Hi, This is a call to vote on the release of the Apache Milagro (incubating) MPC v0.1 tag from the following repository:
Incubator-milagro-MPC: https://github.com/apache/incubator-milagro-MPC/releases/tag/0.1 OVERVIEW libmpc is a modern cryptographic C library that implements Multi-Party Computation, or MPC. This library implements the primitives necessary to instantiate the multi-party ECDSA signature scheme provided in Gennaro and Goldfeder’s “Fast Multiparty Threshold ECDSA with Fast Trustless Setup” (GG18) (https://eprint.iacr.org/2019/114.pdf). GG18 consists of a multiparty threshold signature scheme which enables distributed signing among n players such that any subgroup of size t + 1 can sign, whereas any group with t or fewer players cannot. This scheme is proven secure for any t <= n and provides significant reduction of computation and communication complexity comparing to other existing schemes. NCC Group has conducted a security assessment of libmpc (https://research.nccgroup.com/wp-content/uploads/2020/07/NCC_Group_Qredo_Apache_Milagro_MPC_Cryptographic_Review_2020-07-16_v1.3.pdf). RELEASE RATIONALE libmpc has been under development for several years now, and we consider it to be stable enough to have a first official release. With this release, we also introduce a modernised docker-first build-system that we would like to extend to other Apache Milagro releases. We have taken this step to better support the most diverse development and deployment environments currently used by the community. Please provide feedback if there is anything you would like to see happening next. As always, please see the README for build/test instructions, a list of contributors and guidelines on how to contribute yourself. The repo has the required DISCLAIMER, NOTICE and LICENSE file in its root directory. All source files have the appropriate license header. No binaries are included in this release. I have successfully built and ran the tests as per the instructions in the readme file. The compressed archives from this release along with a SHA512 checksum, PGP signature and PGP key file are being staged here: https://dist.apache.org/repos/dist/dev/incubator/milagro/apache-milagro-mpc-0.1-incubating/ Specifically: Source code archive: https://dist.apache.org/repos/dist/dev/incubator/milagro/apache-milagro-mpc-0.1-incubating/apache-milagro-mpc-0.1-incubating-src.tar.gz SHA512 checksum: https://dist.apache.org/repos/dist/dev/incubator/milagro/apache-milagro-mpc-0.1-incubating/apache-milagro-mpc-0.1-incubating-src.tar.gz.sha512 PGP Signature: https://dist.apache.org/repos/dist/dev/incubator/milagro/apache-milagro-mpc-0.1-incubating/apache-milagro-mpc-0.1-incubating-src.tar.gz.asc Keys: https://dist.apache.org/repos/dist/dev/incubator/milagro/KEYS Documentation can be found here: https://milagro.apache.org/docs/mpc-api-0.1/ (including a link at the bottom of the page to the Doxygen output from the MPC library). This round of voting will remain open for at least 72 hours. All committers are welcome to vote. 3 x [+1] votes are required to move forward. If the vote is passed, a second vote is requested from the IPMC. Please vote: [+1] Signatures and checksums verified. Releases built and tests completed. Release approved. [0] No opinion [-1] Release rejected – please include your reasoning. Many thanks to all the contributors. Regards, John John McCane-Whitney DIRECTOR OF PRODUCT +44 (0) 7966 490687 qredo.com <http://www.qredo.com/> <https://www.linkedin.com/company/qredo> <https://twitter.com/qredonetwork> <http://www.qredo.com/> Qredo Ltd is a limited company registered in England and Wales (registered number 7834052). This e-mail and any attachments are confidential, and are intended only for the named addressee(s). If you are not the intended recipient you may not copy, disclose to anyone else or otherwise use the content of this e-mail or any attachment thereto and should notify the sender immediately and delete them from your system.
