Foreign Function & Memory API — prebuilt native library, no JNI, no system dependencies.
Wickra is a multi-language technical-analysis library with a Rust core and
bindings for Python, Node.js and WebAssembly, plus a C ABI for C/C++, C#, Go, Java, R
and any other C-capable language. Every indicator is an O(1) streaming state
machine, so live trading bots and historical backtests share the exact same
implementation. This package is the Java binding; it consumes the C ABI hub
through the Panama FFM API (java.lang.foreign) and exposes all 514
streaming-first indicators as idiomatic AutoCloseable classes.
Requirements
- Java 22 or later (the FFM API is final since Java 22; no preview flag).
- The FFM API is restricted: pass
--enable-native-access=ALL-UNNAMEDwhen you run your application to silence the native-access warning.
Install
Maven:
<dependency>
<groupId>org.wickra</groupId>
<artifactId>wickra</artifactId>
<version>0.8.8</version>
</dependency>
Gradle:
implementation("org.wickra:wickra:0.8.8")
The native library ships prebuilt per platform (Linux, macOS, Windows — x64 and arm64) inside the jar and is extracted automatically on first use. There is nothing to compile.
Quick start
import org.wickra.Ema;
import org.wickra.Rsi;
// Batch: run an indicator over a whole series (NaN at warmup positions).
double[] prices = new double[1000];
for (int i = 0; i < prices.length; i++) {
prices[i] = 100.0 + i * 0.1;
}
try (Ema ema = new Ema(20)) {
double[] values = ema.batch(prices);
}
// Streaming: the same indicator, fed tick by tick in O(1).
try (Rsi rsi = new Rsi(14)) {
for (double price : liveFeed) {
double value = rsi.update(price); // NaN during warmup, no recomputation
if (Double.isFinite(value) && value > 70) {
System.out.println("overbought");
}
}
}
batch(prices) and feeding the same prices through update() produce identical
values — the equivalence is enforced by the test suite. Multi-output indicators
(MACD, Bollinger, ADX, …) return a record, null while warming up. Each
indicator owns a native handle freed by a Cleaner; close() releases it
eagerly (use try-with-resources).
Benchmark
benchmarks/ reports streaming and batch updates-per-second for SMA, ATR
and MACD. It measures this binding's FFI overhead, not a cross-library ratio
(the same Rust core runs under every binding) — see the repository
BENCHMARKS.md §3.
cargo build -p wickra-c --release
mvn -q install -DskipTests
mvn -q -f benchmarks exec:exec -Dexec.mainClass=org.wickra.benchmarks.Throughput
Documentation
The full indicator catalogue, guides, quickstarts, and API reference live in the main repository and documentation site:
- Repository & full indicator list: https://github.com/wickra-lib/wickra
- Docs (quickstarts, cookbook, TA-Lib migration): https://docs.wickra.org
- Runnable examples:
examples/java/
Wickra ships native bindings for Python, Node.js, WebAssembly and Rust, plus a
C ABI hub that any C-capable language (C, C++, Go, C#, Java, R) links against —
all exposing the same indicators from the shared, unsafe-forbidden Rust core.
Disclaimer
Wickra is an indicator toolkit, not a trading system. The values it computes are deterministic transforms of the input data — they are not financial advice and do not predict the market. Any use in a live trading context is at your own risk. The library is provided as is, without warranty of any kind.
License
Licensed under either of Apache-2.0 or MIT at your option.