Diff of the two buildlogs: -- --- b1/build.log 2025-08-30 15:01:04.863754899 +0000 +++ b2/build.log 2025-08-30 15:08:34.800321532 +0000 @@ -1,6 +1,6 @@ I: pbuilder: network access will be disabled during build -I: Current time: Fri Oct 2 09:16:33 -12 2026 -I: pbuilder-time-stamp: 1790975793 +I: Current time: Sun Aug 31 05:01:06 +14 2025 +I: pbuilder-time-stamp: 1756566066 I: Building the build Environment I: extracting base tarball [/var/cache/pbuilder/forky-reproducible-base.tgz] I: copying local configuration @@ -25,52 +25,84 @@ dpkg-source: info: applying disable-rpmtuf.patch I: Not using root during the build. I: Installing the build-deps -I: user script /srv/workspace/pbuilder/2877701/tmp/hooks/D02_print_environment starting +I: user script /srv/workspace/pbuilder/2982458/tmp/hooks/D01_modify_environment starting +debug: Running on infom01-amd64. +I: Changing host+domainname to test build reproducibility +I: Adding a custom variable just for the fun of it... +I: Changing /bin/sh to bash +'/bin/sh' -> '/bin/bash' +lrwxrwxrwx 1 root root 9 Aug 30 15:01 /bin/sh -> /bin/bash +I: Setting pbuilder2's login shell to /bin/bash +I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other +I: user script /srv/workspace/pbuilder/2982458/tmp/hooks/D01_modify_environment finished +I: user script /srv/workspace/pbuilder/2982458/tmp/hooks/D02_print_environment starting I: set - BUILDDIR='/build/reproducible-path' - BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other' - BUILDUSERNAME='pbuilder1' - BUILD_ARCH='amd64' - DEBIAN_FRONTEND='noninteractive' - DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=16 ' - DISTRIBUTION='forky' - HOME='/root' - HOST_ARCH='amd64' + BASH=/bin/sh + BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath + BASH_ALIASES=() + BASH_ARGC=() + BASH_ARGV=() + BASH_CMDS=() + BASH_LINENO=([0]="12" [1]="0") + BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:. + BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment") + BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="x86_64-pc-linux-gnu") + BASH_VERSION='5.2.37(1)-release' + BUILDDIR=/build/reproducible-path + BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other' + BUILDUSERNAME=pbuilder2 + BUILD_ARCH=amd64 + DEBIAN_FRONTEND=noninteractive + DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=12 ' + DIRSTACK=() + DISTRIBUTION=forky + EUID=0 + FUNCNAME=([0]="Echo" [1]="main") + GROUPS=() + HOME=/root + HOSTNAME=i-capture-the-hostname + HOSTTYPE=x86_64 + HOST_ARCH=amd64 IFS=' ' - INVOCATION_ID='9f6db4b8260d4c619620a0a47297fdc7' - LANG='C' - LANGUAGE='en_US:en' - LC_ALL='C' - MAIL='/var/mail/root' - OPTIND='1' - PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games' - PBCURRENTCOMMANDLINEOPERATION='build' - PBUILDER_OPERATION='build' - PBUILDER_PKGDATADIR='/usr/share/pbuilder' - PBUILDER_PKGLIBDIR='/usr/lib/pbuilder' - PBUILDER_SYSCONFDIR='/etc' - PPID='2877701' - PS1='# ' - PS2='> ' + INVOCATION_ID=d23a3c1d5a724b90a89c4709e2fcb5fb + LANG=C + LANGUAGE=et_EE:et + LC_ALL=C + MACHTYPE=x86_64-pc-linux-gnu + MAIL=/var/mail/root + OPTERR=1 + OPTIND=1 + OSTYPE=linux-gnu + PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path + PBCURRENTCOMMANDLINEOPERATION=build + PBUILDER_OPERATION=build + PBUILDER_PKGDATADIR=/usr/share/pbuilder + PBUILDER_PKGLIBDIR=/usr/lib/pbuilder + PBUILDER_SYSCONFDIR=/etc + PIPESTATUS=([0]="0") + POSIXLY_CORRECT=y + PPID=2982458 PS4='+ ' - PWD='/' - SHELL='/bin/bash' - SHLVL='2' - SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.Qowjf3eo/pbuilderrc_qV61 --distribution forky --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/forky-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.Qowjf3eo/b1 --logfile b1/build.log rekor_1.3.9-1.dsc' - SUDO_GID='109' - SUDO_HOME='/var/lib/jenkins' - SUDO_UID='104' - SUDO_USER='jenkins' - TERM='unknown' - TZ='/usr/share/zoneinfo/Etc/GMT+12' - USER='root' - _='/usr/bin/systemd-run' + PWD=/ + SHELL=/bin/bash + SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix + SHLVL=3 + SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.Qowjf3eo/pbuilderrc_PQaL --distribution forky --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/forky-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.Qowjf3eo/b2 --logfile b2/build.log rekor_1.3.9-1.dsc' + SUDO_GID=109 + SUDO_HOME=/var/lib/jenkins + SUDO_UID=104 + SUDO_USER=jenkins + TERM=unknown + TZ=/usr/share/zoneinfo/Etc/GMT-14 + UID=0 + USER=root + _='I: set' I: uname -a - Linux infom02-amd64 6.12.41+deb13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.41-1 (2025-08-12) x86_64 GNU/Linux + Linux i-capture-the-hostname 6.12.41+deb13-cloud-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.41-1 (2025-08-12) x86_64 GNU/Linux I: ls -l /bin - lrwxrwxrwx 1 root root 7 Aug 10 2025 /bin -> usr/bin -I: user script /srv/workspace/pbuilder/2877701/tmp/hooks/D02_print_environment finished + lrwxrwxrwx 1 root root 7 Aug 10 12:30 /bin -> usr/bin +I: user script /srv/workspace/pbuilder/2982458/tmp/hooks/D02_print_environment finished -> Attempting to satisfy build-dependencies -> Creating pbuilder-satisfydepends-dummy package Package: pbuilder-satisfydepends-dummy @@ -689,7 +721,7 @@ Get: 515 http://deb.debian.org/debian forky/main amd64 golang-k8s-sigs-release-utils-dev all 0.8.5-2 [37.3 kB] Get: 516 http://deb.debian.org/debian forky/main amd64 golang-webpki-org-jsoncanonicalizer-dev all 1.0.1-3 [6972 B] Get: 517 http://deb.debian.org/debian forky/main amd64 help2man amd64 1.49.3 [198 kB] -Fetched 232 MB in 9s (26.5 MB/s) +Fetched 232 MB in 11s (20.5 MB/s) Preconfiguring packages ... Selecting previously unselected package golang-golang-x-sys-dev. (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 19855 files and directories currently installed.) @@ -2345,8 +2377,8 @@ Setting up tzdata (2025b-5) ... Current default time zone: 'Etc/UTC' -Local time is now: Fri Oct 2 21:22:27 UTC 2026. -Universal Time is now: Fri Oct 2 21:22:27 UTC 2026. +Local time is now: Sat Aug 30 15:07:19 UTC 2025. +Universal Time is now: Sat Aug 30 15:07:19 UTC 2025. Run 'dpkg-reconfigure tzdata' if you wish to change it. Setting up golang-github-coreos-go-semver-dev (0.3.0-1) ... @@ -2778,7 +2810,11 @@ Building tag database... -> Finished parsing the build-deps I: Building the package -I: Running cd /build/reproducible-path/rekor-1.3.9/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S > ../rekor_1.3.9-1_source.changes +I: user script /srv/workspace/pbuilder/2982458/tmp/hooks/A99_set_merged_usr starting +Not re-configuring usrmerge for forky +I: user script /srv/workspace/pbuilder/2982458/tmp/hooks/A99_set_merged_usr finished +hostname: Name or service not known +I: Running cd /build/reproducible-path/rekor-1.3.9/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S > ../rekor_1.3.9-1_source.changes dpkg-buildpackage: info: source package rekor dpkg-buildpackage: info: source version 1.3.9-1 dpkg-buildpackage: info: source distribution unstable @@ -2798,103 +2834,103 @@ debian/rules execute_before_dh_auto_build make[1]: Entering directory '/build/reproducible-path/rekor-1.3.9' rm -rfv _build/src/github.com/sigstore/rekor/pkg/types/rpm -removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/e2e.go' removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/rpm.go' removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/v0.0.1/fuzz_test.go' removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/v0.0.1/entry.go' removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/v0.0.1/entry_test.go' removed directory '_build/src/github.com/sigstore/rekor/pkg/types/rpm/v0.0.1' removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/e2e_test.go' +removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/e2e.go' removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/rpm_test.go' removed directory '_build/src/github.com/sigstore/rekor/pkg/types/rpm' rm -rfv _build/src/github.com/sigstore/rekor/pkg/types/tuf removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/tuf.go' +removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/tuf_test.go' removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/v0.0.1/fuzz_test.go' removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/v0.0.1/entry.go' removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/v0.0.1/entry_test.go' removed directory '_build/src/github.com/sigstore/rekor/pkg/types/tuf/v0.0.1' -removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/tuf_test.go' removed directory '_build/src/github.com/sigstore/rekor/pkg/types/tuf' rm -rfv _build/src/github.com/sigstore/rekor/pkg/pki/tuf -removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/tuf_e2e_test.go' removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/tuf.go' removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/tuf_test.go' -removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/bogus.json' +removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/tuf_e2e_test.go' +removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/e2e_test.go' +removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/1.root.json' removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/unsigned_root.json' -removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/other_root.json' +removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/bogus.json' removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/timestamp.json' -removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/1.root.json' removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/reformat.1.root.json' +removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/other_root.json' removed directory '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata' -removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/e2e_test.go' removed directory '_build/src/github.com/sigstore/rekor/pkg/pki/tuf' make[1]: Leaving directory '/build/reproducible-path/rekor-1.3.9' dh_auto_build -O--builddirectory=_build -O--buildsystem=golang - cd _build && go install -trimpath -v -p 16 github.com/sigstore/rekor/cmd/rekor-cli -internal/unsafeheader + cd _build && go install -trimpath -v -p 12 github.com/sigstore/rekor/cmd/rekor-cli +internal/godebugs internal/goarch +internal/byteorder +internal/unsafeheader +internal/coverage/rtcov +internal/runtime/atomic +internal/msan internal/profilerecord internal/goos -internal/godebugs -internal/asan -unicode -math/bits -internal/coverage/rtcov -internal/byteorder internal/runtime/syscall -internal/msan -internal/runtime/atomic +internal/abi +internal/runtime/math +internal/asan +internal/runtime/sys internal/goexperiment internal/cpu sync/atomic +math/bits +internal/chacha8rand +unicode unicode/utf8 -internal/abi -internal/runtime/math internal/itoa crypto/internal/fips140/alias -internal/runtime/sys +crypto/internal/fips140deps/byteorder +crypto/internal/fips140/subtle cmp -crypto/internal/boring/sig unicode/utf16 -internal/chacha8rand -crypto/internal/fips140deps/byteorder +crypto/internal/boring/sig vendor/golang.org/x/crypto/cryptobyte/asn1 -crypto/internal/fips140/subtle internal/nettrace encoding +internal/runtime/exithook container/list vendor/golang.org/x/crypto/internal/alias +crypto/internal/fips140deps/cpu log/internal +internal/bytealg go.mongodb.org/mongo-driver/bson/bsonoptions go.mongodb.org/mongo-driver/bson/bsontype -google.golang.org/protobuf/internal/flags -internal/runtime/exithook google.golang.org/protobuf/internal/set +google.golang.org/protobuf/internal/flags github.com/sigstore/rekor/pkg/pki/identity golang.org/x/crypto/internal/alias +math golang.org/x/crypto/salsa20/salsa image/color golang.org/x/exp/constraints github.com/pelletier/go-toml/v2/internal/characters log/slog/internal go.opentelemetry.io/otel/metric/embedded +golang.org/x/exp/slices go.opentelemetry.io/otel/trace/embedded google.golang.org/grpc/serviceconfig -golang.org/x/exp/slices github.com/tink-crypto/tink-go/internal github.com/tink-crypto/tink-go/internal/internalapi github.com/tink-crypto/tink-go/key -internal/bytealg -crypto/internal/fips140deps/cpu github.com/aws/aws-sdk-go-v2/internal/sdkio github.com/aws/aws-sdk-go/aws/client/metadata github.com/googleapis/gax-go/v2/internal github.com/golang/groupcache/lru -math go.opencensus.io go.opencensus.io/trace/internal -github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/common go.opencensus.io/internal/tagencoding +github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/common github.com/transparency-dev/merkle internal/stringslite internal/race @@ -2906,181 +2942,177 @@ internal/reflectlite iter crypto/subtle -weak sync +weak maps slices +errors +sort internal/bisect -internal/testlog internal/singleflight -github.com/josharian/intern +internal/testlog unique +github.com/josharian/intern go.uber.org/zap/internal/pool google.golang.org/protobuf/internal/pragma -github.com/aws/aws-sdk-go/internal/sync/singleflight -log/slog/internal/buffer github.com/spf13/viper/internal/encoding -errors -sort +log/slog/internal/buffer +github.com/aws/aws-sdk-go/internal/sync/singleflight runtime/cgo internal/oserror -internal/godebug -io -path strconv -github.com/sassoftware/relic/signers/sigerrors -container/heap -golang.org/x/crypto/cast5 -github.com/hashicorp/hcl/hcl/strconv -vendor/golang.org/x/net/dns/dnsmessage +path math/rand/v2 -google.golang.org/grpc/internal/buffer +vendor/golang.org/x/net/dns/dnsmessage +golang.org/x/crypto/cast5 +io syscall -hash +github.com/sassoftware/relic/signers/sigerrors +internal/godebug bytes -internal/saferio -github.com/aws/smithy-go/transport/http/internal/io -github.com/aws/aws-sdk-go/internal/sdkio -go.step.sm/crypto/internal/utils/utfbom strings -crypto/internal/fips140deps/godebug -hash/crc32 -hash/adler32 -math/rand -hash/fnv crypto/internal/randutil -google.golang.org/grpc/internal/grpcrand -reflect +internal/saferio +github.com/hashicorp/hcl/hcl/strconv +hash +google.golang.org/grpc/internal/buffer +crypto net/netip +hash/crc32 +reflect +hash/fnv golang.org/x/crypto/openpgp/errors +hash/adler32 golang.org/x/crypto/blowfish -encoding/base32 -crypto -github.com/x448/float16 +golang.org/x/crypto/openpgp/s2k vendor/golang.org/x/text/transform +crypto/internal/fips140deps/godebug +math/rand golang.org/x/text/transform +github.com/aws/smithy-go/transport/http/internal/io github.com/aws/smithy-go/io -golang.org/x/crypto/openpgp/s2k +container/heap +github.com/aws/aws-sdk-go/internal/sdkio +go.step.sm/crypto/internal/utils/utfbom +encoding/base32 +github.com/x448/float16 +golang.org/x/text/runes crypto/internal/fips140 -crypto/internal/impl html -net/http/internal/ascii +crypto/internal/impl +regexp/syntax bufio +net/http/internal/ascii +google.golang.org/grpc/internal/grpcrand github.com/aws/aws-sdk-go-v2/internal/strings github.com/aws/aws-sdk-go/internal/strings -regexp/syntax -golang.org/x/text/runes github.com/aws/aws-sdk-go/internal/sdkuri go.step.sm/crypto/internal/emoji crypto/internal/fips140/sha3 -crypto/tls/internal/fips140tls crypto/internal/fips140/sha256 crypto/internal/fips140/sha512 +crypto/tls/internal/fips140tls +internal/syscall/execenv +internal/syscall/unix compress/bzip2 image +time crypto/sha3 crypto/internal/fips140/hmac -internal/syscall/unix -internal/syscall/execenv -time crypto/internal/fips140/check crypto/internal/fips140hash +crypto/internal/fips140/edwards25519/field crypto/internal/fips140/aes crypto/internal/fips140/nistec/fiat -crypto/internal/fips140/edwards25519/field crypto/internal/fips140/bigmod crypto/internal/fips140/hkdf crypto/internal/fips140/tls12 crypto/internal/fips140/tls13 regexp -image/internal/imageutil crypto/internal/fips140/edwards25519 +image/internal/imageutil image/jpeg google.golang.org/api/internal/third_party/uritemplates context -go.uber.org/zap/buffer +io/fs internal/poll -google.golang.org/grpc/backoff +go.uber.org/zap/buffer google.golang.org/grpc/keepalive -github.com/aws/smithy-go/ptr +google.golang.org/grpc/backoff github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/common -io/fs github.com/aws/aws-sdk-go-v2/internal/timeconv +github.com/aws/smithy-go/ptr github.com/aws/aws-sdk-go/internal/sdkrand github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.1 -github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v1 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.2 -go.uber.org/zap/internal/bufferpool +github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v1 crypto/internal/fips140/nistec -go.uber.org/zap/internal/stacktrace +go.uber.org/zap/internal/bufferpool google.golang.org/grpc/internal/backoff +google.golang.org/grpc/internal/grpcsync github.com/tink-crypto/tink-go/tink github.com/aws/aws-sdk-go-v2/internal/sdk go.opentelemetry.io/otel/internal/baggage github.com/aws/smithy-go/context -google.golang.org/grpc/internal/grpcsync -internal/filepathlite +go.uber.org/zap/internal/stacktrace embed github.com/spf13/afero/internal/common +internal/filepathlite google.golang.org/protobuf/internal/editiondefaults -os internal/fmtsort -encoding/binary go.opentelemetry.io/otel/internal/attribute +encoding/binary +os encoding/base64 vendor/golang.org/x/crypto/internal/poly1305 golang.org/x/crypto/internal/poly1305 github.com/tink-crypto/tink-go/internal/outputprefix filippo.io/edwards25519/field golang.org/x/sys/unix -golang.org/x/crypto/openpgp/armor encoding/pem +golang.org/x/crypto/openpgp/armor golang.org/x/crypto/nacl/secretbox filippo.io/edwards25519 -crypto/internal/sysrand +fmt io/ioutil -path/filepath -google.golang.org/protobuf/internal/detrand go.uber.org/zap/internal/exit -vendor/golang.org/x/sys/cpu -google.golang.org/grpc/internal/envconfig internal/sysinfo +google.golang.org/grpc/internal/envconfig +google.golang.org/protobuf/internal/detrand +crypto/internal/sysrand +path/filepath golang.org/x/sys/cpu -fmt +vendor/golang.org/x/sys/cpu net crypto/internal/entropy crypto/internal/fips140/drbg -golang.org/x/crypto/blake2b golang.org/x/crypto/sha3 -github.com/spf13/afero/mem -github.com/sassoftware/relic/lib/atomicfile +golang.org/x/crypto/blake2b os/exec -github.com/shibumi/go-pathspec -crypto/internal/fips140only crypto/internal/fips140/aes/gcm +github.com/spf13/afero/mem +github.com/shibumi/go-pathspec +github.com/sassoftware/relic/lib/atomicfile crypto/internal/fips140/ecdh +crypto/internal/fips140only crypto/internal/fips140/ecdsa crypto/internal/fips140/ed25519 +crypto/md5 crypto/internal/fips140/rsa crypto/internal/fips140/mlkem -crypto/rc4 -crypto/md5 -github.com/mitchellh/go-homedir +math/big crypto/cipher -crypto/internal/boring -vendor/golang.org/x/crypto/chacha20 -golang.org/x/crypto/chacha20 -crypto/des -software.sslmate.com/src/go-pkcs12/internal/rc2 -net/url -encoding/csv encoding/hex -log +net/url encoding/json -math/big +encoding/csv encoding/xml compress/flate -vendor/golang.org/x/text/unicode/norm +crypto/rc4 +crypto/internal/boring +crypto/des +vendor/golang.org/x/crypto/chacha20 +log crypto/sha256 crypto/aes crypto/ecdh @@ -3088,208 +3120,186 @@ crypto/sha1 crypto/hmac vendor/golang.org/x/crypto/chacha20poly1305 +vendor/golang.org/x/text/unicode/norm vendor/golang.org/x/net/http2/hpack mime -mime/quotedprintable vendor/golang.org/x/text/unicode/bidi +mime/quotedprintable +compress/gzip net/http/internal database/sql/driver gopkg.in/yaml.v3 golang.org/x/sync/errgroup +github.com/mitchellh/go-homedir google.golang.org/protobuf/internal/errors go/token +google.golang.org/protobuf/encoding/protowire google.golang.org/protobuf/internal/version +github.com/oklog/ulid +internal/profile +vendor/golang.org/x/text/secure/bidirule +google.golang.org/protobuf/reflect/protoreflect text/tabwriter -google.golang.org/protobuf/encoding/protowire runtime/trace -compress/gzip +vendor/golang.org/x/net/idna runtime/debug flag +github.com/mailru/easyjson/jlexer +go.uber.org/atomic +runtime/pprof go.uber.org/zap/internal/color encoding/gob -google.golang.org/protobuf/reflect/protoreflect -github.com/oklog/ulid -internal/profile -runtime/pprof github.com/go-openapi/analysis/internal/debug -github.com/go-openapi/jsonreference/internal -vendor/golang.org/x/text/secure/bidirule -github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer -golang.org/x/crypto/pbkdf2 -golang.org/x/term -github.com/opencontainers/go-digest -compress/zlib -text/template/parse -golang.org/x/crypto/scrypt -golang.org/x/crypto/curve25519 -golang.org/x/crypto/ssh/internal/bcrypt_pbkdf -github.com/fsnotify/fsnotify/internal -github.com/spf13/jwalterweatherman -github.com/subosito/gotenv -golang.org/x/text/unicode/norm -github.com/mailru/easyjson/jlexer -go.uber.org/atomic -github.com/fsnotify/fsnotify -github.com/blang/semver -github.com/hashicorp/hcl/hcl/token -vendor/golang.org/x/net/idna -gopkg.in/ini.v1 -github.com/hashicorp/hcl/hcl/ast -google.golang.org/protobuf/internal/descfmt crypto/dsa crypto/elliptic crypto/internal/boring/bbig encoding/asn1 crypto/rand +github.com/go-openapi/jsonreference/internal +github.com/blang/semver +crypto/ed25519 +crypto/rsa +crypto/internal/hpke +go.mongodb.org/mongo-driver/bson/primitive +go.uber.org/multierr +go.uber.org/zap/zapcore +github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer +google.golang.org/protobuf/internal/descfmt google.golang.org/protobuf/internal/descopts google.golang.org/protobuf/internal/strs +go.mongodb.org/mongo-driver/x/bsonx/bsoncore google.golang.org/protobuf/internal/encoding/messageset google.golang.org/protobuf/internal/genid google.golang.org/protobuf/internal/order -crypto/ed25519 -crypto/rsa -crypto/internal/hpke -go.mongodb.org/mongo-driver/bson/primitive -google.golang.org/protobuf/internal/encoding/text google.golang.org/protobuf/reflect/protoregistry +vendor/golang.org/x/crypto/cryptobyte +crypto/x509/pkix +google.golang.org/protobuf/internal/encoding/text google.golang.org/protobuf/runtime/protoiface -go.uber.org/multierr -google.golang.org/protobuf/internal/protolazy golang.org/x/crypto/ed25519 -github.com/secure-systems-lab/go-securesystemslib/encrypted -golang.org/x/crypto/openpgp/elgamal -text/template +golang.org/x/crypto/pbkdf2 github.com/jedisct1/go-minisign -google.golang.org/protobuf/internal/encoding/json -go.mongodb.org/mongo-driver/x/bsonx/bsoncore -google.golang.org/protobuf/proto -go.uber.org/zap/zapcore -github.com/hashicorp/hcl/hcl/scanner -github.com/hashicorp/hcl/json/token +golang.org/x/term +google.golang.org/protobuf/internal/protolazy +github.com/opencontainers/go-digest +golang.org/x/crypto/scrypt github.com/sigstore/sigstore/pkg/signature/options -vendor/golang.org/x/crypto/cryptobyte -crypto/x509/pkix +github.com/secure-systems-lab/go-securesystemslib/encrypted +compress/zlib +google.golang.org/protobuf/proto +crypto/ecdsa +golang.org/x/crypto/openpgp/elgamal +text/template/parse +golang.org/x/crypto/chacha20 google.golang.org/protobuf/internal/encoding/defval +golang.org/x/crypto/curve25519 +golang.org/x/crypto/ssh/internal/bcrypt_pbkdf +google.golang.org/protobuf/internal/encoding/json +github.com/fsnotify/fsnotify/internal +golang.org/x/text/unicode/norm +github.com/spf13/jwalterweatherman +github.com/subosito/gotenv +github.com/hashicorp/hcl/hcl/token +github.com/fsnotify/fsnotify +gopkg.in/ini.v1 github.com/spf13/viper/internal/encoding/json -github.com/hashicorp/hcl/json/scanner -github.com/hashicorp/hcl/hcl/parser +go.mongodb.org/mongo-driver/bson/bsonrw github.com/pelletier/go-toml/v2/internal/danger +github.com/hashicorp/hcl/hcl/ast +go.uber.org/zap/internal +github.com/hashicorp/hcl/hcl/scanner +github.com/hashicorp/hcl/json/token +google.golang.org/protobuf/encoding/prototext +github.com/pelletier/go-toml/v2/unstable +google.golang.org/protobuf/internal/filedesc github.com/spf13/viper/internal/encoding/yaml +github.com/hashicorp/hcl/json/scanner golang.org/x/mod/sumdb/note +github.com/hashicorp/hcl/hcl/parser +text/template +golang.org/x/crypto/openpgp/packet +github.com/hashicorp/hcl/json/parser +github.com/hashicorp/hcl/hcl/printer github.com/go-openapi/runtime/logger github.com/opentracing/opentracing-go/log log/slog -github.com/hashicorp/hcl/json/parser go.opentelemetry.io/otel/attribute -github.com/pelletier/go-toml/v2/unstable +github.com/pelletier/go-toml/v2/internal/tracker go.opentelemetry.io/otel/codes -github.com/hashicorp/hcl/hcl/printer go.opentelemetry.io/otel/baggage +github.com/hashicorp/hcl golang.org/x/net/internal/timeseries google.golang.org/grpc/internal/grpclog +github.com/pelletier/go-toml/v2 +google.golang.org/grpc/grpclog google.golang.org/grpc/attributes google.golang.org/grpc/internal/idle -github.com/hashicorp/hcl golang.org/x/text/unicode/bidi -crypto/ecdsa -google.golang.org/grpc/grpclog +github.com/spf13/viper/internal/encoding/hcl golang.org/x/net/http2/hpack -github.com/google/trillian/types/internal/tls -github.com/tink-crypto/tink-go/subtle/random -google.golang.org/protobuf/internal/filedesc -google.golang.org/protobuf/encoding/prototext -github.com/tink-crypto/tink-go/internal/signature/ecdsa -github.com/pelletier/go-toml/v2/internal/tracker go.opentelemetry.io/otel/metric -github.com/spf13/viper/internal/encoding/hcl go.opentelemetry.io/otel/trace +golang.org/x/crypto/openpgp go.opentelemetry.io/otel/semconv/v1.17.0 +html/template google.golang.org/grpc/connectivity +github.com/go-logr/logr +github.com/google/trillian/types/internal/tls +github.com/tink-crypto/tink-go/subtle/random +github.com/tink-crypto/tink-go/internal/signature/ecdsa golang.org/x/crypto/hkdf github.com/aws/aws-sdk-go-v2/internal/rand github.com/tink-crypto/tink-go/subtle -html/template +google.golang.org/protobuf/internal/encoding/tag +google.golang.org/protobuf/encoding/protojson github.com/aws/aws-sdk-go-v2/internal/sync/singleflight +golang.org/x/text/secure/bidirule github.com/aws/smithy-go/internal/sync/singleflight -github.com/pelletier/go-toml/v2 +go.mongodb.org/mongo-driver/bson/bsoncodec +github.com/go-logr/logr/funcr +google.golang.org/protobuf/internal/impl github.com/aws/smithy-go/logging -github.com/go-logr/logr -go.mongodb.org/mongo-driver/bson/bsonrw +golang.org/x/net/idna +github.com/spf13/viper/internal/encoding/toml github.com/aws/smithy-go github.com/aws/smithy-go/time +github.com/tink-crypto/tink-go/signature/subtle github.com/aws/smithy-go/rand -go.uber.org/zap/internal -golang.org/x/text/secure/bidirule github.com/aws/smithy-go/middleware github.com/aws/aws-sdk-go-v2/aws/ratelimit -github.com/tink-crypto/tink-go/signature/subtle -golang.org/x/crypto/openpgp/packet github.com/aws/aws-sdk-go-v2/feature/ec2/imds/internal/config github.com/aws/smithy-go/auth os/user -golang.org/x/net/idna -github.com/go-logr/logr/funcr github.com/aws/aws-sdk-go-v2/aws/protocol/restjson github.com/aws/smithy-go/document +github.com/spf13/cast github.com/aws/smithy-go/encoding github.com/aws/aws-sdk-go-v2/aws/protocol/xml -github.com/aws/aws-sdk-go-v2/internal/ini +github.com/go-logr/stdr github.com/aws/smithy-go/encoding/json -github.com/aws/smithy-go/encoding/xml -golang.org/x/sync/singleflight github.com/aws/aws-sdk-go-v2/service/sso/types github.com/aws/aws-sdk-go-v2/service/ssooidc/types +github.com/aws/aws-sdk-go-v2/aws/middleware/private/metrics +github.com/aws/aws-sdk-go-v2/internal/context github.com/aws/aws-sdk-go-v2/service/sts/types +github.com/aws/smithy-go/encoding/xml +github.com/aws/aws-sdk-go-v2/internal/middleware +github.com/aws/aws-sdk-go-v2/internal/ini github.com/aws/aws-sdk-go-v2/service/kms/types -github.com/jellydator/ttlcache +golang.org/x/sync/singleflight github.com/aws/aws-sdk-go/aws/awserr github.com/jmespath/go-jmespath -github.com/go-logr/stdr github.com/googleapis/gax-go/v2/callctx -github.com/aws/aws-sdk-go-v2/aws/middleware/private/metrics -github.com/aws/aws-sdk-go-v2/internal/context golang.org/x/oauth2/jws +github.com/jellydator/ttlcache +github.com/spf13/viper/internal/encoding/dotenv +github.com/spf13/viper/internal/encoding/ini +github.com/aws/aws-sdk-go/internal/ini go.opencensus.io/internal -github.com/aws/aws-sdk-go-v2/internal/middleware go.opencensus.io/trace/tracestate +github.com/aws/aws-sdk-go/aws/endpoints go.opencensus.io/resource -github.com/aws/aws-sdk-go/internal/ini go.opencensus.io/tag -github.com/aws/aws-sdk-go/aws/endpoints -github.com/pkg/errors -go.step.sm/crypto/internal/bcrypt_pbkdf -github.com/spf13/cast -go.step.sm/crypto/fingerprint -go.opencensus.io/metric/metricdata -go.opencensus.io/trace -go.step.sm/crypto/x25519 -go.opencensus.io/metric/metricproducer -google.golang.org/protobuf/internal/encoding/tag -google.golang.org/protobuf/encoding/protojson -go.step.sm/crypto/internal/utils -github.com/spf13/viper/internal/encoding/toml -go.step.sm/crypto/randutil -sigs.k8s.io/yaml/goyaml.v2 -go.opencensus.io/stats/internal -github.com/secure-systems-lab/go-securesystemslib/cjson -testing -go.opencensus.io/stats -github.com/fxamacker/cbor -google.golang.org/protobuf/internal/impl -github.com/aws/aws-sdk-go/aws/awsutil -golang.org/x/crypto/openpgp -archive/zip -golang.org/x/crypto/ssh/terminal -github.com/spf13/viper/internal/encoding/dotenv -github.com/spf13/viper/internal/encoding/ini -go.opencensus.io/stats/view -github.com/howeyc/gopass -github.com/sassoftware/relic/lib/binpatch -github.com/transparency-dev/merkle/compact -go.mongodb.org/mongo-driver/bson/bsoncodec -github.com/transparency-dev/merkle/rfc6962 -github.com/common-nighthawk/go-figure -github.com/transparency-dev/merkle/proof crypto/x509 net/textproto vendor/golang.org/x/net/http/httpproxy @@ -3297,307 +3307,333 @@ github.com/mitchellh/mapstructure github.com/mailru/easyjson/buffer github.com/google/go-containerregistry/pkg/name -github.com/spf13/pflag -github.com/mailru/easyjson/jwriter -google.golang.org/grpc/internal -google.golang.org/grpc/internal/syscall -github.com/sigstore/sigstore/pkg/signature/payload -google.golang.org/grpc/internal/resolver/dns/internal -github.com/aws/aws-sdk-go-v2/internal/shareddefaults -github.com/aws/aws-sdk-go/internal/shareddefaults -archive/tar vendor/golang.org/x/net/http/httpguts mime/multipart net/mail -github.com/godbus/dbus -golang.org/x/net/http/httpguts +github.com/mailru/easyjson/jwriter +github.com/spf13/pflag +google.golang.org/grpc/internal google.golang.org/grpc/metadata google.golang.org/grpc/codes -github.com/aws/aws-sdk-go/aws/credentials -golang.org/x/crypto/openpgp/clearsign -sigs.k8s.io/yaml -google.golang.org/grpc/internal/balancerload +github.com/sigstore/sigstore/pkg/signature/payload +golang.org/x/net/http/httpguts +google.golang.org/grpc/internal/syscall google.golang.org/grpc/internal/grpcutil +google.golang.org/grpc/internal/balancerload google.golang.org/grpc/stats google.golang.org/grpc/tap -github.com/aws/aws-sdk-go/aws/credentials/processcreds +google.golang.org/grpc/internal/resolver/dns/internal +github.com/aws/aws-sdk-go/aws/awsutil google.golang.org/grpc/encoding -github.com/veraison/go-cose +go.opencensus.io/trace +go.opencensus.io/metric/metricdata +go.opencensus.io/stats/internal +github.com/pkg/errors +go.step.sm/crypto/internal/bcrypt_pbkdf +go.step.sm/crypto/fingerprint +go.step.sm/crypto/x25519 +go.opencensus.io/stats +go.opencensus.io/metric/metricproducer +sigs.k8s.io/yaml/goyaml.v2 +go.step.sm/crypto/internal/utils +go.step.sm/crypto/randutil +go.opencensus.io/stats/view go.mongodb.org/mongo-driver/bson -github.com/spf13/cobra +github.com/secure-systems-lab/go-securesystemslib/cjson +testing +github.com/fxamacker/cbor +golang.org/x/crypto/openpgp/clearsign +archive/zip +github.com/asaskevich/govalidator github.com/sigstore/sigstore/pkg/cryptoutils crypto/tls -github.com/secure-systems-lab/go-securesystemslib/signerverifier -github.com/asaskevich/govalidator golang.org/x/crypto/ssh +github.com/spf13/cobra +golang.org/x/crypto/ssh/terminal +github.com/howeyc/gopass +software.sslmate.com/src/go-pkcs12/internal/rc2 software.sslmate.com/src/go-pkcs12 -github.com/sassoftware/relic/lib/zipslicer -github.com/zalando/go-keyring/secret_service -sigs.k8s.io/release-utils/version -github.com/zalando/go-keyring -github.com/sassoftware/relic/lib/passprompt +github.com/sassoftware/relic/lib/binpatch +github.com/transparency-dev/merkle/compact +github.com/transparency-dev/merkle/rfc6962 +github.com/common-nighthawk/go-figure +github.com/transparency-dev/merkle/proof +github.com/secure-systems-lab/go-securesystemslib/signerverifier +sigs.k8s.io/yaml google.golang.org/protobuf/internal/filetype +github.com/veraison/go-cose +sigs.k8s.io/release-utils/version google.golang.org/protobuf/runtime/protoimpl -google.golang.org/protobuf/protoadapt -github.com/tink-crypto/tink-go/proto/ed25519_go_proto -github.com/tink-crypto/tink-go/proto/common_go_proto -google.golang.org/genproto/googleapis/rpc/code google.golang.org/protobuf/types/descriptorpb google.golang.org/protobuf/types/known/anypb +google.golang.org/protobuf/protoadapt +google.golang.org/protobuf/types/known/durationpb google.golang.org/protobuf/types/known/timestamppb google.golang.org/protobuf/types/known/fieldmaskpb -google.golang.org/protobuf/types/known/durationpb github.com/tink-crypto/tink-go/proto/tink_go_proto -github.com/secure-systems-lab/go-securesystemslib/dsse -go.step.sm/crypto/keyutil google.golang.org/grpc/encoding/proto -google.golang.org/grpc/internal/pretty github.com/golang/protobuf/ptypes/duration -google.golang.org/genproto/googleapis/rpc/errdetails -google.golang.org/genproto/googleapis/rpc/status -github.com/in-toto/in-toto-golang/in_toto -github.com/googleapis/gax-go/v2/apierror/internal/proto github.com/golang/protobuf/ptypes/timestamp -github.com/tink-crypto/tink-go/core/cryptofmt -github.com/tink-crypto/tink-go/core/registry -github.com/tink-crypto/tink-go/proto/ecdsa_go_proto -go.step.sm/crypto/pemutil +google.golang.org/genproto/googleapis/rpc/status +google.golang.org/grpc/internal/pretty +github.com/tink-crypto/tink-go/proto/common_go_proto +github.com/tink-crypto/tink-go/proto/ed25519_go_proto +google.golang.org/genproto/googleapis/rpc/code +google.golang.org/genproto/googleapis/rpc/errdetails google.golang.org/grpc/binarylog/grpc_binarylog_v1 +github.com/tink-crypto/tink-go/core/registry google.golang.org/grpc/internal/status +github.com/tink-crypto/tink-go/core/cryptofmt +github.com/tink-crypto/tink-go/proto/ecdsa_go_proto +go.step.sm/crypto/keyutil github.com/tink-crypto/tink-go/internal/primitiveset -github.com/tink-crypto/tink-go/internal/registryconfig -github.com/tink-crypto/tink-go/internal/protoserialization google.golang.org/grpc/status -github.com/tink-crypto/tink-go/keyset +github.com/googleapis/gax-go/v2/apierror/internal/proto +github.com/tink-crypto/tink-go/internal/protoserialization +github.com/tink-crypto/tink-go/internal/registryconfig +github.com/secure-systems-lab/go-securesystemslib/dsse +go.step.sm/crypto/pemutil google.golang.org/grpc/internal/binarylog +github.com/in-toto/in-toto-golang/in_toto +github.com/tink-crypto/tink-go/keyset +google.golang.org/genproto/googleapis/api/annotations +github.com/tink-crypto/tink-go/insecurecleartextkeyset +github.com/sigstore/protobuf-specs/gen/pb-go/common/v1 +github.com/sigstore/rekor/pkg/signer/tink +github.com/aws/aws-sdk-go/internal/shareddefaults +archive/tar +github.com/godbus/dbus +github.com/aws/aws-sdk-go-v2/internal/shareddefaults +github.com/aws/aws-sdk-go/aws/credentials +github.com/sigstore/protobuf-specs/gen/pb-go/rekor/v1 +github.com/sigstore/sigstore/pkg/signature +github.com/aws/aws-sdk-go/aws/credentials/processcreds net/http/httptrace google.golang.org/grpc/internal/credentials github.com/sassoftware/relic/lib/x509tools -google.golang.org/genproto/googleapis/api/annotations google.golang.org/api/transport/cert -github.com/tink-crypto/tink-go/insecurecleartextkeyset net/http google.golang.org/grpc/credentials -github.com/sigstore/rekor/pkg/signer/tink -github.com/sigstore/protobuf-specs/gen/pb-go/common/v1 +google.golang.org/grpc/internal/channelz +google.golang.org/grpc/credentials/insecure google.golang.org/grpc/resolver google.golang.org/grpc/peer -google.golang.org/grpc/credentials/insecure -google.golang.org/grpc/internal/channelz github.com/sassoftware/relic/lib/pkcs7 +github.com/sigstore/rekor/pkg/pki/x509 +github.com/sigstore/sigstore/pkg/signature/dsse +github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/encoding +github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/internal/signerverifier +github.com/sigstore/rekor/pkg/pki/minisign google.golang.org/grpc/internal/metadata google.golang.org/grpc/internal/resolver/passthrough google.golang.org/grpc/internal/transport/networktype -github.com/sigstore/protobuf-specs/gen/pb-go/rekor/v1 google.golang.org/grpc/balancer/grpclb/state -github.com/sigstore/sigstore/pkg/signature +github.com/sigstore/sigstore/pkg/signature/kms/cliplugin google.golang.org/grpc/internal/resolver/unix google.golang.org/grpc/internal/resolver/dns -google.golang.org/grpc/resolver/dns google.golang.org/grpc/channelz +github.com/sigstore/rekor/pkg/pki/pkcs7 google.golang.org/grpc/balancer +github.com/sassoftware/relic/lib/zipslicer +github.com/sigstore/sigstore/pkg/signature/kms +google.golang.org/grpc/resolver/dns google.golang.org/grpc/balancer/base google.golang.org/grpc/internal/serviceconfig google.golang.org/grpc/internal/resolver google.golang.org/grpc/balancer/roundrobin google.golang.org/grpc/internal/balancer/gracefulswitch -github.com/sigstore/rekor/pkg/pki/minisign -github.com/sigstore/rekor/pkg/pki/pkcs7 -github.com/sigstore/rekor/pkg/pki/x509 -github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/encoding -github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/internal/signerverifier -github.com/sigstore/sigstore/pkg/signature/dsse -github.com/sigstore/sigstore/pkg/signature/kms/cliplugin -github.com/sigstore/sigstore/pkg/signature/kms +github.com/zalando/go-keyring/secret_service +github.com/zalando/go-keyring +github.com/sassoftware/relic/lib/passprompt expvar github.com/go-openapi/errors net/http/pprof github.com/sigstore/rekor/pkg/pki/pgp github.com/go-openapi/swag +go.uber.org/zap github.com/sigstore/rekor/pkg/pki/ssh +github.com/magiconair/properties github.com/sigstore/rekor/pkg/util github.com/go-openapi/runtime/middleware/denco -go.opentelemetry.io/otel/semconv/internal/v2 -go.uber.org/zap -go.opentelemetry.io/otel/propagation github.com/go-chi/chi +github.com/spf13/afero github.com/go-openapi/runtime/middleware/header +github.com/sigstore/rekor/pkg/pki +github.com/sigstore/rekor/cmd/rekor-cli/app/state github.com/opentracing/opentracing-go -github.com/spf13/afero -github.com/magiconair/properties +go.opentelemetry.io/otel/propagation +github.com/go-openapi/strfmt +go.opentelemetry.io/otel/semconv/internal/v2 net/http/httputil +github.com/spf13/viper/internal/encoding/javaproperties github.com/hashicorp/go-cleanhttp -github.com/opentracing/opentracing-go/ext -github.com/sigstore/rekor/pkg/pki -go.opentelemetry.io/otel/internal/global -github.com/go-openapi/strfmt golang.org/x/net/trace -github.com/sigstore/rekor/cmd/rekor-cli/app/state +go.opentelemetry.io/otel/internal/global golang.org/x/net/http2 -go.opentelemetry.io/otel/semconv/v1.17.0/httpconv +github.com/opentracing/opentracing-go/ext +github.com/go-chi/chi/middleware github.com/hashicorp/go-retryablehttp +go.opentelemetry.io/otel/semconv/v1.17.0/httpconv github.com/aws/smithy-go/encoding/httpbinding github.com/aws/smithy-go/endpoints +github.com/aws/smithy-go/transport/http github.com/aws/aws-sdk-go/aws +github.com/go-openapi/jsonpointer google.golang.org/api/googleapi golang.org/x/oauth2/internal +go.opentelemetry.io/otel cloud.google.com/go/compute/metadata -github.com/aws/smithy-go/transport/http -golang.org/x/oauth2 -github.com/go-chi/chi/middleware -github.com/googleapis/gax-go/v2/apierror -github.com/spf13/viper/internal/encoding/javaproperties go.opencensus.io/trace/propagation -golang.org/x/oauth2/authhandler -golang.org/x/oauth2/google/internal/impersonate -golang.org/x/oauth2/google/internal/stsexchange -golang.org/x/oauth2/jwt -google.golang.org/api/internal/impersonate +github.com/go-openapi/jsonreference +github.com/googleapis/gax-go/v2/apierror +github.com/spf13/viper +golang.org/x/oauth2 go.opencensus.io/plugin/ochttp/propagation/b3 -go.opentelemetry.io/otel +google.golang.org/api/googleapi/transport +github.com/sigstore/rekor/pkg/log google.golang.org/api/transport/http/internal/propagation -github.com/sassoftware/relic/lib/pkcs9 -github.com/go-openapi/jsonpointer -github.com/aws/aws-sdk-go/aws/auth/bearer +github.com/go-openapi/spec github.com/aws/aws-sdk-go/aws/request +github.com/aws/aws-sdk-go/aws/auth/bearer +go.opencensus.io/plugin/ochttp github.com/aws/smithy-go/auth/bearer -github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn github.com/aws/aws-sdk-go-v2/internal/auth -github.com/spf13/viper +github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn github.com/aws/aws-sdk-go-v2/aws/protocol/query +github.com/go-openapi/runtime github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding github.com/aws/smithy-go/private/requestcompression -google.golang.org/api/googleapi/transport -go.opencensus.io/plugin/ochttp -github.com/sassoftware/relic/lib/certloader github.com/aws/aws-sdk-go-v2/aws -golang.org/x/oauth2/google/externalaccount -golang.org/x/oauth2/google/internal/externalaccountauthorizeduser -github.com/sigstore/rekor/pkg/log -github.com/go-openapi/jsonreference -github.com/go-openapi/runtime -github.com/go-openapi/spec -github.com/sassoftware/relic/config -github.com/sassoftware/relic/lib/signjar -golang.org/x/oauth2/google +github.com/sassoftware/relic/lib/pkcs9 +golang.org/x/oauth2/authhandler +golang.org/x/oauth2/google/internal/impersonate +golang.org/x/oauth2/google/internal/stsexchange +golang.org/x/oauth2/jwt +google.golang.org/api/internal/impersonate +github.com/sassoftware/relic/lib/certloader github.com/aws/aws-sdk-go/aws/client -github.com/aws/aws-sdk-go/aws/corehandlers github.com/aws/aws-sdk-go/private/protocol github.com/aws/aws-sdk-go/aws/csm -github.com/aws/aws-sdk-go-v2/credentials +golang.org/x/oauth2/google/externalaccount +golang.org/x/oauth2/google/internal/externalaccountauthorizeduser +github.com/aws/aws-sdk-go/aws/corehandlers github.com/aws/aws-sdk-go-v2/aws/middleware -github.com/aws/aws-sdk-go-v2/aws/defaults +github.com/go-openapi/runtime/security +github.com/go-openapi/runtime/yamlpc +github.com/aws/aws-sdk-go-v2/credentials github.com/aws/aws-sdk-go-v2/credentials/processcreds +github.com/aws/aws-sdk-go-v2/aws/defaults github.com/aws/aws-sdk-go-v2/aws/signer/internal/v4 github.com/aws/aws-sdk-go-v2/internal/configsources +github.com/aws/aws-sdk-go-v2/aws/transport/http github.com/aws/aws-sdk-go-v2/internal/endpoints +github.com/aws/aws-sdk-go-v2/aws/retry github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 -github.com/go-openapi/runtime/security -github.com/go-openapi/runtime/yamlpc -github.com/aws/aws-sdk-go/aws/ec2metadata -github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints -github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints -github.com/aws/aws-sdk-go-v2/service/kms/internal/endpoints -github.com/aws/aws-sdk-go-v2/service/ssooidc/internal/endpoints github.com/aws/aws-sdk-go/private/protocol/rest -github.com/aws/aws-sdk-go/private/protocol/query/queryutil github.com/aws/aws-sdk-go/private/protocol/json/jsonutil +github.com/aws/aws-sdk-go/private/protocol/query/queryutil github.com/aws/aws-sdk-go/private/protocol/xml/xmlutil -github.com/aws/aws-sdk-go-v2/aws/transport/http -github.com/aws/aws-sdk-go-v2/aws/retry +github.com/aws/aws-sdk-go/aws/ec2metadata +github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints github.com/aws/aws-sdk-go-v2/aws/signer/v4 -github.com/aws/aws-sdk-go/aws/credentials/ec2rolecreds -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url -github.com/aws/aws-sdk-go-v2/internal/auth/smithy +github.com/aws/aws-sdk-go-v2/service/ssooidc/internal/endpoints +github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints +github.com/aws/aws-sdk-go-v2/service/kms/internal/endpoints +golang.org/x/oauth2/google +github.com/go-openapi/analysis/internal/flatten/normalize +github.com/go-openapi/analysis/internal/flatten/operations +github.com/go-openapi/analysis/internal/flatten/replace +github.com/go-openapi/analysis/internal/flatten/schutils +github.com/sassoftware/relic/config github.com/aws/aws-sdk-go/aws/credentials/endpointcreds -github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client github.com/aws/aws-sdk-go-v2/feature/ec2/imds +github.com/go-openapi/analysis/internal/flatten/sortref +github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client +github.com/aws/aws-sdk-go/aws/signer/v4 +github.com/aws/aws-sdk-go/private/protocol/jsonrpc github.com/aws/aws-sdk-go/private/protocol/query +github.com/aws/aws-sdk-go-v2/internal/auth/smithy +github.com/aws/aws-sdk-go/aws/credentials/ec2rolecreds +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url +github.com/sassoftware/relic/lib/signjar github.com/aws/aws-sdk-go-v2/service/sso +github.com/aws/aws-sdk-go-v2/credentials/endpointcreds github.com/aws/aws-sdk-go-v2/service/ssooidc -github.com/aws/aws-sdk-go/private/protocol/jsonrpc -github.com/aws/aws-sdk-go/aws/signer/v4 +github.com/aws/aws-sdk-go/private/protocol/restjson +github.com/aws/aws-sdk-go/aws/defaults github.com/aws/aws-sdk-go-v2/service/kms +github.com/go-openapi/analysis github.com/aws/aws-sdk-go-v2/service/sts -github.com/aws/aws-sdk-go/aws/defaults -github.com/aws/aws-sdk-go/private/protocol/restjson -github.com/go-openapi/analysis/internal/flatten/operations -github.com/go-openapi/analysis/internal/flatten/replace -github.com/go-openapi/analysis/internal/flatten/schutils -github.com/go-openapi/analysis/internal/flatten/normalize -github.com/aws/aws-sdk-go-v2/credentials/endpointcreds -github.com/aws/aws-sdk-go/service/kms github.com/aws/aws-sdk-go/service/sts -github.com/aws/aws-sdk-go/service/ssooidc +github.com/aws/aws-sdk-go/service/kms github.com/aws/aws-sdk-go/service/sso -github.com/go-openapi/analysis/internal/flatten/sortref -github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds +github.com/aws/aws-sdk-go/service/ssooidc google.golang.org/grpc/internal/transport -github.com/go-openapi/analysis +github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds github.com/aws/aws-sdk-go/service/sso/ssoiface github.com/aws/aws-sdk-go/service/sts/stsiface github.com/aws/aws-sdk-go/aws/credentials/ssocreds github.com/aws/aws-sdk-go/aws/credentials/stscreds -github.com/aws/aws-sdk-go-v2/credentials/ssocreds -github.com/aws/aws-sdk-go/aws/session github.com/go-openapi/loads +github.com/aws/aws-sdk-go/aws/session github.com/go-openapi/runtime/middleware/untyped github.com/go-openapi/validate +github.com/aws/aws-sdk-go-v2/credentials/ssocreds github.com/aws/aws-sdk-go-v2/credentials/stscreds google.golang.org/grpc github.com/aws/aws-sdk-go-v2/config github.com/aws/aws-sdk-go/service/kms/kmsiface -github.com/tink-crypto/tink-go-awskms/integration/awskms github.com/go-openapi/runtime/middleware github.com/sigstore/rekor/pkg/generated/models -github.com/google/trillian +github.com/tink-crypto/tink-go-awskms/integration/awskms +github.com/go-openapi/runtime/client github.com/googleapis/gax-go/v2 +github.com/google/trillian google.golang.org/api/internal -github.com/go-openapi/runtime/client -google.golang.org/api/option -google.golang.org/api/transport/internal/dca -google.golang.org/api/internal/gensupport -google.golang.org/api/transport/http -google.golang.org/api/option/internaloption +github.com/sigstore/rekor/pkg/types github.com/sigstore/rekor/pkg/generated/client/index +github.com/sigstore/rekor/pkg/generated/client/tlog github.com/sigstore/rekor/pkg/generated/client/pubkey github.com/sigstore/rekor/pkg/generated/client/entries -github.com/sigstore/rekor/pkg/types -github.com/sigstore/rekor/pkg/generated/client/tlog -github.com/google/trillian/types -google.golang.org/api/cloudkms/v1 +google.golang.org/api/transport/internal/dca +google.golang.org/api/option +google.golang.org/api/internal/gensupport +google.golang.org/api/option/internaloption +google.golang.org/api/transport/http github.com/sigstore/rekor/pkg/generated/client github.com/sigstore/rekor/pkg/tle github.com/sigstore/rekor/pkg/types/cose github.com/sigstore/rekor/pkg/types/alpine +github.com/sigstore/rekor/pkg/types/dsse github.com/sigstore/rekor/pkg/types/hashedrekord +github.com/sigstore/rekor/pkg/types/helm github.com/sigstore/rekor/pkg/types/intoto -github.com/sigstore/rekor/pkg/types/dsse +github.com/sigstore/rekor/pkg/client +github.com/sigstore/rekor/cmd/rekor-cli/app/format github.com/sigstore/rekor/pkg/types/jar -github.com/sigstore/rekor/pkg/types/helm +github.com/google/trillian/types +google.golang.org/api/cloudkms/v1 github.com/sigstore/rekor/pkg/types/rekord -github.com/sigstore/rekor/pkg/types/rfc3161 -github.com/sigstore/rekor/pkg/client github.com/sigstore/rekor/pkg/verify -github.com/sigstore/rekor/cmd/rekor-cli/app/format -github.com/sigstore/rekor/pkg/types/jar/v0.0.1 -github.com/sigstore/rekor/pkg/types/hashedrekord/v0.0.1 +github.com/sigstore/rekor/pkg/types/rfc3161 +github.com/sigstore/rekor/pkg/types/cose/v0.0.1 github.com/sigstore/rekor/pkg/types/dsse/v0.0.1 +github.com/sigstore/rekor/pkg/types/rekord/v0.0.1 github.com/sigstore/rekor/pkg/types/helm/v0.0.1 +github.com/sigstore/rekor/pkg/types/hashedrekord/v0.0.1 +github.com/sigstore/rekor/pkg/types/alpine/v0.0.1 +github.com/sigstore/rekor/pkg/types/jar/v0.0.1 github.com/sigstore/rekor/pkg/types/intoto/v0.0.2 github.com/sigstore/rekor/pkg/types/intoto/v0.0.1 github.com/sigstore/rekor/pkg/types/rfc3161/v0.0.1 -github.com/sigstore/rekor/pkg/types/rekord/v0.0.1 -github.com/sigstore/rekor/pkg/types/cose/v0.0.1 -github.com/sigstore/rekor/pkg/types/alpine/v0.0.1 -github.com/tink-crypto/tink-go-gcpkms/integration/gcpkms github.com/sigstore/sigstore/pkg/signature/kms/aws +github.com/tink-crypto/tink-go-gcpkms/integration/gcpkms github.com/sigstore/rekor/pkg/signer github.com/sigstore/rekor/pkg/sharding github.com/sigstore/rekor/cmd/rekor-cli/app github.com/sigstore/rekor/cmd/rekor-cli dh_auto_test -O--builddirectory=_build -O--buildsystem=golang - cd _build && go test -vet=off -v -p 16 github.com/sigstore/rekor/cmd/rekor-cli + cd _build && go test -vet=off -v -p 12 github.com/sigstore/rekor/cmd/rekor-cli === RUN TestCover Rekor command line interface tool @@ -3627,7 +3663,7 @@ Use "rekor-cli [command] --help" for more information about a command. --- PASS: TestCover (0.00s) PASS -ok github.com/sigstore/rekor/cmd/rekor-cli 0.020s +ok github.com/sigstore/rekor/cmd/rekor-cli 0.016s create-stamp debian/debhelper-build-stamp dh_testroot -O--builddirectory=_build -O--buildsystem=golang dh_prep -O--builddirectory=_build -O--buildsystem=golang @@ -3642,7 +3678,7 @@ mkdir -pv /build/reproducible-path/rekor-1.3.9/debian/rekor/usr/share/man/man1 mkdir: created directory '/build/reproducible-path/rekor-1.3.9/debian/rekor/usr/share/man' mkdir: created directory '/build/reproducible-path/rekor-1.3.9/debian/rekor/usr/share/man/man1' -env PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/build/reproducible-path/rekor-1.3.9/debian/tmp/usr/bin \ +env PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path:/build/reproducible-path/rekor-1.3.9/debian/tmp/usr/bin \ help2man --no-info --version-string="1.3.9-1" \ --no-discard-stderr -Idebian/rekor-cli.h2m \ rekor-cli -o /build/reproducible-path/rekor-1.3.9/debian/rekor/usr/share/man/man1/rekor-cli.1 @@ -3663,9 +3699,9 @@ dh_gencontrol -O--builddirectory=_build -O--buildsystem=golang dh_md5sums -O--builddirectory=_build -O--buildsystem=golang dh_builddeb -O--builddirectory=_build -O--buildsystem=golang -dpkg-deb: building package 'rekor-dbgsym' in '../rekor-dbgsym_1.3.9-1_amd64.deb'. dpkg-deb: building package 'rekor' in '../rekor_1.3.9-1_amd64.deb'. dpkg-deb: building package 'golang-github-sigstore-rekor-dev' in '../golang-github-sigstore-rekor-dev_1.3.9-1_all.deb'. +dpkg-deb: building package 'rekor-dbgsym' in '../rekor-dbgsym_1.3.9-1_amd64.deb'. dpkg-genbuildinfo --build=binary -O../rekor_1.3.9-1_amd64.buildinfo dpkg-genchanges --build=binary -O../rekor_1.3.9-1_amd64.changes dpkg-genchanges: info: binary-only upload (no source code included) @@ -3673,12 +3709,14 @@ dpkg-buildpackage: info: binary-only upload (no source included) dpkg-genchanges: info: including full source code in upload I: copying local configuration +I: user script /srv/workspace/pbuilder/2982458/tmp/hooks/B01_cleanup starting +I: user script /srv/workspace/pbuilder/2982458/tmp/hooks/B01_cleanup finished I: unmounting dev/ptmx filesystem I: unmounting dev/pts filesystem I: unmounting dev/shm filesystem I: unmounting proc filesystem I: unmounting sys filesystem I: cleaning the build env -I: removing directory /srv/workspace/pbuilder/2877701 and its subdirectories -I: Current time: Fri Oct 2 09:24:04 -12 2026 -I: pbuilder-time-stamp: 1790976244 +I: removing directory /srv/workspace/pbuilder/2982458 and its subdirectories +I: Current time: Sun Aug 31 05:08:34 +14 2025 +I: pbuilder-time-stamp: 1756566514