49 Commits
Author SHA1 Message Date
TIANHE 9f47e5efbc chore(deps): bump CodeQL action to 4.38.1 2026-09-24 15:59:27 +08:00
TIANHE afa89a2a81 docs: add public roadmap contribution workflow 2026-09-18 17:11:13 +08:00
TIANHE 6f82a5f5b0 fix: reconcile exchange fills atomically across REST and private streams
Normalize venue contract quantities before posting and derive incremental
prices and fees from cumulative order snapshots. Serialize ledger, position
and grid state updates; reconcile delayed fees and preserve rebates,
fractional quantities and native fee currencies across supported venues.

Fix product/account routing, REST adapter contracts, initial grid recovery,
and migration bootstrap registration. Add PostgreSQL concurrency and
rollback regression coverage to CI and document venue contracts/deployment.

Validation: 2716 passed, 7 environment skips, 23 integration/stress deselected;
critical lint, compile, structure, lockfile and documentation checks passed.
Real exchange order placement was not exercised. Refs #248.
2026-09-16 21:25:41 +08:00
TIANHE 886786253e fix: preserve MCP error results across Python versions 2026-09-11 18:52:26 +08:00
dependabot[bot]dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>Henry
f5804c66f3 Bump the python-runtime group in /backend_api_python with 35 updates (#188)
* Bump the python-runtime group in /backend_api_python with 35 updates

Updates the requirements on [werkzeug](https://github.com/pallets/werkzeug), [flask-cors](https://github.com/corydolphin/flask-cors), [finnhub-python](https://github.com/Finnhub-Stock-API/finnhub-python), [yfinance](https://github.com/ranaroussi/yfinance), [ccxt](https://github.com/ccxt/ccxt), [pandas](https://github.com/pandas-dev/pandas), [ta-lib](https://github.com/ta-lib/ta-lib-python), [exchange-calendars](https://github.com/gerrymanoim/exchange_calendars), [requests](https://github.com/psf/requests), [websocket-client](https://github.com/websocket-client/websocket-client), [litellm](https://github.com/BerriAI/litellm), [certifi](https://github.com/certifi/python-certifi), [akshare](https://github.com/akfamily/akshare), [pyjwt](https://github.com/jpadilla/pyjwt), [python-dotenv](https://github.com/theskumar/python-dotenv), [cryptography](https://github.com/pyca/cryptography), [pyotp](https://github.com/pyauth/pyotp), [qrcode](https://github.com/lincolnloop/python-qrcode), [psycopg2-binary](https://github.com/psycopg/psycopg2), [prometheus-client](https://github.com/prometheus/client_python), [redis](https://github.com/redis/redis-py), [celery](https://github.com/celery/celery), [gunicorn](https://github.com/benoitc/gunicorn), [flask-smorest](https://github.com/marshmallow-code/flask-smorest), [marshmallow](https://github.com/marshmallow-code/marshmallow), [pyyaml](https://github.com/yaml/pyyaml), [pypdf](https://github.com/py-pdf/pypdf), [reportlab](https://www.reportlab.com/), [bcrypt](https://github.com/pyca/bcrypt), [alpaca-py](https://github.com/alpacahq/alpaca-py), [bandit](https://github.com/PyCQA/bandit), [pip-audit](https://github.com/pypa/pip-audit), [pytest](https://github.com/pytest-dev/pytest), [pytest-cov](https://github.com/pytest-dev/pytest-cov) and [ruff](https://github.com/astral-sh/ruff) to permit the latest version.

Updates `werkzeug` to 3.1.8
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](https://github.com/pallets/werkzeug/compare/3.1.6...3.1.8)

Updates `flask-cors` from 6.0.0 to 6.0.5
- [Release notes](https://github.com/corydolphin/flask-cors/releases)
- [Changelog](https://github.com/corydolphin/flask-cors/blob/main/CHANGELOG.md)
- [Commits](https://github.com/corydolphin/flask-cors/compare/6.0.0...6.0.5)

Updates `finnhub-python` to 2.4.29
- [Changelog](https://github.com/Finnhub-Stock-API/finnhub-python/blob/master/CHANGELOG.md)
- [Commits](https://github.com/Finnhub-Stock-API/finnhub-python/commits)

Updates `yfinance` to 1.5.2
- [Release notes](https://github.com/ranaroussi/yfinance/releases)
- [Changelog](https://github.com/ranaroussi/yfinance/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/ranaroussi/yfinance/compare/0.2.18...1.5.2)

Updates `ccxt` to 4.5.69
- [Release notes](https://github.com/ccxt/ccxt/releases)
- [Commits](https://github.com/ccxt/ccxt/compare/4.0.3...v4.5.69)

Updates `pandas` to 3.0.5
- [Release notes](https://github.com/pandas-dev/pandas/releases)
- [Commits](https://github.com/pandas-dev/pandas/compare/v1.5.0...v3.0.5)

Updates `ta-lib` from 0.6.8 to 0.7.1
- [Release notes](https://github.com/ta-lib/ta-lib-python/releases)
- [Changelog](https://github.com/TA-Lib/ta-lib-python/blob/master/CHANGELOG)
- [Commits](https://github.com/ta-lib/ta-lib-python/compare/v0.6.8...v0.7.1)

Updates `exchange-calendars` to 4.13.2
- [Release notes](https://github.com/gerrymanoim/exchange_calendars/releases)
- [Changelog](https://github.com/gerrymanoim/exchange_calendars/blob/master/docs/changes_archive.md)
- [Commits](https://github.com/gerrymanoim/exchange_calendars/compare/4.13...4.13.2)

Updates `requests` to 2.34.2
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.32.0...v2.34.2)

Updates `websocket-client` to 1.9.0
- [Release notes](https://github.com/websocket-client/websocket-client/releases)
- [Changelog](https://github.com/websocket-client/websocket-client/blob/master/ChangeLog)
- [Commits](https://github.com/websocket-client/websocket-client/compare/v1.8.0...v1.9.0)

Updates `litellm` to 1.93.0
- [Release notes](https://github.com/BerriAI/litellm/releases)
- [Commits](https://github.com/BerriAI/litellm/compare/litellm_1.81.13-dev...v1.93.0)

Updates `certifi` to 2026.7.22
- [Commits](https://github.com/certifi/python-certifi/compare/2024.02.02...2026.07.22)

Updates `akshare` to 1.18.80
- [Release notes](https://github.com/akfamily/akshare/releases)
- [Changelog](https://github.com/akfamily/akshare/blob/main/docs/changelog.md)
- [Commits](https://github.com/akfamily/akshare/compare/release-v1.16.77...release-v1.18.80)

Updates `pyjwt` to 2.13.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](https://github.com/jpadilla/pyjwt/compare/2.12.0...2.13.0)

Updates `python-dotenv` to 1.2.2
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.0.1...v1.2.2)

Updates `cryptography` to 49.0.0
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/43.0.0...49.0.0)

Updates `pyotp` to 2.10.0
- [Release notes](https://github.com/pyauth/pyotp/releases)
- [Changelog](https://github.com/pyauth/pyotp/blob/main/Changes.rst)
- [Commits](https://github.com/pyauth/pyotp/compare/v2.9.0...v2.10.0)

Updates `qrcode` to 8.2
- [Changelog](https://github.com/lincolnloop/python-qrcode/blob/main/CHANGES.rst)
- [Commits](https://github.com/lincolnloop/python-qrcode/compare/v7.4.2...v8.2)

Updates `psycopg2-binary` to 2.9.12
- [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS)
- [Commits](https://github.com/psycopg/psycopg2/compare/2.9.9...2.9.12)

Updates `prometheus-client` to 0.26.0
- [Release notes](https://github.com/prometheus/client_python/releases)
- [Commits](https://github.com/prometheus/client_python/compare/v0.22.0...v0.26.0)

Updates `redis` to 8.0.1
- [Release notes](https://github.com/redis/redis-py/releases)
- [Changelog](https://github.com/redis/redis-py/blob/master/CHANGES)
- [Commits](https://github.com/redis/redis-py/compare/v5.0.0...v8.0.1)

Updates `celery` to 5.6.3
- [Release notes](https://github.com/celery/celery/releases)
- [Changelog](https://github.com/celery/celery/blob/v5.6.3/Changelog.rst)
- [Commits](https://github.com/celery/celery/compare/v5.5.0...v5.6.3)

Updates `gunicorn` to 26.0.0
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](https://github.com/benoitc/gunicorn/compare/22.0.0...26.0.0)

Updates `flask-smorest` to 0.47.0
- [Release notes](https://github.com/marshmallow-code/flask-smorest/releases)
- [Changelog](https://github.com/marshmallow-code/flask-smorest/blob/dev/CHANGELOG.rst)
- [Commits](https://github.com/marshmallow-code/flask-smorest/compare/0.44.0...0.47.0)

Updates `marshmallow` to 4.3.0
- [Changelog](https://github.com/marshmallow-code/marshmallow/blob/dev/CHANGELOG.rst)
- [Commits](https://github.com/marshmallow-code/marshmallow/compare/3.24.1...4.3.0)

Updates `pyyaml` to 6.0.3
- [Release notes](https://github.com/yaml/pyyaml/releases)
- [Changelog](https://github.com/yaml/pyyaml/blob/6.0.3/CHANGES)
- [Commits](https://github.com/yaml/pyyaml/compare/6.0...6.0.3)

Updates `pypdf` to 6.14.2
- [Release notes](https://github.com/py-pdf/pypdf/releases)
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md)
- [Commits](https://github.com/py-pdf/pypdf/compare/6.0.0...6.14.2)

Updates `reportlab` to 5.0.0

Updates `bcrypt` to 5.0.0
- [Changelog](https://github.com/pyca/bcrypt/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/bcrypt/compare/4.1.0...5.0.0)

Updates `alpaca-py` to 0.43.5
- [Release notes](https://github.com/alpacahq/alpaca-py/releases)
- [Commits](https://github.com/alpacahq/alpaca-py/compare/v0.30.0...v0.43.5)

Updates `bandit` to 1.9.4
- [Release notes](https://github.com/PyCQA/bandit/releases)
- [Commits](https://github.com/PyCQA/bandit/compare/1.8.6...1.9.4)

Updates `pip-audit` to 2.10.1
- [Release notes](https://github.com/pypa/pip-audit/releases)
- [Changelog](https://github.com/pypa/pip-audit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/pypa/pip-audit/compare/v2.9.0...v2.10.1)

Updates `pytest` to 9.1.1
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/9.0.3...9.1.1)

Updates `pytest-cov` to 7.1.0
- [Changelog](https://github.com/pytest-dev/pytest-cov/blob/master/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest-cov/compare/v6.2.0...v7.1.0)

Updates `ruff` to 0.16.0
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.12.0...0.16.0)

---
updated-dependencies:
- dependency-name: werkzeug
  dependency-version: 3.1.8
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: flask-cors
  dependency-version: 6.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-runtime
- dependency-name: finnhub-python
  dependency-version: 2.4.29
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: yfinance
  dependency-version: 1.5.2
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: ccxt
  dependency-version: 4.5.69
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: pandas
  dependency-version: 3.0.5
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: ta-lib
  dependency-version: 0.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-runtime
- dependency-name: exchange-calendars
  dependency-version: 4.13.2
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: requests
  dependency-version: 2.34.2
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: websocket-client
  dependency-version: 1.9.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: litellm
  dependency-version: 1.93.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: certifi
  dependency-version: 2026.7.22
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: akshare
  dependency-version: 1.18.80
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: pyjwt
  dependency-version: 2.13.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: python-dotenv
  dependency-version: 1.2.2
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: cryptography
  dependency-version: 49.0.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: pyotp
  dependency-version: 2.10.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: qrcode
  dependency-version: '8.2'
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: psycopg2-binary
  dependency-version: 2.9.12
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: prometheus-client
  dependency-version: 0.26.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: redis
  dependency-version: 8.0.1
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: celery
  dependency-version: 5.6.3
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: gunicorn
  dependency-version: 26.0.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: flask-smorest
  dependency-version: 0.47.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: marshmallow
  dependency-version: 4.3.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: pyyaml
  dependency-version: 6.0.3
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: pypdf
  dependency-version: 6.14.2
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: reportlab
  dependency-version: 5.0.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: bcrypt
  dependency-version: 5.0.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: alpaca-py
  dependency-version: 0.43.5
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: bandit
  dependency-version: 1.9.4
  dependency-type: direct:development
  dependency-group: python-runtime
- dependency-name: pip-audit
  dependency-version: 2.10.1
  dependency-type: direct:development
  dependency-group: python-runtime
- dependency-name: pytest
  dependency-version: 9.1.1
  dependency-type: direct:development
  dependency-group: python-runtime
- dependency-name: pytest-cov
  dependency-version: 7.1.0
  dependency-type: direct:development
  dependency-group: python-runtime
- dependency-name: ruff
  dependency-version: 0.16.0
  dependency-type: direct:development
  dependency-group: python-runtime
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix: synchronize upgraded Python dependency lock

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Henry <jinyuxu@JinyudeMacBook-Air.local>
2026-08-01 01:52:21 +08:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 8fafc74099 Bump github/codeql-action from 4 to 4.37.3 (#187)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4 to 4.37.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v4...v4.37.3)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 01:03:33 +08:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 98f451d750 Bump docker/login-action from 4 to 4.5.2 (#186)
Bumps [docker/login-action](https://github.com/docker/login-action) from 4 to 4.5.2.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](https://github.com/docker/login-action/compare/v4...v4.5.2)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.5.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 01:03:28 +08:00
Henry f591f94a0e feat: complete full quantitative trading MCP 2026-07-31 04:37:37 +08:00
Henry ea7b53da8d fix CI dependency setup 2026-07-30 14:37:22 +08:00
TIANHE 7420677c7a v5.0.4
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-07-19 20:34:38 +08:00
TIANHE 74ee0caa43 fix(ci): restore OpenAPI validation 2026-07-19 09:41:38 +08:00
TIANHE 753a1d7f65 chore(ci): upgrade GitHub Actions to latest majors 2026-07-19 02:34:47 +08:00
TIANHE 38a52ba742 v5.0.1
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-07-18 17:58:46 +08:00
TIANHE 79b196bcf4 v5.0.1
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-07-18 17:43:02 +08:00
TIANHE 27f4b5ad00 v5.0.1
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-07-13 17:30:33 +08:00
TIANHE a87ee6192f feat: harden backend contracts observability and delivery 2026-07-13 15:42:50 +08:00
TIANHE 68fa6c42e1 v4.0.2
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-06-22 03:18:04 +08:00
TIANHE 2cc3efbf38 v4.0.1
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-06-17 02:55:06 +08:00
Dinger c435e1eeb6 v3.0.31
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-06-06 20:17:54 +08:00
Dinger 85024c26db v3.0.22
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-06-01 00:16:42 +08:00
Dinger 45402ad901 v3.0.22
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-06-01 00:11:52 +08:00
Dinger 8e60d7440e v3.0.22
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-05-31 23:57:56 +08:00
Dinger 928fcd9342 v3.0.22
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-05-31 23:48:17 +08:00
Dinger a1a51e9afc v3.0.22
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-05-31 23:39:35 +08:00
Dinger 7e2bc43152 v3.0.14
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-05-25 19:59:33 +08:00
hang666 df120c98d6 fix(deploy): preserve locally-built frontend image when build override is active
Tested empirically: with only `pull_policy: always` on the frontend service,
running `docker compose -f docker-compose.yml -f docker-compose.build.yml
build` produces a local image — but the very next `docker compose pull`
(or plain `up`) silently replaces it with GHCR's `:latest`, undoing every
local Vue change.

Override `pull_policy: build` in docker-compose.build.yml so Compose never
attempts to pull when the build override is layered. Main file alone still
pulls as before.

Also add a merged-config validation step to CI so future edits can't break
the file-stacking combination without anyone noticing.
2026-05-19 18:42:47 +08:00
hang666 34ac297389 chore(versioning): centralise version in VERSION file + add bump/check scripts
- Add repo-root VERSION as single source of truth (3.0.11).
- Mirror it via backend_api_python/app/_version.py; settings.py now imports
  APP_VERSION instead of hardcoding "3.0.9" in two places.
- scripts/bump_version.py rewrites VERSION + _version.py + env.example
  in one command.
- scripts/check_version.py verifies declarations match VERSION; wired into
  basic-ci.yml as a `version-check` job that fails PRs on drift.
- Switch all 7 README shields.io version badges to the dynamic
  `/github/v/release/<owner>/<repo>` endpoint so they auto-track GitHub
  Releases without needing the bump script.
2026-05-19 18:18:35 +08:00
hang666 04f62598c7 fix(ci): preserve UI-authored release notes via append_body
When a Release is drafted through the GitHub web UI before the tag is
pushed, the workflow would silently overwrite the hand-written
changelog. Set append_body: true so the workflow body is appended after
existing notes instead of replacing them.
2026-05-17 02:27:19 +08:00
hang666 197622d5b4 feat(ci): create GitHub Release with auto-notes on v* tag
After pushing the backend image to GHCR, action-gh-release@v2 publishes
a Release with GitHub-generated changelog and a pull snippet. Tag pushes
only — workflow_dispatch still produces just a short-SHA image. Bumps
`contents` permission to write.
2026-05-17 02:27:19 +08:00
hang666 da8261ff0a refactor(deploy): pull frontend image from GHCR, drop bundled dist tree
The Vue source lives in the private QuantDinger-Vue repo, which now
publishes ghcr.io/brokermr810/quantdinger-frontend on every v* tag.
Consuming that image directly removes ~21 MB of build artefacts and
44 dist-touching commits from this repo's history going forward.

- docker-compose.yml: frontend service switches from build: to
  image: ${FRONTEND_IMAGE:-ghcr.io/brokermr810/quantdinger-frontend}.
- Remove frontend/ (dist/, dist.zip, Dockerfile, nginx.conf.template,
  railway.json) — superseded by the published image.
- Remove scripts/build-frontend.{sh,ps1} and
  scripts/private-frontend-ci.yml.example — manual dist-sync flow gone.
- .github/workflows/docker-publish.yml: drop the frontend job; the
  Vue repo's release-frontend.yml owns that path now.
- Delete .github/workflows/update-frontend.yml (auto-sync no longer needed).
- .github/workflows/basic-ci.yml: drop the frontend-check job that
  asserted frontend/dist existed.
- .gitignore / .dockerignore: clean up the dist-allowlist exceptions.
- Docs (README, CONTRIBUTING, DEVELOPMENT, docs/README_*.md,
  docs/CLOUD_DEPLOYMENT_*.md, docs/FRONTEND_FAST_ANALYSIS.md):
  rewrite the "npm run build -> replace frontend/dist" narrative as
  "tag v* -> auto-publish to GHCR".
2026-05-17 02:27:18 +08:00
Dinger 67a123a933 v3.0.9
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-05-16 21:26:16 +08:00
Dinger dce93f1c84 v3.0.8
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-05-16 15:37:30 +08:00
hang666 7f05a6ebe9 feat(docker): add GHCR publish workflow and zero-repo compose variant
- Backend Dockerfile: new BUILD_REGION arg (cn=Aliyun mirrors+fallback,
  global=official only); default keeps China zero-config experience
- New docker-compose.ghcr.yml pulls prebuilt multi-arch backend +
  frontend images from ghcr.io; backend self-applies init.sql so no
  host SQL mount needed; single root .env serves both compose
  substitution and backend runtime config
- New .github/workflows/docker-publish.yml builds amd64+arm64 images
  on v* tag push / manual dispatch, with GHA cache, concurrency
  cancellation, and BUILD_REGION=global on the runner
- basic-ci.yml: add compose-check job to validate both compose files
- READMEs (EN/CN/JA/KO/TH/VI/AR): add zero-repo install snippet
- .env.example: document BUILD_REGION, IMAGE_TAG, BACKEND_IMAGE,
  FRONTEND_IMAGE knobs
2026-05-14 23:50:47 +08:00
Claude 93baa92cb1 ci: update nginx config check to match template rename
The frontend nginx.conf was renamed to nginx.conf.template (envsubst-driven)
in 50c64b3 so the proxy_pass URL can be set per environment. The basic-ci
"Verify Nginx config" step still asserted the old filename and would have
failed on the next push/PR to main.
2026-05-06 23:05:56 +00:00
Dinger cecbe3ddb0 v3.0.3
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-05-02 15:35:55 +08:00
dinger caaf294867 chore(security): 升级 Python 依赖并启用 Dependabot
- Flask 3.1.3、Werkzeug>=3.1.6、flask-cors 5.0.1(修复已知 GHSA)
- PyJWT>=2.12、cryptography>=43、requests>=2.32
- 新增 .github/dependabot.yml 每周检查 backend_api_python pip 依赖

Made-with: Cursor
2026-04-25 03:05:55 +08:00
Quantdinger 092333143a Update FUNDING.yml 2026-04-13 15:30:29 +08:00
Quantdinger d9005516b5 Create FUNDING.yml 2026-04-11 23:56:07 +08:00
Dinger f5c9a9b3b6 v3.0.1
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-04-09 22:38:47 +08:00
TIANHE a90f336b93 fix: remove frontend source CI (moved to private repo), update README with Vibe Coding positioning 2026-02-27 20:29:59 +08:00
TIANHE abbad97bdd v2.2.1: frontend closed-source + Docker one-click deploy
- Remove frontend source code (now in private repo)
- Add pre-built frontend/dist/ with Nginx serving
- Simplify docker-compose.yml (no Node.js build needed)
- Update README with docs index and Docker deploy guide
- Add admin order list and AI analysis stats tabs
- Add quick trade API routes
- Clean up redundant files (package-lock.json, yarn.lock, .iml)
- Add GitHub Actions workflow for frontend update automation
2026-02-27 19:57:23 +08:00
TIANHE 996e3b38fe new
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-01-13 17:09:50 +08:00
TIANHE 7053aefc33 Supports MT5 and forex trading.
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-01-13 04:10:05 +08:00
TIANHE 491cfece81 new
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-01-06 04:09:26 +08:00
TIANHE 5f6fd72a3a new
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-01-06 04:06:18 +08:00
TIANHE 2b608f37d3 new
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-01-06 04:02:32 +08:00
TIANHE 5b5ededb1d new 2026-01-06 04:00:41 +08:00
TIANHE 9b4f0c16ac new
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-01-06 03:57:59 +08:00
TIANHE 493d375f6e new
Signed-off-by: TIANHE <TIANHE@GMAIL.COM>
2026-01-06 03:52:26 +08:00