Diff of the two buildlogs:

--
--- b1/build.log	2025-03-18 02:49:38.014669162 +0000
+++ b2/build.log	2025-03-18 03:08:45.922736698 +0000
@@ -1,6 +1,6 @@
 I: pbuilder: network access will be disabled during build
-I: Current time: Sun Apr 19 21:08:54 -12 2026
-I: pbuilder-time-stamp: 1776676134
+I: Current time: Tue Mar 18 16:49:40 +14 2025
+I: pbuilder-time-stamp: 1742266180
 I: Building the build Environment
 I: extracting base tarball [/var/cache/pbuilder/unstable-reproducible-base.tgz]
 I: copying local configuration
@@ -29,52 +29,84 @@
 dpkg-source: info: applying use-xanzy-gitlab.patch
 I: Not using root during the build.
 I: Installing the build-deps
-I: user script /srv/workspace/pbuilder/3813363/tmp/hooks/D02_print_environment starting
+I: user script /srv/workspace/pbuilder/2739090/tmp/hooks/D01_modify_environment starting
+debug: Running on ionos1-amd64.
+I: Changing host+domainname to test build reproducibility
+I: Adding a custom variable just for the fun of it...
+I: Changing /bin/sh to bash
+'/bin/sh' -> '/bin/bash'
+lrwxrwxrwx 1 root root 9 Mar 18 02:49 /bin/sh -> /bin/bash
+I: Setting pbuilder2's login shell to /bin/bash
+I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other
+I: user script /srv/workspace/pbuilder/2739090/tmp/hooks/D01_modify_environment finished
+I: user script /srv/workspace/pbuilder/2739090/tmp/hooks/D02_print_environment starting
 I: set
-  BUILDDIR='/build/reproducible-path'
-  BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other'
-  BUILDUSERNAME='pbuilder1'
-  BUILD_ARCH='amd64'
-  DEBIAN_FRONTEND='noninteractive'
-  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=42 '
-  DISTRIBUTION='unstable'
-  HOME='/root'
-  HOST_ARCH='amd64'
+  BASH=/bin/sh
+  BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath
+  BASH_ALIASES=()
+  BASH_ARGC=()
+  BASH_ARGV=()
+  BASH_CMDS=()
+  BASH_LINENO=([0]="12" [1]="0")
+  BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:.
+  BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment")
+  BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="x86_64-pc-linux-gnu")
+  BASH_VERSION='5.2.37(1)-release'
+  BUILDDIR=/build/reproducible-path
+  BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other'
+  BUILDUSERNAME=pbuilder2
+  BUILD_ARCH=amd64
+  DEBIAN_FRONTEND=noninteractive
+  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=20 '
+  DIRSTACK=()
+  DISTRIBUTION=unstable
+  EUID=0
+  FUNCNAME=([0]="Echo" [1]="main")
+  GROUPS=()
+  HOME=/root
+  HOSTNAME=i-capture-the-hostname
+  HOSTTYPE=x86_64
+  HOST_ARCH=amd64
   IFS=' 	
   '
-  INVOCATION_ID='7a11bedfcf944f8fb11fbfb37896d4dc'
-  LANG='C'
-  LANGUAGE='en_US:en'
-  LC_ALL='C'
-  MAIL='/var/mail/root'
-  OPTIND='1'
-  PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games'
-  PBCURRENTCOMMANDLINEOPERATION='build'
-  PBUILDER_OPERATION='build'
-  PBUILDER_PKGDATADIR='/usr/share/pbuilder'
-  PBUILDER_PKGLIBDIR='/usr/lib/pbuilder'
-  PBUILDER_SYSCONFDIR='/etc'
-  PPID='3813363'
-  PS1='# '
-  PS2='> '
+  INVOCATION_ID=e957df17273740a396f2e3e4d9b23c2e
+  LANG=C
+  LANGUAGE=et_EE:et
+  LC_ALL=C
+  MACHTYPE=x86_64-pc-linux-gnu
+  MAIL=/var/mail/root
+  OPTERR=1
+  OPTIND=1
+  OSTYPE=linux-gnu
+  PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path
+  PBCURRENTCOMMANDLINEOPERATION=build
+  PBUILDER_OPERATION=build
+  PBUILDER_PKGDATADIR=/usr/share/pbuilder
+  PBUILDER_PKGLIBDIR=/usr/lib/pbuilder
+  PBUILDER_SYSCONFDIR=/etc
+  PIPESTATUS=([0]="0")
+  POSIXLY_CORRECT=y
+  PPID=2739090
   PS4='+ '
-  PWD='/'
-  SHELL='/bin/bash'
-  SHLVL='2'
-  SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.n1qNI2BV/pbuilderrc_k308 --distribution unstable --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.n1qNI2BV/b1 --logfile b1/build.log cosign_2.4.3-1.dsc'
-  SUDO_GID='110'
-  SUDO_UID='105'
-  SUDO_USER='jenkins'
-  TERM='unknown'
-  TZ='/usr/share/zoneinfo/Etc/GMT+12'
-  USER='root'
-  _='/usr/bin/systemd-run'
-  http_proxy='http://213.165.73.152:3128'
+  PWD=/
+  SHELL=/bin/bash
+  SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix
+  SHLVL=3
+  SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.n1qNI2BV/pbuilderrc_8RtN --distribution unstable --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.n1qNI2BV/b2 --logfile b2/build.log cosign_2.4.3-1.dsc'
+  SUDO_GID=110
+  SUDO_UID=105
+  SUDO_USER=jenkins
+  TERM=unknown
+  TZ=/usr/share/zoneinfo/Etc/GMT-14
+  UID=0
+  USER=root
+  _='I: set'
+  http_proxy=http://46.16.76.132:3128
 I: uname -a
-  Linux ionos5-amd64 6.12.12+bpo-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.12-1~bpo12+1 (2025-02-23) x86_64 GNU/Linux
+  Linux i-capture-the-hostname 6.1.0-32-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.129-1 (2025-03-06) x86_64 GNU/Linux
 I: ls -l /bin
-  lrwxrwxrwx 1 root root 7 Mar  4  2025 /bin -> usr/bin
-I: user script /srv/workspace/pbuilder/3813363/tmp/hooks/D02_print_environment finished
+  lrwxrwxrwx 1 root root 7 Mar  4 11:20 /bin -> usr/bin
+I: user script /srv/workspace/pbuilder/2739090/tmp/hooks/D02_print_environment finished
  -> Attempting to satisfy build-dependencies
  -> Creating pbuilder-satisfydepends-dummy package
 Package: pbuilder-satisfydepends-dummy
@@ -735,7 +767,7 @@
 Get: 529 http://deb.debian.org/debian unstable/main amd64 golang-github-withfig-autocomplete-tools-dev all 0.0~git20241029.747689a+ds-2 [5556 B]
 Get: 530 http://deb.debian.org/debian unstable/main amd64 golang-github-xanzy-go-gitlab-dev all 0.110.0-1 [274 kB]
 Get: 531 http://deb.debian.org/debian unstable/main amd64 help2man amd64 1.49.3 [198 kB]
-Fetched 242 MB in 10s (24.8 MB/s)
+Fetched 242 MB in 15s (16.7 MB/s)
 Preconfiguring packages ...
 Selecting previously unselected package golang-golang-x-sys-dev.
 (Reading database ... 
(Reading database ... 5%
(Reading database ... 10%
(Reading database ... 15%
(Reading database ... 20%
(Reading database ... 25%
(Reading database ... 30%
(Reading database ... 35%
(Reading database ... 40%
(Reading database ... 45%
(Reading database ... 50%
(Reading database ... 55%
(Reading database ... 60%
(Reading database ... 65%
(Reading database ... 70%
(Reading database ... 75%
(Reading database ... 80%
(Reading database ... 85%
(Reading database ... 90%
(Reading database ... 95%
(Reading database ... 100%
(Reading database ... 19784 files and directories currently installed.)
@@ -2436,8 +2468,8 @@
 Setting up tzdata (2025a-2) ...
 
 Current default time zone: 'Etc/UTC'
-Local time is now:      Mon Apr 20 09:10:58 UTC 2026.
-Universal Time is now:  Mon Apr 20 09:10:58 UTC 2026.
+Local time is now:      Tue Mar 18 02:59:05 UTC 2025.
+Universal Time is now:  Tue Mar 18 02:59:05 UTC 2025.
 Run 'dpkg-reconfigure tzdata' if you wish to change it.
 
 Setting up golang-github-coreos-go-semver-dev (0.3.0-1) ...
@@ -2880,7 +2912,11 @@
 Building tag database...
  -> Finished parsing the build-deps
 I: Building the package
-I: Running cd /build/reproducible-path/cosign-2.4.3/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S  > ../cosign_2.4.3-1_source.changes
+I: user script /srv/workspace/pbuilder/2739090/tmp/hooks/A99_set_merged_usr starting
+Not re-configuring usrmerge for unstable
+I: user script /srv/workspace/pbuilder/2739090/tmp/hooks/A99_set_merged_usr finished
+hostname: Name or service not known
+I: Running cd /build/reproducible-path/cosign-2.4.3/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S  > ../cosign_2.4.3-1_source.changes
 dpkg-buildpackage: info: source package cosign
 dpkg-buildpackage: info: source version 2.4.3-1
 dpkg-buildpackage: info: source distribution unstable
@@ -2902,82 +2938,82 @@
 rm -rf _build/src/github.com/sigstore/cosign/pkg/cosign/rego
 make[1]: Leaving directory '/build/reproducible-path/cosign-2.4.3'
    dh_auto_build -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go install -trimpath -v -p 42 github.com/sigstore/cosign/cmd/cosign
-log/internal
-github.com/docker/cli/cli/config/types
+	cd _build && go install -trimpath -v -p 20 github.com/sigstore/cosign/cmd/cosign
+internal/unsafeheader
+internal/godebugs
+internal/goos
+encoding
 internal/coverage/rtcov
-go.mongodb.org/mongo-driver/bson/bsontype
-go.mongodb.org/mongo-driver/bson/bsonoptions
-github.com/google/go-containerregistry/pkg/compression
+internal/msan
+cmp
+unicode/utf8
+math/bits
+internal/goexperiment
 internal/profilerecord
-internal/goarch
+internal/asan
 unicode
-internal/nettrace
-google.golang.org/protobuf/internal/flags
 internal/itoa
+internal/byteorder
+internal/goarch
+sync/atomic
 container/list
-github.com/google/go-cmp/cmp/internal/flags
-vendor/golang.org/x/crypto/internal/alias
+internal/cpu
+crypto/internal/fips140/alias
+crypto/internal/boring/sig
+internal/runtime/syscall
+internal/runtime/atomic
 unicode/utf16
+vendor/golang.org/x/crypto/cryptobyte/asn1
+internal/nettrace
+vendor/golang.org/x/crypto/internal/alias
+github.com/docker/cli/cli/config/types
+internal/abi
+internal/runtime/math
+internal/chacha8rand
+internal/runtime/sys
+crypto/internal/fips140deps/byteorder
+crypto/internal/fips140/subtle
+log/internal
+github.com/google/go-containerregistry/pkg/v1/types
+github.com/klauspost/compress/internal/cpuinfo
 github.com/klauspost/compress/internal/le
-github.com/sigstore/rekor/pkg/pki/identity
-internal/unsafeheader
-internal/msan
-cmp
+github.com/google/go-containerregistry/pkg/compression
+github.com/google/go-cmp/cmp/internal/flags
 golang.org/x/crypto/internal/alias
-internal/runtime/atomic
-internal/byteorder
-unicode/utf8
 github.com/aws/aws-sdk-go-v2/internal/sdkio
-vendor/golang.org/x/crypto/cryptobyte/asn1
 github.com/awslabs/amazon-ecr-credential-helper/ecr-login/version
-crypto/internal/fips140/alias
-github.com/google/go-containerregistry/pkg/v1/types
-internal/cpu
-encoding
-internal/godebugs
-github.com/klauspost/compress/internal/cpuinfo
-crypto/internal/boring/sig
-internal/goexperiment
-math/bits
-internal/asan
-internal/goos
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/common
-sync/atomic
-internal/runtime/syscall
+google.golang.org/protobuf/internal/flags
+google.golang.org/protobuf/internal/set
+go.mongodb.org/mongo-driver/bson/bsonoptions
+go.mongodb.org/mongo-driver/bson/bsontype
+github.com/sigstore/rekor/pkg/pki/identity
+golang.org/x/crypto/salsa20/salsa
 image/color
-internal/runtime/math
-log/slog/internal
-github.com/sigstore/cosign/pkg/types
-internal/abi
 golang.org/x/exp/constraints
-go.opentelemetry.io/otel/trace/embedded
 golang.org/x/crypto/cryptobyte/asn1
+log/slog/internal
+github.com/sigstore/cosign/pkg/types
 go.opentelemetry.io/otel/metric/embedded
+go.opentelemetry.io/otel/trace/embedded
+github.com/pelletier/go-toml/v2/internal/characters
 github.com/transparency-dev/merkle
 github.com/theupdateframework/go-tuf/v0/internal/sets
 k8s.io/apimachinery/pkg/selection
+internal/runtime/exithook
 k8s.io/utils/strings/slices
-google.golang.org/grpc/serviceconfig
 k8s.io/apimachinery/pkg/types
+google.golang.org/grpc/serviceconfig
+github.com/golang/groupcache/lru
+golang.org/x/exp/slices
 go.opencensus.io
 go.opencensus.io/trace/internal
-internal/runtime/sys
 go.opencensus.io/internal/tagencoding
 golang.org/x/text/encoding/internal/identifier
+internal/bytealg
+crypto/internal/fips140deps/cpu
 golang.org/x/text/internal/utf8internal
 cuelang.org/go/pkg/tool
-crypto/internal/fips140/subtle
-internal/chacha8rand
-crypto/internal/fips140deps/byteorder
-github.com/golang/groupcache/lru
-github.com/pelletier/go-toml/v2/internal/characters
-google.golang.org/protobuf/internal/set
-golang.org/x/crypto/salsa20/salsa
-golang.org/x/exp/slices
-crypto/internal/fips140deps/cpu
-internal/bytealg
-internal/runtime/exithook
 math
 internal/stringslite
 internal/race
@@ -2987,707 +3023,698 @@
 go.opentelemetry.io/otel/internal
 runtime
 internal/reflectlite
-weak
-k8s.io/klog/internal/dbg
-crypto/subtle
 sync
 iter
-maps
+crypto/subtle
+weak
+k8s.io/klog/internal/dbg
 slices
+maps
 cuelang.org/go/internal/mod/semver
-errors
-sort
-internal/singleflight
-internal/testlog
 internal/bisect
-google.golang.org/protobuf/internal/pragma
+internal/testlog
+internal/singleflight
 unique
+google.golang.org/protobuf/internal/pragma
 github.com/josharian/intern
 go.uber.org/zap/internal/pool
 log/slog/internal/buffer
-github.com/sigstore/cosign/cmd/cosign/cli/sign/privacy
 github.com/spf13/viper/internal/encoding
+github.com/sigstore/cosign/cmd/cosign/cli/sign/privacy
+errors
+sort
 runtime/cgo
+internal/godebug
 internal/oserror
 io
+strconv
 path
-math/rand/v2
 vendor/golang.org/x/net/dns/dnsmessage
-github.com/sassoftware/relic/signers/sigerrors
+math/rand/v2
+container/heap
 github.com/hashicorp/hcl/hcl/strconv
+github.com/gogo/protobuf/sortkeys
 google.golang.org/grpc/internal/buffer
+k8s.io/apimachinery/pkg/util/sets
+github.com/sassoftware/relic/signers/sigerrors
 golang.org/x/crypto/cast5
-strconv
-internal/godebug
-hash
-crypto/internal/randutil
-github.com/google/go-containerregistry/internal/and
+golang.org/x/mod/semver
 bytes
 strings
 syscall
-hash/fnv
-github.com/aws/smithy-go/transport/http/internal/io
-hash/crc32
-internal/saferio
-hash/adler32
-github.com/gogo/protobuf/sortkeys
-container/heap
-golang.org/x/mod/semver
-k8s.io/apimachinery/pkg/util/sets
+hash
 crypto/internal/fips140deps/godebug
+crypto/internal/randutil
 math/rand
-crypto
+github.com/google/go-containerregistry/internal/and
+github.com/aws/smithy-go/transport/http/internal/io
+internal/saferio
 golang.org/x/crypto/openpgp/errors
 golang.org/x/crypto/blowfish
-encoding/base32
-net/netip
 github.com/x448/float16
+encoding/base32
 reflect
+net/netip
+hash/crc32
+crypto
+hash/adler32
+hash/fnv
 golang.org/x/crypto/openpgp/s2k
-vendor/golang.org/x/text/transform
-github.com/aws/smithy-go/io
-github.com/mitchellh/go-wordwrap
-golang.org/x/text/transform
-github.com/syndtr/goleveldb/leveldb/comparer
-crypto/internal/impl
-bufio
+google.golang.org/grpc/internal/grpcrand
 crypto/internal/fips140
-net/http/internal/ascii
-github.com/aws/aws-sdk-go-v2/internal/strings
-github.com/theupdateframework/go-tuf/v0/internal/roles
-k8s.io/klog/internal/severity
+crypto/internal/impl
 regexp/syntax
-go/build/constraint
+net/http/internal/ascii
 net/http/internal/testcert
+github.com/aws/aws-sdk-go-v2/internal/strings
 html
+k8s.io/klog/internal/severity
+github.com/theupdateframework/go-tuf/v0/internal/roles
 github.com/munnerz/goautoneg
-google.golang.org/grpc/internal/grpcrand
-crypto/tls/internal/fips140tls
+go/build/constraint
+vendor/golang.org/x/text/transform
+github.com/aws/smithy-go/io
+golang.org/x/text/transform
+github.com/mitchellh/go-wordwrap
+github.com/syndtr/goleveldb/leveldb/comparer
+bufio
 crypto/internal/fips140/sha3
+crypto/tls/internal/fips140tls
 crypto/internal/fips140/sha256
 crypto/internal/fips140/sha512
-golang.org/x/text/encoding
 golang.org/x/text/runes
-golang.org/x/text/encoding/internal
-compress/bzip2
-image
-golang.org/x/text/encoding/unicode
+golang.org/x/text/encoding
 crypto/sha3
 crypto/internal/fips140/hmac
-crypto/internal/fips140/check
+compress/bzip2
+image
+golang.org/x/text/encoding/internal
 crypto/internal/fips140hash
+crypto/internal/fips140/check
+golang.org/x/text/encoding/unicode
 crypto/internal/fips140/edwards25519/field
 crypto/internal/fips140/bigmod
-crypto/internal/fips140/tls12
 crypto/internal/fips140/hkdf
 crypto/internal/fips140/aes
+crypto/internal/fips140/tls12
 crypto/internal/fips140/nistec/fiat
 crypto/internal/fips140/tls13
-internal/syscall/execenv
-internal/syscall/unix
+crypto/internal/fips140/edwards25519
 time
+internal/syscall/unix
+internal/syscall/execenv
 regexp
-crypto/internal/fips140/edwards25519
 image/internal/imageutil
 image/jpeg
+internal/fmtsort
+encoding/binary
+go.opentelemetry.io/otel/internal/attribute
+github.com/modern-go/reflect2
+sigs.k8s.io/structured-merge-diff/schema
+github.com/google/go-cmp/cmp/internal/function
 k8s.io/apimachinery/pkg/version
-crypto/internal/fips140/nistec
-github.com/google/go-containerregistry/internal/retry/wait
-github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.2
-github.com/aws/aws-sdk-go-v2/internal/timeconv
 context
+github.com/google/go-containerregistry/internal/retry/wait
 github.com/google/go-cmp/cmp/internal/diff
-io/fs
 github.com/aws/smithy-go/ptr
+io/fs
+internal/poll
+github.com/aws/aws-sdk-go-v2/internal/timeconv
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.1
-k8s.io/utils/clock
-google.golang.org/grpc/backoff
+github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.2
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v1
 go.uber.org/zap/buffer
 k8s.io/klog/internal/clock
+k8s.io/utils/clock
+google.golang.org/grpc/backoff
 google.golang.org/grpc/keepalive
-internal/poll
-k8s.io/utils/clock/testing
 go.uber.org/zap/internal/bufferpool
-go.uber.org/zap/internal/stacktrace
+k8s.io/utils/clock/testing
 github.com/aws/aws-sdk-go-v2/internal/sdk
 github.com/aws/smithy-go/context
-google.golang.org/grpc/internal/backoff
 go.opentelemetry.io/otel/internal/baggage
 google.golang.org/grpc/internal/grpcsync
+google.golang.org/grpc/internal/backoff
+go.uber.org/zap/internal/stacktrace
+crypto/internal/fips140/nistec
 internal/filepathlite
-github.com/spf13/afero/internal/common
 embed
+github.com/spf13/afero/internal/common
 google.golang.org/protobuf/internal/editiondefaults
-os
-github.com/google/go-cmp/cmp/internal/function
-go.opentelemetry.io/otel/internal/attribute
-internal/fmtsort
-encoding/binary
-github.com/modern-go/reflect2
-sigs.k8s.io/structured-merge-diff/schema
 vendor/golang.org/x/crypto/internal/poly1305
-github.com/google/gofuzz/bytesource
 encoding/base64
 golang.org/x/crypto/internal/poly1305
-github.com/cespare/xxhash
-github.com/golang/snappy
 github.com/klauspost/compress/internal/snapref
+github.com/golang/snappy
+github.com/google/gofuzz/bytesource
+github.com/cespare/xxhash
 golang.org/x/sys/unix
+os
 golang.org/x/crypto/nacl/secretbox
-golang.org/x/crypto/openpgp/armor
 encoding/pem
-google.golang.org/protobuf/internal/detrand
+golang.org/x/crypto/openpgp/armor
+fmt
+crypto/internal/sysrand
+vendor/golang.org/x/sys/cpu
+path/filepath
 internal/sysinfo
 go.uber.org/zap/internal/exit
-io/ioutil
 k8s.io/klog/internal/buffer
-internal/lazyregexp
-path/filepath
-fmt
-google.golang.org/grpc/internal/envconfig
 golang.org/x/sys/cpu
+io/ioutil
+google.golang.org/protobuf/internal/detrand
+internal/lazyregexp
 golang.org/x/mod/internal/lazyregexp
-crypto/internal/sysrand
 cuelang.org/go/internal/golangorgx/tools/robustio
 github.com/rogpeppe/go-internal/lockedfile/internal/filelock
-github.com/rogpeppe/go-internal/robustio
-vendor/golang.org/x/sys/cpu
 net
+github.com/rogpeppe/go-internal/robustio
+google.golang.org/grpc/internal/envconfig
 crypto/internal/entropy
 crypto/internal/fips140/drbg
-golang.org/x/crypto/blake2b
-golang.org/x/crypto/sha3
-github.com/shibumi/go-pathspec
-github.com/spf13/afero/mem
-os/exec
-k8s.io/client-go/util/homedir
 crypto/internal/fips140only
+crypto/internal/fips140/aes/gcm
 crypto/internal/fips140/ecdh
-crypto/internal/fips140/ed25519
 crypto/internal/fips140/ecdsa
-crypto/internal/fips140/aes/gcm
+crypto/internal/fips140/ed25519
 crypto/internal/fips140/mlkem
 crypto/internal/fips140/rsa
+golang.org/x/crypto/blake2b
+golang.org/x/crypto/sha3
 crypto/rc4
 crypto/md5
+github.com/shibumi/go-pathspec
+github.com/spf13/afero/mem
+os/exec
+k8s.io/client-go/util/homedir
 crypto/cipher
-github.com/mitchellh/go-homedir
-github.com/skratchdot/open-golang/open
-crypto/internal/boring
-crypto/des
-vendor/golang.org/x/crypto/chacha20
-golang.org/x/crypto/chacha20
 flag
+compress/flate
 encoding/hex
-golang.org/x/sys/execabs
-log
-encoding/json
-github.com/pkg/errors
-github.com/google/go-containerregistry/internal/editor
 net/url
-github.com/containerd/stargz-snapshotter/estargz/errorutil
+github.com/pkg/errors
+encoding/json
+log
 os/user
+github.com/containerd/stargz-snapshotter/estargz/errorutil
+math/big
+github.com/opencontainers/go-digest
 runtime/debug
 github.com/klauspost/compress/fse
 golang.org/x/sync/errgroup
-math/big
-github.com/opencontainers/go-digest
-github.com/google/go-containerregistry/internal/retry
 runtime/trace
 github.com/opencontainers/image-spec/specs-go
-compress/flate
-net/http/internal
+github.com/google/go-containerregistry/internal/retry
 vendor/golang.org/x/net/http2/hpack
+vendor/golang.org/x/text/unicode/norm
 mime
 mime/quotedprintable
-github.com/google/go-cmp/cmp/internal/value
-text/template/parse
+net/http/internal
+crypto/internal/boring
+crypto/des
+vendor/golang.org/x/crypto/chacha20
+github.com/opencontainers/image-spec/specs-go/v1
 encoding/csv
-github.com/aws/aws-sdk-go-v2/feature/ec2/imds/internal/config
-vendor/golang.org/x/text/unicode/norm
+golang.org/x/sys/execabs
+github.com/google/go-containerregistry/internal/editor
+crypto/aes
+crypto/ecdh
+crypto/sha512
+crypto/hmac
+crypto/sha1
+crypto/sha256
+github.com/google/go-containerregistry/pkg/logs
+github.com/mitchellh/go-homedir
+testing
+vendor/golang.org/x/text/unicode/bidi
+text/template/parse
+github.com/google/go-containerregistry/internal/redact
+github.com/google/go-cmp/cmp/internal/value
+golang.org/x/crypto/chacha20
+golang.org/x/crypto/ssh/internal/bcrypt_pbkdf
+github.com/aws/aws-sdk-go-v2/internal/sync/singleflight
+vendor/golang.org/x/crypto/chacha20poly1305
+github.com/aws/smithy-go/internal/sync/singleflight
+github.com/aws/smithy-go/logging
+golang.org/x/crypto/curve25519
+github.com/klauspost/compress/huff0
+github.com/aws/smithy-go/middleware
+github.com/aws/smithy-go
 github.com/aws/aws-sdk-go-v2/aws/ratelimit
+github.com/aws/aws-sdk-go-v2/feature/ec2/imds/internal/config
 github.com/aws/smithy-go/encoding
-github.com/aws/smithy-go
-google.golang.org/protobuf/internal/errors
-github.com/aws/aws-sdk-go-v2/internal/ini
-google.golang.org/protobuf/internal/version
 encoding/xml
+compress/gzip
+github.com/aws/aws-sdk-go-v2/internal/ini
+google.golang.org/protobuf/internal/errors
+github.com/google/go-cmp/cmp
 go/token
+github.com/aws/smithy-go/auth
+google.golang.org/protobuf/internal/version
+github.com/google/go-containerregistry/internal/gzip
 database/sql/driver
-github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer
+google.golang.org/protobuf/encoding/protowire
 gopkg.in/yaml.v3
 encoding/gob
+github.com/go-openapi/analysis/internal/debug
+github.com/go-openapi/jsonreference/internal
+github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer
+vendor/golang.org/x/text/secure/bidirule
+internal/profile
 text/tabwriter
+google.golang.org/protobuf/reflect/protoreflect
 go.uber.org/zap/internal/color
+golang.org/x/crypto/pbkdf2
+golang.org/x/term
+golang.org/x/crypto/scrypt
+runtime/pprof
+text/template
+compress/zlib
 github.com/sigstore/cosign/pkg/cosign/env
-crypto/aes
-crypto/ecdh
-crypto/sha512
-crypto/hmac
-crypto/sha1
-crypto/sha256
-google.golang.org/protobuf/encoding/protowire
+github.com/aws/aws-sdk-go-v2/internal/context
+github.com/oklog/ulid
 github.com/nozzle/throttler
+github.com/aws/aws-sdk-go-v2/internal/middleware
 github.com/sigstore/cosign/internal/pkg/oci/remote
 github.com/sigstore/cosign/internal/ui
 github.com/sigstore/cosign/internal/pkg/now
-vendor/golang.org/x/crypto/chacha20poly1305
-github.com/opencontainers/image-spec/specs-go/v1
 github.com/go-openapi/runtime/logger
 github.com/opentracing/opentracing-go/log
+go.opentelemetry.io/otel/baggage
+github.com/fsnotify/fsnotify/internal
 golang.org/x/text/unicode/norm
+github.com/spf13/jwalterweatherman
 github.com/subosito/gotenv
+github.com/fsnotify/fsnotify
 github.com/hashicorp/hcl/hcl/token
-github.com/aws/smithy-go/auth
 gopkg.in/ini.v1
 github.com/pelletier/go-toml/v2/internal/danger
-github.com/transparency-dev/merkle/compact
-github.com/theupdateframework/go-tuf/v0/internal/fsutil
-github.com/syndtr/goleveldb/leveldb/util
-golang.org/x/crypto/ssh/internal/bcrypt_pbkdf
-golang.org/x/crypto/pbkdf2
-github.com/transparency-dev/merkle/rfc6962
-github.com/google/go-containerregistry/pkg/logs
-vendor/golang.org/x/text/unicode/bidi
-github.com/aws/smithy-go/logging
-google.golang.org/protobuf/reflect/protoreflect
-github.com/go-openapi/analysis/internal/debug
-github.com/oklog/ulid
-github.com/google/go-cmp/cmp
-golang.org/x/crypto/scrypt
-github.com/spf13/jwalterweatherman
-github.com/syndtr/goleveldb/leveldb/storage
-golang.org/x/time/rate
-github.com/google/gofuzz
-k8s.io/apimachinery/third_party/forked/golang/reflect
-github.com/pelletier/go-toml/v2/unstable
-github.com/aws/smithy-go/internal/sync/singleflight
-github.com/aws/aws-sdk-go-v2/internal/sync/singleflight
+vendor/golang.org/x/net/idna
 github.com/sigstore/sigstore-go/pkg/util
+github.com/pelletier/go-toml/v2/unstable
 github.com/hashicorp/hcl/hcl/ast
 github.com/hashicorp/hcl/hcl/scanner
-github.com/hashicorp/hcl/json/token
-github.com/transparency-dev/merkle/proof
-k8s.io/apimachinery/pkg/fields
-k8s.io/apimachinery/pkg/util/errors
-github.com/aws/smithy-go/middleware
-go/scanner
-golang.org/x/crypto/curve25519
-github.com/klauspost/compress/huff0
-github.com/google/go-containerregistry/internal/redact
-github.com/go-openapi/jsonreference/internal
-go.opentelemetry.io/otel/baggage
-github.com/google/go-querystring/query
-go/doc/comment
-github.com/syndtr/goleveldb/leveldb/cache
-github.com/syndtr/goleveldb/leveldb/filter
-github.com/hashicorp/hcl/json/scanner
-k8s.io/apimachinery/pkg/conversion/queryparams
-k8s.io/apimachinery/pkg/util/naming
-github.com/modern-go/concurrent
-gopkg.in/yaml.v2
-golang.org/x/text/unicode/bidi
-testing
-compress/gzip
-compress/zlib
-golang.org/x/net/http2/hpack
-github.com/hashicorp/hcl/hcl/parser
-k8s.io/utils/ptr
-k8s.io/apimachinery/pkg/util/version
-k8s.io/apimachinery/pkg/util/validation/field
-sigs.k8s.io/yaml/goyaml.v2
-k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json
-k8s.io/client-go/pkg/version
-github.com/davecgh/go-spew/spew
-k8s.io/client-go/tools/metrics
-k8s.io/apimachinery/pkg/conversion
-k8s.io/client-go/util/flowcontrol
-k8s.io/kube-openapi/pkg/cached
-github.com/hashicorp/hcl/json/parser
-go/ast
-github.com/google/go-containerregistry/internal/gzip
-internal/profile
-github.com/syndtr/goleveldb/leveldb/opt
-runtime/pprof
-github.com/hashicorp/hcl/hcl/printer
-vendor/golang.org/x/text/secure/bidirule
-github.com/emicklei/go-restful/log
-github.com/imdario/mergo
-github.com/go-jose/go-jose/v3/json
-github.com/sigstore/cosign/pkg/providers
-github.com/common-nighthawk/go-figure
-gopkg.in/square/go-jose.v2/json
-github.com/pelletier/go-toml/v2/internal/tracker
-github.com/hashicorp/hcl
-golang.org/x/net/internal/timeseries
-google.golang.org/grpc/internal/grpclog
-google.golang.org/grpc/attributes
-google.golang.org/grpc/internal/idle
-github.com/syndtr/goleveldb/leveldb/errors
-go.opencensus.io/internal
-go.opencensus.io/trace/tracestate
-github.com/sigstore/cosign/pkg/providers/envvar
-text/template
-github.com/sigstore/cosign/pkg/providers/filesystem
-go.opencensus.io/resource
-github.com/syndtr/goleveldb/leveldb/iterator
-github.com/go-jose/go-jose/json
-github.com/spiffe/go-spiffe/v2/spiffeid
-golang.org/x/text/secure/bidirule
-github.com/zeebo/errs
-github.com/syndtr/goleveldb/leveldb/journal
-github.com/spiffe/go-spiffe/v2/logger
-cuelang.org/go/cue/token
-cuelang.org/go/internal/source
-cuelang.org/go/internal/envflag
-golang.org/x/mod/module
-github.com/aws/aws-sdk-go-v2/internal/context
-text/scanner
-go.opencensus.io/metric/metricdata
-github.com/aws/aws-sdk-go-v2/internal/middleware
-github.com/protocolbuffers/txtpbfmt/ast
-cuelang.org/go/internal/par
-cuelang.org/go/internal/cuedebug
-cuelang.org/go/internal/cueexperiment
-cuelabs.dev/go/oci/ociregistry/ociref
-go.opencensus.io/metric/metricproducer
-github.com/rogpeppe/go-internal/lockedfile
-cuelang.org/go/internal/mod/mvs
-archive/zip
 google.golang.org/protobuf/internal/descfmt
 google.golang.org/protobuf/internal/descopts
 google.golang.org/protobuf/internal/strs
-vendor/golang.org/x/net/idna
 google.golang.org/protobuf/internal/encoding/messageset
 google.golang.org/protobuf/internal/genid
 google.golang.org/protobuf/internal/order
-google.golang.org/protobuf/runtime/protoiface
-github.com/syndtr/goleveldb/leveldb/memdb
-github.com/syndtr/goleveldb/leveldb/table
-github.com/emicklei/proto
-github.com/protocolbuffers/txtpbfmt/unquote
 google.golang.org/protobuf/internal/encoding/text
+google.golang.org/protobuf/runtime/protoiface
 google.golang.org/protobuf/internal/encoding/json
-google.golang.org/protobuf/internal/protolazy
-github.com/sigstore/cosign/cmd/cosign/cli/debug
-cuelang.org/go/cue/errors
-cuelang.org/go/cue/scanner
-github.com/protocolbuffers/txtpbfmt/parser
-k8s.io/apimachinery/pkg/util/dump
-golang.org/x/sync/singleflight
-google.golang.org/protobuf/reflect/protoregistry
-github.com/jellydator/ttlcache
 github.com/aws/aws-sdk-go-v2/aws/protocol/xml
-golang.org/x/net/idna
-crypto/internal/boring/bbig
+google.golang.org/protobuf/reflect/protoregistry
+github.com/docker/docker-credential-helpers/credentials
+github.com/sirupsen/logrus
 crypto/elliptic
-crypto/rand
+crypto/internal/boring/bbig
 encoding/asn1
+crypto/rand
 crypto/dsa
+github.com/google/go-containerregistry/pkg/v1
+github.com/docker/docker-credential-helpers/client
 github.com/aws/smithy-go/time
-github.com/aws/smithy-go/document
-github.com/aws/smithy-go/encoding/xml
-github.com/google/certificate-transparency-go/asn1
-github.com/dustin/go-humanize
-gopkg.in/inf.v0
-github.com/fxamacker/cbor
-github.com/cockroachdb/apd
 crypto/ed25519
 crypto/internal/hpke
 crypto/rsa
+github.com/klauspost/compress/zstd
 github.com/aws/aws-sdk-go-v2/internal/rand
 github.com/aws/smithy-go/rand
-github.com/klauspost/compress/zstd
-golang.org/x/term
-golang.org/x/crypto/openpgp/elgamal
-github.com/fsnotify/fsnotify/internal
-golang.org/x/crypto/ed25519
+github.com/aws/aws-sdk-go-v2/aws/middleware/private/metrics
+github.com/docker/cli/cli/config/credentials
+github.com/aws/aws-sdk-go-v2/aws/protocol/restjson
+github.com/docker/docker/pkg/homedir
+archive/tar
+github.com/vbatts/tar-split/archive/tar
+github.com/aws/aws-sdk-go-v2/internal/shareddefaults
+github.com/aws/smithy-go/document
+github.com/aws/smithy-go/encoding/json
+github.com/aws/smithy-go/encoding/xml
+github.com/aws/smithy-go/waiter
+github.com/jmespath/go-jmespath
+github.com/secure-systems-lab/go-securesystemslib/cjson
+google.golang.org/protobuf/internal/encoding/defval
+google.golang.org/protobuf/proto
+github.com/google/go-containerregistry/internal/verify
+github.com/google/go-containerregistry/pkg/v1/match
+github.com/google/go-containerregistry/pkg/legacy
+github.com/google/go-containerregistry/pkg/v1/stream
+github.com/google/go-containerregistry/pkg/v1/static
 github.com/aws/aws-sdk-go-v2/service/sso/types
 github.com/aws/aws-sdk-go-v2/service/ssooidc/types
 github.com/aws/aws-sdk-go-v2/service/sts/types
+vendor/golang.org/x/crypto/cryptobyte
+crypto/x509/pkix
 github.com/aws/aws-sdk-go-v2/service/ecr/types
-github.com/aws/smithy-go/waiter
 github.com/aws/aws-sdk-go-v2/service/ecrpublic/types
-google.golang.org/protobuf/proto
-github.com/jedisct1/go-minisign
-google.golang.org/protobuf/internal/encoding/defval
-golang.org/x/mod/sumdb/note
-github.com/syndtr/goleveldb/leveldb
-golang.org/x/crypto/nacl/box
-github.com/segmentio/ksuid
-github.com/docker/docker-credential-helpers/credentials
-github.com/sirupsen/logrus
-github.com/google/go-containerregistry/pkg/v1
-github.com/aws/aws-sdk-go-v2/aws/protocol/restjson
-github.com/aws/smithy-go/encoding/json
-github.com/aws/aws-sdk-go-v2/aws/middleware/private/metrics
-github.com/secure-systems-lab/go-securesystemslib/cjson
-github.com/jmespath/go-jmespath
+golang.org/x/oauth2/jws
+google.golang.org/protobuf/internal/protolazy
 go.mongodb.org/mongo-driver/bson/primitive
 github.com/mailru/easyjson/jlexer
 github.com/blang/semver
 go.uber.org/atomic
+golang.org/x/crypto/ed25519
 github.com/secure-systems-lab/go-securesystemslib/encrypted
-log/slog
-github.com/sigstore/cosign/internal/pkg/cosign/payload/size
-go.opentelemetry.io/otel/attribute
-go.opentelemetry.io/otel/codes
-github.com/fsnotify/fsnotify
-github.com/spf13/viper/internal/encoding/hcl
-github.com/spf13/viper/internal/encoding/json
-github.com/pelletier/go-toml/v2
-html/template
-golang.org/x/oauth2/jws
 github.com/sigstore/sigstore/pkg/signature/options
-go/doc
-github.com/gogo/protobuf/proto
-github.com/docker/docker-credential-helpers/client
-go/parser
-github.com/theupdateframework/go-tuf/v0/data
-sigs.k8s.io/json/internal/golang/encoding/json
-github.com/docker/docker/pkg/homedir
-archive/tar
-vendor/golang.org/x/crypto/cryptobyte
-crypto/x509/pkix
-github.com/vbatts/tar-split/archive/tar
-github.com/aws/aws-sdk-go-v2/internal/shareddefaults
+github.com/jedisct1/go-minisign
+golang.org/x/crypto/openpgp/elgamal
+github.com/google/certificate-transparency-go/asn1
 golang.org/x/crypto/cryptobyte
-github.com/spf13/viper/internal/encoding/yaml
+log/slog
+github.com/dustin/go-humanize
+github.com/docker/cli/cli/config/configfile
+github.com/awslabs/amazon-ecr-credential-helper/ecr-login/config
 go.mongodb.org/mongo-driver/x/bsonx/bsoncore
-go.uber.org/multierr
-github.com/json-iterator/go
-k8s.io/apimachinery/pkg/util/framer
-github.com/google/gnostic-models/jsonschema
-github.com/sigstore/sigstore/pkg/oauth
-github.com/theupdateframework/go-tuf/v0/util
-github.com/docker/cli/cli/config/credentials
-go.opencensus.io/trace
-google.golang.org/grpc/grpclog
-github.com/google/go-containerregistry/internal/verify
-github.com/google/go-containerregistry/pkg/v1/match
-github.com/google/go-containerregistry/pkg/legacy
-github.com/google/go-containerregistry/pkg/v1/stream
-github.com/google/go-containerregistry/pkg/v1/static
-github.com/google/certificate-transparency-go/x509/pkix
-go.opencensus.io/tag
 google.golang.org/protobuf/internal/filedesc
 google.golang.org/protobuf/encoding/prototext
-cuelang.org/go/internal/encoding/json
-cuelang.org/go/internal/cueimports
+go.uber.org/multierr
+html/template
+go.opentelemetry.io/otel/attribute
+github.com/sigstore/cosign/internal/pkg/cosign/payload/size
+go.opentelemetry.io/otel/codes
+github.com/docker/cli/cli/config
+golang.org/x/mod/sumdb/note
+github.com/hashicorp/hcl/hcl/parser
+crypto/ecdsa
+github.com/hashicorp/hcl/json/token
+github.com/spf13/viper/internal/encoding/json
+github.com/pelletier/go-toml/v2/internal/tracker
 go.uber.org/zap/zapcore
-github.com/moby/term
-github.com/aws/aws-sdk-go-v2/service/kms/types
+github.com/spf13/viper/internal/encoding/yaml
+github.com/transparency-dev/merkle/compact
+github.com/hashicorp/hcl/json/scanner
+github.com/transparency-dev/merkle/rfc6962
+github.com/theupdateframework/go-tuf/v0/data
+github.com/theupdateframework/go-tuf/v0/internal/fsutil
+github.com/syndtr/goleveldb/leveldb/util
+github.com/transparency-dev/merkle/proof
+github.com/hashicorp/hcl/hcl/printer
+github.com/syndtr/goleveldb/leveldb/storage
+github.com/google/go-querystring/query
+github.com/pelletier/go-toml/v2
+github.com/hashicorp/hcl/json/parser
+github.com/google/certificate-transparency-go/x509/pkix
+github.com/theupdateframework/go-tuf/v0/util
+golang.org/x/crypto/nacl/box
 go.opentelemetry.io/otel/metric
 go.opentelemetry.io/otel/trace
 go.opentelemetry.io/otel/semconv/v1.17.0
-google.golang.org/grpc/connectivity
-go.opencensus.io/stats/internal
-crypto/ecdsa
-github.com/docker/cli/cli/config/configfile
-github.com/awslabs/amazon-ecr-credential-helper/ecr-login/config
-github.com/sigstore/cosign/cmd/cosign/cli/templates/term
-go.opencensus.io/stats
-sigs.k8s.io/yaml
-go.opencensus.io/stats/view
-github.com/docker/cli/cli/config
 github.com/go-logr/logr
 k8s.io/klog/internal/sloghandler
-cuelang.org/go/cue/literal
+golang.org/x/time/rate
+gopkg.in/inf.v0
+github.com/hashicorp/hcl
+github.com/syndtr/goleveldb/leveldb/cache
+github.com/gogo/protobuf/proto
+github.com/syndtr/goleveldb/leveldb/filter
+go.mongodb.org/mongo-driver/bson/bsonrw
+github.com/fxamacker/cbor
+github.com/google/gofuzz
+k8s.io/apimachinery/third_party/forked/golang/reflect
+github.com/syndtr/goleveldb/leveldb/opt
 github.com/spf13/cast
-github.com/spf13/viper/internal/encoding/toml
 k8s.io/klog/internal/serialize
 github.com/go-logr/logr/funcr
-go.mongodb.org/mongo-driver/bson/bsonrw
+k8s.io/apimachinery/pkg/fields
+github.com/spf13/viper/internal/encoding/hcl
+k8s.io/apimachinery/pkg/util/errors
 k8s.io/klog
-cuelang.org/go/cue/ast
-github.com/go-jose/go-jose/v3/cipher
-github.com/go-jose/go-jose/cipher
-gopkg.in/square/go-jose.v2/cipher
-github.com/spiffe/go-spiffe/v2/internal/cryptoutil
 github.com/google/certificate-transparency-go/tls
+google.golang.org/protobuf/internal/encoding/tag
 golang.org/x/crypto/openpgp/packet
-go.uber.org/zap/internal
-github.com/spiffe/go-spiffe/v2/internal/jwtutil
+google.golang.org/protobuf/encoding/protojson
+go/scanner
+github.com/syndtr/goleveldb/leveldb/errors
+k8s.io/apimachinery/pkg/conversion
+go/doc/comment
+k8s.io/apimachinery/pkg/util/validation/field
+k8s.io/apimachinery/pkg/conversion/queryparams
+github.com/syndtr/goleveldb/leveldb/iterator
+google.golang.org/protobuf/internal/impl
 github.com/spf13/viper/internal/encoding/dotenv
 github.com/spf13/viper/internal/encoding/ini
+go.uber.org/zap/internal
+github.com/syndtr/goleveldb/leveldb/journal
+github.com/spf13/viper/internal/encoding/toml
+go/ast
+sigs.k8s.io/json/internal/golang/encoding/json
+k8s.io/apimachinery/pkg/util/naming
+github.com/modern-go/concurrent
 github.com/go-logr/stdr
-google.golang.org/protobuf/internal/encoding/tag
-google.golang.org/protobuf/encoding/protojson
-sigs.k8s.io/json
-k8s.io/apimachinery/pkg/util/json
-k8s.io/apimachinery/pkg/runtime/serializer/cbor/internal/modes
-k8s.io/apimachinery/pkg/util/yaml
-google.golang.org/protobuf/internal/impl
-github.com/google/go-containerregistry/internal/zstd
+gopkg.in/yaml.v2
+golang.org/x/text/unicode/bidi
+golang.org/x/net/http2/hpack
+k8s.io/utils/ptr
+github.com/syndtr/goleveldb/leveldb/memdb
 github.com/containerd/stargz-snapshotter/estargz
+github.com/google/go-containerregistry/internal/zstd
+github.com/syndtr/goleveldb/leveldb/table
+k8s.io/apimachinery/pkg/util/version
+github.com/google/gnostic-models/jsonschema
 github.com/google/go-containerregistry/internal/compression
-cuelang.org/go/cue/ast/astutil
-cuelang.org/go/mod/module
 github.com/google/go-containerregistry/pkg/v1/partial
+k8s.io/apimachinery/pkg/util/framer
+sigs.k8s.io/yaml/goyaml.v2
+k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json
+k8s.io/client-go/pkg/version
+github.com/davecgh/go-spew/spew
+k8s.io/client-go/tools/metrics
 golang.org/x/crypto/openpgp
+k8s.io/client-go/util/flowcontrol
+k8s.io/kube-openapi/pkg/cached
+github.com/emicklei/go-restful/log
+github.com/syndtr/goleveldb/leveldb
+golang.org/x/text/secure/bidirule
+github.com/json-iterator/go
+github.com/imdario/mergo
+go.mongodb.org/mongo-driver/bson/bsoncodec
+github.com/common-nighthawk/go-figure
+github.com/go-jose/go-jose/v3/cipher
+golang.org/x/net/idna
 github.com/google/go-containerregistry/pkg/v1/empty
 github.com/google/go-containerregistry/pkg/v1/validate
-go.mongodb.org/mongo-driver/bson/bsoncodec
-cuelang.org/go/internal/mod/modrequirements
-cuelang.org/go/mod/modzip
+github.com/go-jose/go-jose/v3/json
+github.com/sigstore/cosign/pkg/providers
+gopkg.in/square/go-jose.v2/cipher
+k8s.io/apimachinery/pkg/util/dump
+gopkg.in/square/go-jose.v2/json
+github.com/segmentio/ksuid
+go/doc
+go/parser
+github.com/sigstore/sigstore/pkg/oauth
+github.com/skratchdot/open-golang/open
+github.com/sigstore/cosign/pkg/providers/envvar
+github.com/sigstore/cosign/pkg/providers/filesystem
+k8s.io/apimachinery/pkg/runtime/serializer/cbor/internal/modes
+golang.org/x/net/internal/timeseries
+google.golang.org/grpc/internal/grpclog
+sigs.k8s.io/json
+google.golang.org/grpc/grpclog
+google.golang.org/grpc/attributes
+k8s.io/apimachinery/pkg/util/json
+google.golang.org/grpc/internal/idle
+go.opencensus.io/internal
+go.opencensus.io/trace/tracestate
+go.opencensus.io/resource
+go.opencensus.io/tag
+github.com/go-jose/go-jose/cipher
+github.com/go-jose/go-jose/json
+go.opencensus.io/trace
+google.golang.org/grpc/connectivity
+go.opencensus.io/metric/metricdata
+github.com/spiffe/go-spiffe/v2/internal/cryptoutil
+github.com/spiffe/go-spiffe/v2/spiffeid
+go.opencensus.io/stats/internal
+github.com/zeebo/errs
+go.opencensus.io/metric/metricproducer
+go.opencensus.io/stats
+github.com/spiffe/go-spiffe/v2/logger
 k8s.io/apimachinery/pkg/runtime/serializer/cbor/direct
-cuelang.org/go/internal
-sigs.k8s.io/structured-merge-diff/value
-cuelang.org/go/cue/stats
-cuelang.org/go/internal/astinternal
-cuelang.org/go/cue/parser
-cuelang.org/go/internal/encoding/yaml
-cuelang.org/go/internal/mod/modimports
-cuelang.org/go/internal/buildattr
-cuelang.org/go/cue/format
-cuelang.org/go/cue/build
-cuelang.org/go/internal/mod/modpkgload
-github.com/google/go-containerregistry/pkg/name
-google.golang.org/grpc/internal/resolver/dns/internal
-google.golang.org/grpc/internal/syscall
-k8s.io/client-go/util/connrotation
-k8s.io/utils/internal/third_party/forked/golang/net
-google.golang.org/grpc/internal
-github.com/mitchellh/mapstructure
-vendor/golang.org/x/net/http/httpproxy
-github.com/mailru/easyjson/buffer
+github.com/spiffe/go-spiffe/v2/internal/jwtutil
+cuelang.org/go/cue/token
+github.com/cockroachdb/apd
 crypto/x509
+github.com/google/go-containerregistry/pkg/name
 net/textproto
+vendor/golang.org/x/net/http/httpproxy
+github.com/spf13/pflag
 github.com/google/uuid
+github.com/mitchellh/mapstructure
+github.com/mailru/easyjson/buffer
 github.com/google/certificate-transparency-go/x509
-github.com/spf13/pflag
-k8s.io/utils/net
+k8s.io/utils/internal/third_party/forked/golang/net
+sigs.k8s.io/yaml
 github.com/mailru/easyjson/jwriter
-cuelang.org/go/internal/core/adt
-google.golang.org/grpc/metadata
-google.golang.org/grpc/codes
-github.com/sigstore/sigstore/pkg/signature/payload
-github.com/google/go-containerregistry/pkg/authn
+k8s.io/utils/net
 vendor/golang.org/x/net/http/httpguts
-net/mail
+github.com/google/go-containerregistry/pkg/authn
 mime/multipart
+net/mail
+github.com/sigstore/sigstore/pkg/signature/payload
 golang.org/x/net/http/httpguts
-sigs.k8s.io/structured-merge-diff/fieldpath
+k8s.io/client-go/util/connrotation
+google.golang.org/grpc/internal
+github.com/google/go-containerregistry/pkg/authn/github
+google.golang.org/grpc/internal/syscall
+google.golang.org/grpc/internal/resolver/dns/internal
+k8s.io/apimachinery/pkg/util/validation
+k8s.io/apimachinery/pkg/util/yaml
+go.opencensus.io/stats/view
+cuelang.org/go/cue/errors
+cuelang.org/go/cue/scanner
+cuelang.org/go/internal/source
+google.golang.org/grpc/metadata
+google.golang.org/grpc/codes
+cuelang.org/go/internal/envflag
+golang.org/x/mod/module
+google.golang.org/grpc/internal/grpcutil
 google.golang.org/grpc/internal/balancerload
 google.golang.org/grpc/stats
 google.golang.org/grpc/tap
-google.golang.org/grpc/internal/grpcutil
+cuelang.org/go/internal/cuedebug
+cuelang.org/go/internal/cueexperiment
 github.com/google/go-containerregistry/internal/estargz
-k8s.io/apimachinery/pkg/util/validation
+cuelang.org/go/internal/encoding/json
+text/scanner
+github.com/protocolbuffers/txtpbfmt/ast
 google.golang.org/grpc/encoding
-github.com/google/go-containerregistry/pkg/authn/github
-github.com/google/go-containerregistry/pkg/v1/tarball
-k8s.io/apimachinery/pkg/util/intstr
-k8s.io/apimachinery/pkg/runtime/schema
-k8s.io/apimachinery/pkg/api/resource
+cuelang.org/go/internal/par
 k8s.io/apimachinery/pkg/labels
+cuelabs.dev/go/oci/ociregistry/ociref
+github.com/rogpeppe/go-internal/lockedfile
+archive/zip
+cuelang.org/go/internal/mod/mvs
+github.com/sigstore/cosign/cmd/cosign/cli/debug
+github.com/moby/term
+github.com/google/go-containerregistry/pkg/v1/tarball
+github.com/aws/aws-sdk-go-v2/service/kms/types
+github.com/protocolbuffers/txtpbfmt/unquote
+golang.org/x/sync/singleflight
 go.mongodb.org/mongo-driver/bson
+github.com/protocolbuffers/txtpbfmt/parser
+github.com/jellydator/ttlcache
+github.com/emicklei/proto
+cuelang.org/go/cue/literal
+cuelang.org/go/internal/cueimports
+github.com/sigstore/cosign/cmd/cosign/cli/templates/term
 github.com/google/go-containerregistry/internal/windows
+cuelang.org/go/cue/ast
 github.com/google/go-containerregistry/pkg/legacy/tarball
 github.com/google/go-containerregistry/pkg/v1/mutate
 github.com/google/go-containerregistry/pkg/v1/cache
-sigs.k8s.io/structured-merge-diff/typed
+k8s.io/apimachinery/pkg/api/resource
+k8s.io/apimachinery/pkg/runtime/schema
+k8s.io/apimachinery/pkg/util/intstr
 github.com/google/go-containerregistry/pkg/v1/layout
-github.com/spf13/cobra
 github.com/google/certificate-transparency-go
 github.com/secure-systems-lab/go-securesystemslib/signerverifier
-github.com/sigstore/sigstore/pkg/cryptoutils
 github.com/asaskevich/govalidator
+github.com/sigstore/sigstore/pkg/cryptoutils
 github.com/digitorus/pkcs7
-github.com/theupdateframework/go-tuf/v0/pkg/keys
-gopkg.in/square/go-jose.v2
-github.com/go-jose/go-jose/v3
-golang.org/x/crypto/ssh
-github.com/go-jose/go-jose
 k8s.io/client-go/util/keyutil
+github.com/theupdateframework/go-tuf/v0/pkg/keys
 crypto/tls
+sigs.k8s.io/structured-merge-diff/value
+golang.org/x/crypto/ssh
+github.com/go-jose/go-jose/v3
+gopkg.in/square/go-jose.v2
 github.com/spiffe/go-spiffe/v2/internal/pemutil
+github.com/go-jose/go-jose
+github.com/spf13/cobra
 github.com/spiffe/go-spiffe/v2/internal/x509util
-github.com/google/certificate-transparency-go/gossip/minimal/x509ext
-github.com/sigstore/cosign/pkg/cosign/fulcioverifier/ctutil
+cuelang.org/go/cue/ast/astutil
+cuelang.org/go/mod/module
 github.com/spiffe/go-spiffe/v2/bundle/x509bundle
 github.com/sigstore/sigstore-go/pkg/fulcio/certificate
 github.com/sigstore/sigstore/pkg/signature
-github.com/spiffe/go-spiffe/v2/svid/x509svid
+github.com/google/certificate-transparency-go/gossip/minimal/x509ext
+github.com/sigstore/cosign/pkg/cosign/fulcioverifier/ctutil
 github.com/digitorus/timestamp
-sigs.k8s.io/structured-merge-diff/merge
-k8s.io/client-go/applyconfigurations/internal
+github.com/spiffe/go-spiffe/v2/svid/x509svid
 github.com/theupdateframework/go-tuf/v0/internal/signer
 github.com/theupdateframework/go-tuf/v0/sign
 github.com/theupdateframework/go-tuf/v0/verify
+github.com/sigstore/timestamp-authority/pkg/verification
 github.com/sigstore/rekor/pkg/pki/minisign
-github.com/sigstore/sigstore/pkg/signature/kms
 github.com/sigstore/cosign/pkg/cosign/pkcs11key
+github.com/sigstore/sigstore/pkg/signature/kms
 github.com/sigstore/cosign/pkg/cosign/pivkey
 github.com/theupdateframework/go-tuf/metadata
-github.com/withfig/autocomplete-tools/integrations/cobra
-sigs.k8s.io/release-utils/version
-github.com/sigstore/cosign/cmd/cosign/cli/templates
-github.com/sigstore/timestamp-authority/pkg/verification
+cuelang.org/go/internal/mod/modrequirements
+cuelang.org/go/mod/modzip
+cuelang.org/go/internal
 github.com/theupdateframework/go-tuf/v0/pkg/targets
-github.com/theupdateframework/go-tuf/v0
 github.com/sigstore/rekor/pkg/pki/x509
 google.golang.org/protobuf/internal/filetype
-github.com/go-jose/go-jose/v3/jwt
+github.com/theupdateframework/go-tuf/v0
 google.golang.org/protobuf/runtime/protoimpl
-github.com/spiffe/go-spiffe/v2/bundle/jwtbundle
+cuelang.org/go/cue/parser
+cuelang.org/go/internal/astinternal
+cuelang.org/go/cue/stats
 github.com/go-jose/go-jose/jwt
+github.com/spiffe/go-spiffe/v2/bundle/jwtbundle
+github.com/sigstore/cosign/cmd/cosign/cli/templates
+sigs.k8s.io/release-utils/version
+github.com/withfig/autocomplete-tools/integrations/cobra
 google.golang.org/protobuf/types/known/timestamppb
-google.golang.org/protobuf/protoadapt
-google.golang.org/protobuf/types/known/anypb
-google.golang.org/protobuf/types/known/structpb
-google.golang.org/protobuf/types/known/durationpb
 github.com/sigstore/protobuf-specs/gen/pb-go/dsse
+google.golang.org/protobuf/types/known/structpb
 google.golang.org/protobuf/types/descriptorpb
+google.golang.org/protobuf/types/known/anypb
+google.golang.org/protobuf/protoadapt
+github.com/go-jose/go-jose/v3/jwt
+google.golang.org/protobuf/types/known/durationpb
 github.com/spiffe/go-spiffe/v2/bundle/spiffebundle
+github.com/theupdateframework/go-tuf/metadata/trustedmetadata
+github.com/google/certificate-transparency-go/client/configpb
+github.com/golang/protobuf/ptypes/timestamp
 google.golang.org/grpc/encoding/proto
 google.golang.org/grpc/internal/pretty
-github.com/spiffe/go-spiffe/v2/svid/jwtsvid
-google.golang.org/genproto/googleapis/rpc/status
 github.com/google/gnostic-models/extensions
+google.golang.org/genproto/googleapis/rpc/status
 github.com/golang/protobuf/ptypes/duration
-github.com/golang/protobuf/ptypes/timestamp
-github.com/google/certificate-transparency-go/client/configpb
-github.com/theupdateframework/go-tuf/metadata/trustedmetadata
-google.golang.org/grpc/internal/status
+github.com/spiffe/go-spiffe/v2/svid/jwtsvid
+cuelang.org/go/internal/encoding/yaml
 github.com/in-toto/attestation/go/v1
+google.golang.org/grpc/internal/status
 google.golang.org/grpc/binarylog/grpc_binarylog_v1
+cuelang.org/go/cue/build
+cuelang.org/go/internal/buildattr
 google.golang.org/grpc/status
+cuelang.org/go/internal/mod/modimports
+cuelang.org/go/cue/format
+sigs.k8s.io/structured-merge-diff/fieldpath
+cuelang.org/go/internal/mod/modpkgload
 google.golang.org/grpc/internal/binarylog
+google.golang.org/genproto/googleapis/api/annotations
 google.golang.org/protobuf/internal/editionssupport
 google.golang.org/protobuf/types/gofeaturespb
-google.golang.org/genproto/googleapis/api/annotations
+sigs.k8s.io/structured-merge-diff/typed
+cuelang.org/go/internal/core/adt
 google.golang.org/protobuf/reflect/protodesc
 github.com/secure-systems-lab/go-securesystemslib/dsse
 github.com/sigstore/protobuf-specs/gen/pb-go/common/v1
-github.com/sigstore/sigstore/pkg/signature/dsse
 github.com/in-toto/in-toto-golang/in_toto
-cuelang.org/go/internal/core/validate
-cuelang.org/go/internal/core/walk
-cuelang.org/go/internal/core/debug
-cuelang.org/go/internal/core/dep
-cuelang.org/go/internal/core/toposort
+github.com/sigstore/sigstore/pkg/signature/dsse
 github.com/sigstore/protobuf-specs/gen/pb-go/rekor/v1
 github.com/sigstore/protobuf-specs/gen/pb-go/trustroot/v1
-cuelang.org/go/internal/core/compile
 github.com/sigstore/protobuf-specs/gen/pb-go/bundle/v1
-github.com/golang/protobuf/proto
-cuelang.org/go/internal/core/eval
 net/http/httptrace
-google.golang.org/api/transport/cert
 google.golang.org/grpc/internal/credentials
-k8s.io/client-go/util/cert
+google.golang.org/api/transport/cert
 github.com/sassoftware/relic/lib/x509tools
-cuelang.org/go/internal/core/export
-github.com/sigstore/cosign/pkg/cosign/attestation
-net/http
+k8s.io/client-go/util/cert
+github.com/golang/protobuf/proto
+sigs.k8s.io/structured-merge-diff/merge
+k8s.io/client-go/applyconfigurations/internal
 google.golang.org/grpc/credentials
-cuelang.org/go/internal/core/runtime
-google.golang.org/grpc/peer
+net/http
+github.com/sigstore/cosign/pkg/cosign/attestation
+google.golang.org/grpc/internal/channelz
 google.golang.org/grpc/resolver
 google.golang.org/grpc/credentials/insecure
-google.golang.org/grpc/internal/channelz
+google.golang.org/grpc/peer
 google.golang.org/grpc/internal/metadata
 google.golang.org/grpc/internal/resolver/passthrough
 google.golang.org/grpc/internal/transport/networktype
@@ -3696,527 +3723,536 @@
 google.golang.org/grpc/internal/resolver/dns
 github.com/sassoftware/relic/lib/pkcs7
 google.golang.org/grpc/resolver/dns
-github.com/sigstore/rekor/pkg/pki/pkcs7
 google.golang.org/grpc/channelz
 google.golang.org/grpc/balancer
-cuelang.org/go/internal/types
+github.com/sigstore/rekor/pkg/pki/pkcs7
 google.golang.org/grpc/balancer/base
 google.golang.org/grpc/internal/serviceconfig
 google.golang.org/grpc/internal/resolver
 google.golang.org/grpc/balancer/roundrobin
 google.golang.org/grpc/internal/balancer/gracefulswitch
-cuelang.org/go/internal/core/convert
-cuelang.org/go/internal/core/subsume
-go.opencensus.io/trace/propagation
+cuelang.org/go/internal/core/validate
+cuelang.org/go/internal/core/walk
+cuelang.org/go/internal/core/debug
+cuelang.org/go/internal/core/dep
+cuelang.org/go/internal/core/toposort
+cuelang.org/go/internal/core/compile
+cuelang.org/go/internal/core/eval
+cuelang.org/go/internal/core/runtime
+cuelang.org/go/internal/core/export
+cuelang.org/go/internal/types
+net/http/httputil
+net/http/httptest
 github.com/aws/smithy-go/encoding/httpbinding
-k8s.io/apimachinery/pkg/util/runtime
 github.com/aws/smithy-go/endpoints
-cuelabs.dev/go/oci/ociregistry
-cloud.google.com/go/compute/metadata
-net/http/httptest
-github.com/docker/distribution/registry/client/auth/challenge
+net/http/pprof
+github.com/go-chi/chi
+go.uber.org/zap
+github.com/sigstore/rekor/pkg/pki/pgp
 golang.org/x/oauth2/internal
-github.com/go-openapi/errors
+github.com/sigstore/cosign/pkg/blob
 github.com/go-openapi/runtime/middleware/denco
-github.com/go-openapi/runtime/middleware/header
-go.opentelemetry.io/otel/semconv/internal/v2
+github.com/google/certificate-transparency-go/x509util
+cloud.google.com/go/compute/metadata
+github.com/go-openapi/errors
+expvar
+github.com/sigstore/rekor/pkg/pki/ssh
 github.com/go-openapi/swag
-github.com/sigstore/rekor/pkg/util
+github.com/docker/distribution/registry/client/auth/challenge
+github.com/go-openapi/runtime/middleware/header
 github.com/opentracing/opentracing-go
 go.opentelemetry.io/otel/propagation
+go.opentelemetry.io/otel/semconv/internal/v2
+github.com/sigstore/rekor/pkg/util
+github.com/spf13/afero
+golang.org/x/oauth2
+github.com/sigstore/rekor/pkg/pki
+github.com/magiconair/properties
 github.com/theupdateframework/go-tuf/metadata/fetcher
 golang.org/x/net/context/ctxhttp
-github.com/hashicorp/go-cleanhttp
-github.com/sigstore/rekor/pkg/pki/ssh
 github.com/theupdateframework/go-tuf/v0/client
-github.com/spf13/afero
-github.com/google/gnostic-models/compiler
-github.com/sigstore/fulcio/pkg/api
-github.com/sigstore/cosign/internal/pkg/cosign/tsa/client
-golang.org/x/net/trace
-github.com/sigstore/cosign/pkg/blob
-expvar
-github.com/sigstore/cosign/pkg/providers/github
-cuelang.org/go/internal/cueversion
-net/http/httputil
-golang.org/x/net/http2
-github.com/emicklei/go-restful
-github.com/go-chi/chi
-github.com/magiconair/properties
-net/http/pprof
-github.com/sigstore/rekor/pkg/pki/pgp
-github.com/google/certificate-transparency-go/x509util
-google.golang.org/api/googleapi/transport
-go.uber.org/zap
-go.opencensus.io/plugin/ochttp/propagation/b3
-google.golang.org/api/transport/http/internal/propagation
-github.com/google/go-github/github
-github.com/theupdateframework/go-tuf/metadata/config
-github.com/hashicorp/go-retryablehttp
-github.com/google/certificate-transparency-go/jsonclient
-k8s.io/apimachinery/pkg/util/wait
-k8s.io/apimachinery/pkg/runtime
-k8s.io/client-go/util/workqueue
-k8s.io/client-go/features
-go.opencensus.io/plugin/ochttp
-github.com/theupdateframework/go-tuf/metadata/updater
-golang.org/x/oauth2
-cuelang.org/go/cue
 github.com/opentracing/opentracing-go/ext
-go.opentelemetry.io/otel/internal/global
-github.com/sigstore/rekor/pkg/pki
-cuelabs.dev/go/oci/ociregistry/ociauth
-cuelabs.dev/go/oci/ociregistry/internal/ocirequest
-github.com/go-openapi/strfmt
-go.opentelemetry.io/otel/semconv/v1.17.0/httpconv
-github.com/google/gnostic-models/openapiv2
-github.com/google/gnostic-models/openapiv3
-github.com/google/certificate-transparency-go/client
-github.com/google/go-containerregistry/internal/httptest
-github.com/theupdateframework/go-tuf/v0/client/leveldbstore
-github.com/sigstore/sigstore/pkg/tuf
 golang.org/x/oauth2/authhandler
 golang.org/x/oauth2/google/internal/impersonate
 golang.org/x/oauth2/google/internal/stsexchange
-github.com/coreos/go-oidc/v3/oidc
 golang.org/x/oauth2/jwt
-google.golang.org/api/internal/impersonate
-github.com/aws/smithy-go/transport/http
-github.com/google/go-containerregistry/pkg/v1/remote/transport
-github.com/google/go-containerregistry/pkg/registry
+github.com/go-openapi/strfmt
+go.opentelemetry.io/otel/internal/global
+go.opentelemetry.io/otel/semconv/v1.17.0/httpconv
+github.com/google/go-containerregistry/internal/httptest
 github.com/google/certificate-transparency-go/loglist3
-github.com/spf13/viper/internal/encoding/javaproperties
-github.com/xanzy/go-gitlab
+github.com/theupdateframework/go-tuf/metadata/config
+github.com/google/certificate-transparency-go/jsonclient
+github.com/google/go-containerregistry/pkg/v1/remote/transport
+github.com/aws/smithy-go/transport/http
 github.com/go-chi/chi/middleware
+github.com/google/go-github/github
+github.com/theupdateframework/go-tuf/metadata/updater
+github.com/hashicorp/go-cleanhttp
+k8s.io/apimachinery/pkg/util/runtime
 golang.org/x/oauth2/google/internal/externalaccountauthorizeduser
 golang.org/x/oauth2/google/externalaccount
-github.com/sigstore/sigstore-go/pkg/tuf
+github.com/google/go-containerregistry/pkg/registry
+github.com/google/gnostic-models/compiler
+github.com/google/certificate-transparency-go/client
+golang.org/x/net/http2
+github.com/theupdateframework/go-tuf/v0/client/leveldbstore
+k8s.io/apimachinery/pkg/runtime
+k8s.io/client-go/features
+github.com/hashicorp/go-retryablehttp
+github.com/spf13/viper/internal/encoding/javaproperties
+k8s.io/apimachinery/pkg/util/wait
+github.com/google/go-containerregistry/pkg/v1/remote
+github.com/sigstore/sigstore/pkg/tuf
+github.com/go-openapi/jsonpointer
+github.com/spf13/viper
 github.com/google/certificate-transparency-go/ctutil
-github.com/sigstore/sigstore/pkg/oauthflow
-github.com/sigstore/sigstore/pkg/fulcioroots
+github.com/google/gnostic-models/openapiv2
+github.com/google/gnostic-models/openapiv3
+k8s.io/client-go/util/workqueue
 go.opentelemetry.io/otel
-github.com/google/go-containerregistry/pkg/v1/remote
-cuelabs.dev/go/oci/ociregistry/ociclient
+github.com/aws/smithy-go/auth/bearer
 github.com/aws/aws-sdk-go-v2/internal/auth
-github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding
-github.com/aws/aws-sdk-go-v2/aws/protocol/query
 github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn
-github.com/aws/smithy-go/auth/bearer
+github.com/aws/aws-sdk-go-v2/aws/protocol/query
+github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding
 github.com/aws/smithy-go/private/requestcompression
-github.com/sigstore/cosign/internal/pkg/cosign/fulcio/fulcioroots
-github.com/spf13/viper
-github.com/go-openapi/jsonpointer
-golang.org/x/oauth2/google
-github.com/sigstore/sigstore-go/pkg/root
 github.com/aws/aws-sdk-go-v2/aws
-github.com/go-openapi/runtime
 github.com/go-openapi/jsonreference
-github.com/sigstore/rekor/pkg/log
-k8s.io/kube-openapi/pkg/internal
+golang.org/x/oauth2/google
+github.com/go-openapi/runtime
+github.com/sigstore/sigstore-go/pkg/tuf
+github.com/emicklei/go-restful
+github.com/sigstore/fulcio/pkg/api
 github.com/go-openapi/spec
+k8s.io/kube-openapi/pkg/internal
+github.com/sigstore/sigstore/pkg/fulcioroots
+github.com/coreos/go-oidc/v3/oidc
+github.com/xanzy/go-gitlab
+github.com/sigstore/cosign/internal/pkg/cosign/tsa/client
+github.com/sigstore/cosign/internal/pkg/cosign/fulcio/fulcioroots
+github.com/sigstore/rekor/pkg/log
+github.com/sigstore/cosign/pkg/providers/github
+github.com/sigstore/sigstore/pkg/oauthflow
+google.golang.org/api/internal/impersonate
+golang.org/x/net/trace
+github.com/sigstore/sigstore-go/pkg/root
 github.com/google/go-containerregistry/pkg/v1/google
-k8s.io/apimachinery/pkg/runtime/serializer/recognizer
-k8s.io/apimachinery/pkg/runtime/serializer/streaming
-k8s.io/client-go/tools/clientcmd/api
-github.com/aws/aws-sdk-go-v2/credentials/processcreds
+go.opencensus.io/trace/propagation
+google.golang.org/api/googleapi/transport
+github.com/go-openapi/runtime/security
+github.com/go-openapi/runtime/yamlpc
+github.com/aws/aws-sdk-go-v2/aws/middleware
 github.com/aws/aws-sdk-go-v2/credentials
+github.com/aws/aws-sdk-go-v2/credentials/processcreds
 github.com/aws/aws-sdk-go-v2/aws/defaults
-github.com/aws/aws-sdk-go-v2/internal/configsources
 github.com/aws/aws-sdk-go-v2/aws/signer/internal/v4
+github.com/aws/aws-sdk-go-v2/internal/configsources
 github.com/aws/aws-sdk-go-v2/internal/endpoints
 github.com/aws/aws-sdk-go-v2/internal/endpoints/v2
-github.com/aws/aws-sdk-go-v2/aws/middleware
 github.com/awslabs/amazon-ecr-credential-helper/ecr-login/cache
-k8s.io/apimachinery/pkg/runtime/serializer/json
-github.com/go-openapi/runtime/yamlpc
-github.com/go-openapi/runtime/security
-github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints
-github.com/aws/aws-sdk-go-v2/service/ssooidc/internal/endpoints
+go.opencensus.io/plugin/ochttp/propagation/b3
+google.golang.org/api/transport/http/internal/propagation
+cuelang.org/go/internal/core/convert
+cuelang.org/go/internal/core/subsume
+cuelang.org/go/internal/cueversion
+cuelabs.dev/go/oci/ociregistry
 github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints
-github.com/aws/aws-sdk-go-v2/service/ecrpublic/internal/endpoints
-github.com/aws/aws-sdk-go-v2/service/ecr/internal/endpoints
-github.com/aws/aws-sdk-go-v2/service/kms/internal/endpoints
-k8s.io/client-go/tools/clientcmd/api/v1
+github.com/aws/aws-sdk-go-v2/service/ssooidc/internal/endpoints
 github.com/aws/aws-sdk-go-v2/aws/transport/http
 github.com/aws/aws-sdk-go-v2/aws/retry
-cuelang.org/go/internal/value
-cuelang.org/go/encoding/json
-cuelang.org/go/encoding/protobuf/pbinternal
-cuelang.org/go/encoding/toml
 github.com/aws/aws-sdk-go-v2/aws/signer/v4
-cuelang.org/go/internal/cli
-cuelang.org/go/encoding/jsonschema
+github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints
+github.com/aws/aws-sdk-go-v2/service/ecr/internal/endpoints
+github.com/aws/aws-sdk-go-v2/service/ecrpublic/internal/endpoints
+go.opencensus.io/plugin/ochttp
+github.com/aws/aws-sdk-go-v2/service/kms/internal/endpoints
+cuelabs.dev/go/oci/ociregistry/ociauth
+cuelabs.dev/go/oci/ociregistry/internal/ocirequest
 github.com/google/go-containerregistry/pkg/crane
 github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client
 github.com/aws/aws-sdk-go-v2/feature/ec2/imds
+k8s.io/apimachinery/pkg/runtime/serializer/recognizer
+k8s.io/apimachinery/pkg/runtime/serializer/streaming
+k8s.io/client-go/tools/clientcmd/api
 github.com/aws/aws-sdk-go-v2/service/internal/presigned-url
 github.com/aws/aws-sdk-go-v2/internal/auth/smithy
-k8s.io/apimachinery/pkg/util/net
-google.golang.org/grpc/internal/transport
-cuelang.org/go/internal/task
-cuelang.org/go/internal/pkg
-cuelang.org/go/encoding/protobuf/jsonpb
-cuelang.org/go/encoding/protobuf/textproto
-github.com/aws/aws-sdk-go-v2/service/ssooidc
-github.com/aws/aws-sdk-go-v2/service/sts
+k8s.io/apimachinery/pkg/runtime/serializer/json
+github.com/go-openapi/analysis/internal/flatten/normalize
+github.com/go-openapi/analysis/internal/flatten/operations
+github.com/go-openapi/analysis/internal/flatten/replace
+github.com/go-openapi/analysis/internal/flatten/schutils
+github.com/go-openapi/analysis/internal/flatten/sortref
+github.com/aws/aws-sdk-go-v2/credentials/endpointcreds
 github.com/aws/aws-sdk-go-v2/service/sso
+github.com/aws/aws-sdk-go-v2/service/ssooidc
 github.com/aws/aws-sdk-go-v2/service/ecrpublic
+github.com/aws/aws-sdk-go-v2/service/sts
 github.com/aws/aws-sdk-go-v2/service/ecr
+k8s.io/client-go/tools/clientcmd/api/v1
 github.com/aws/aws-sdk-go-v2/service/kms
-github.com/go-openapi/analysis/internal/flatten/normalize
-github.com/go-openapi/analysis/internal/flatten/schutils
-github.com/go-openapi/analysis/internal/flatten/replace
-github.com/go-openapi/analysis/internal/flatten/operations
-github.com/aws/aws-sdk-go-v2/credentials/endpointcreds
-github.com/go-openapi/analysis/internal/flatten/sortref
-github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds
 github.com/google/go-containerregistry/internal/cmd
+github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds
+github.com/go-openapi/analysis
+k8s.io/apimachinery/pkg/util/net
+google.golang.org/grpc/internal/transport
+cuelang.org/go/cue
+cuelabs.dev/go/oci/ociregistry/ociclient
+github.com/google/go-containerregistry/cmd/crane/cmd
+github.com/go-openapi/loads
 k8s.io/apimachinery/pkg/watch
 k8s.io/client-go/transport
-github.com/go-openapi/analysis
+github.com/go-openapi/runtime/middleware/untyped
+github.com/go-openapi/validate
+k8s.io/apimachinery/pkg/apis/meta/v1
+github.com/aws/aws-sdk-go-v2/credentials/ssocreds
+k8s.io/kube-openapi/pkg/validation/spec
+k8s.io/kube-openapi/pkg/util/proto
+google.golang.org/grpc
+cuelang.org/go/internal/value
+cuelang.org/go/encoding/json
+cuelang.org/go/encoding/toml
+cuelang.org/go/internal/cli
+cuelang.org/go/encoding/jsonschema
+cuelang.org/go/encoding/protobuf/pbinternal
+github.com/aws/aws-sdk-go-v2/credentials/stscreds
+cuelang.org/go/internal/pkg
+github.com/aws/aws-sdk-go-v2/config
+cuelang.org/go/internal/task
+github.com/go-openapi/runtime/middleware
+github.com/sigstore/rekor/pkg/generated/models
+cuelang.org/go/encoding/protobuf/jsonpb
+cuelang.org/go/encoding/protobuf/textproto
+cuelang.org/go/pkg/crypto/ed25519
 cuelang.org/go/pkg/crypto/hmac
 cuelang.org/go/pkg/crypto/md5
 cuelang.org/go/pkg/crypto/sha1
 cuelang.org/go/pkg/crypto/sha256
+cuelang.org/go/pkg/crypto/sha512
 cuelang.org/go/pkg/encoding/base64
 cuelang.org/go/pkg/encoding/csv
-cuelang.org/go/pkg/crypto/ed25519
 cuelang.org/go/pkg/encoding/hex
 cuelang.org/go/pkg/encoding/json
 cuelang.org/go/pkg/encoding/toml
-cuelang.org/go/pkg/crypto/sha512
+github.com/go-openapi/runtime/client
 cuelang.org/go/pkg/encoding/yaml
-cuelang.org/go/pkg/list
 cuelang.org/go/pkg/html
+k8s.io/kube-openapi/pkg/schemaconv
+k8s.io/kube-openapi/pkg/spec3
+cuelang.org/go/pkg/list
 cuelang.org/go/pkg/math
 cuelang.org/go/pkg/math/bits
 cuelang.org/go/pkg/net
-cuelang.org/go/pkg/text/tabwriter
-cuelang.org/go/pkg/text/template
-cuelang.org/go/pkg/strconv
 cuelang.org/go/pkg/path
-cuelang.org/go/pkg/tool/cli
-cuelang.org/go/pkg/struct
+cuelang.org/go/pkg/regexp
+cuelang.org/go/pkg/strconv
 cuelang.org/go/pkg/strings
+cuelang.org/go/pkg/struct
+cuelang.org/go/pkg/text/tabwriter
+cuelang.org/go/pkg/text/template
 cuelang.org/go/pkg/time
-cuelang.org/go/pkg/regexp
-k8s.io/apimachinery/pkg/apis/meta/v1
-github.com/google/go-containerregistry/cmd/crane/cmd
-cuelang.org/go/pkg/tool/exec
-cuelang.org/go/pkg/tool/http
-cuelang.org/go/pkg/tool/os
-cuelang.org/go/pkg/uuid
-cuelang.org/go/encoding/openapi
-cuelang.org/go/encoding/yaml
-github.com/go-openapi/loads
-cuelang.org/go/pkg/tool/file
-github.com/aws/aws-sdk-go-v2/credentials/ssocreds
-github.com/go-openapi/runtime/middleware/untyped
-github.com/go-openapi/validate
-k8s.io/kube-openapi/pkg/util/proto
-k8s.io/kube-openapi/pkg/validation/spec
-google.golang.org/grpc
-cuelang.org/go/pkg
-github.com/aws/aws-sdk-go-v2/credentials/stscreds
-cuelang.org/go/cue/cuecontext
-cuelang.org/go/encoding/protobuf
-github.com/aws/aws-sdk-go-v2/config
-cuelang.org/go/internal/filetypes
-cuelang.org/go/internal/mod/modresolve
-cuelang.org/go/internal/encoding
-cuelang.org/go/internal/cueconfig
-github.com/go-openapi/runtime/middleware
-github.com/sigstore/rekor/pkg/generated/models
-k8s.io/kube-openapi/pkg/schemaconv
-k8s.io/kube-openapi/pkg/spec3
-cuelang.org/go/mod/modfile
 google.golang.org/api/internal
 github.com/spiffe/go-spiffe/v2/proto/spiffe/workload
-k8s.io/apimachinery/pkg/runtime/serializer/protobuf
+k8s.io/apimachinery/pkg/api/errors
+k8s.io/api/core/v1
 k8s.io/api/apidiscovery/v2
-k8s.io/apimachinery/pkg/apis/meta/v1/unstructured
-k8s.io/api/admissionregistration/v1
 k8s.io/api/apidiscovery/v2beta1
+k8s.io/apimachinery/pkg/runtime/serializer/protobuf
+k8s.io/apimachinery/pkg/apis/meta/v1/unstructured
 k8s.io/api/apiserverinternal/v1alpha1
+k8s.io/api/admissionregistration/v1
 k8s.io/api/authentication/v1
 k8s.io/api/certificates/v1alpha1
 k8s.io/api/authorization/v1
-k8s.io/apimachinery/pkg/api/errors
-k8s.io/api/policy/v1
+k8s.io/api/coordination/v1
 k8s.io/api/flowcontrol/v1
+k8s.io/api/flowcontrol/v1beta1
+k8s.io/api/flowcontrol/v1beta2
 k8s.io/api/flowcontrol/v1beta3
-k8s.io/api/coordination/v1
+github.com/sigstore/rekor/pkg/types
+github.com/sigstore/rekor/pkg/generated/client/entries
+github.com/sigstore/rekor/pkg/generated/client/pubkey
+github.com/sigstore/rekor/pkg/generated/client/tlog
+github.com/sigstore/rekor/pkg/generated/client/index
+k8s.io/apimachinery/pkg/runtime/serializer/versioning
 k8s.io/api/networking/v1alpha1
-k8s.io/api/rbac/v1
-k8s.io/api/policy/v1beta1
-k8s.io/apimachinery/pkg/apis/meta/v1/validation
-k8s.io/api/flowcontrol/v1beta2
-k8s.io/api/rbac/v1beta1
-k8s.io/apimachinery/pkg/api/meta
-k8s.io/apimachinery/pkg/api/equality
-k8s.io/api/flowcontrol/v1beta1
-k8s.io/client-go/rest/watch
-k8s.io/apimachinery/pkg/apis/meta/v1beta1
-k8s.io/api/rbac/v1alpha1
-k8s.io/client-go/pkg/apis/clientauthentication
-k8s.io/api/core/v1
-google.golang.org/api/option
-google.golang.org/api/transport/internal/dca
-cuelang.org/go/mod/modregistry
-cuelang.org/go/internal/mod/modload
-github.com/go-openapi/runtime/client
-k8s.io/client-go/pkg/apis/clientauthentication/v1
-k8s.io/client-go/pkg/apis/clientauthentication/v1beta1
-google.golang.org/api/transport/http
-google.golang.org/api/option/internaloption
-k8s.io/apimachinery/pkg/apis/meta/internalversion
-github.com/spiffe/go-spiffe/v2/workloadapi
+k8s.io/api/policy/v1
 k8s.io/api/coordination/v1alpha1
 k8s.io/api/coordination/v1beta1
-k8s.io/client-go/pkg/apis/clientauthentication/install
-k8s.io/apimachinery/pkg/runtime/serializer/versioning
-k8s.io/apimachinery/pkg/apis/meta/internalversion/validation
-k8s.io/client-go/util/watchlist
-k8s.io/kube-openapi/pkg/common
-google.golang.org/api/impersonate
-google.golang.org/api/idtoken
-k8s.io/api/authentication/v1alpha1
-k8s.io/api/authentication/v1beta1
-github.com/sigstore/rekor/pkg/generated/client/pubkey
-github.com/sigstore/rekor/pkg/types
-github.com/sigstore/rekor/pkg/generated/client/index
-github.com/sigstore/rekor/pkg/generated/client/tlog
-github.com/sigstore/rekor/pkg/generated/client/entries
-k8s.io/apimachinery/pkg/api/validation
-k8s.io/client-go/util/consistencydetector
-k8s.io/client-go/tools/clientcmd/api/latest
-k8s.io/apimachinery/pkg/runtime/serializer
-github.com/sigstore/cosign/pkg/providers/spiffe
-k8s.io/api/authorization/v1beta1
-cuelang.org/go/mod/modcache
-k8s.io/client-go/plugin/pkg/client/auth/exec
-github.com/sigstore/cosign/pkg/providers/google
-k8s.io/apimachinery/pkg/util/managedfields/internal
+k8s.io/api/policy/v1beta1
 github.com/sigstore/rekor/pkg/generated/client
-k8s.io/kube-openapi/pkg/handler3
-github.com/sigstore/cosign/pkg/providers/all
+k8s.io/api/rbac/v1
+k8s.io/apimachinery/pkg/runtime/serializer
 github.com/sigstore/rekor/pkg/tle
+k8s.io/api/rbac/v1alpha1
+github.com/sigstore/rekor/pkg/types/dsse
 github.com/sigstore/rekor/pkg/types/hashedrekord
 github.com/sigstore/rekor/pkg/types/intoto
-github.com/sigstore/rekor/pkg/types/dsse
 github.com/sigstore/rekor/pkg/types/rekord
-github.com/sigstore/rekor/pkg/verify
-github.com/sigstore/rekor/pkg/client
-k8s.io/client-go/rest
 github.com/sigstore/cosign/pkg/cosign/bundle
-github.com/sigstore/cosign/pkg/oci
-cuelang.org/go/mod/modconfig
-github.com/sigstore/rekor/pkg/types/dsse/v0.0.1
+github.com/sigstore/rekor/pkg/verify
+k8s.io/api/authentication/v1alpha1
+k8s.io/api/authentication/v1beta1
 github.com/sigstore/rekor/pkg/types/hashedrekord/v0.0.1
-github.com/sigstore/rekor/pkg/types/rekord/v0.0.1
+k8s.io/api/authorization/v1beta1
+github.com/sigstore/cosign/pkg/oci
 github.com/sigstore/rekor/pkg/types/intoto/v0.0.1
+github.com/sigstore/rekor/pkg/types/dsse/v0.0.1
 github.com/sigstore/rekor/pkg/types/intoto/v0.0.2
+github.com/sigstore/rekor/pkg/types/rekord/v0.0.1
+k8s.io/api/rbac/v1beta1
+k8s.io/apimachinery/pkg/api/equality
+k8s.io/apimachinery/pkg/api/meta
+k8s.io/apimachinery/pkg/apis/meta/v1/validation
 github.com/sigstore/cosign/internal/pkg/cosign
-github.com/sigstore/cosign/pkg/oci/empty
+k8s.io/client-go/pkg/apis/clientauthentication
 github.com/sigstore/cosign/pkg/oci/internal/signature
-github.com/sigstore/cosign/pkg/oci/platform
+github.com/sigstore/cosign/pkg/oci/empty
 k8s.io/api/admissionregistration/v1alpha1
 k8s.io/api/admissionregistration/v1beta1
-cuelang.org/go/cue/load
 github.com/sigstore/cosign/pkg/oci/signed
+github.com/sigstore/sigstore-go/pkg/tlog
+k8s.io/client-go/rest/watch
+k8s.io/kube-openapi/pkg/common
 github.com/sigstore/cosign/pkg/oci/remote
+k8s.io/apimachinery/pkg/apis/meta/v1beta1
+k8s.io/client-go/pkg/apis/clientauthentication/v1
+k8s.io/client-go/pkg/apis/clientauthentication/v1beta1
+k8s.io/client-go/tools/clientcmd/api/latest
 github.com/sigstore/cosign/pkg/oci/layout
 github.com/sigstore/cosign/pkg/oci/static
-github.com/sigstore/sigstore-go/pkg/tlog
-github.com/sigstore/cosign/internal/pkg/cosign/payload
-github.com/sigstore/cosign/pkg/oci/mutate
-k8s.io/apimachinery/pkg/util/managedfields
 github.com/sigstore/sigstore-go/pkg/verify
-k8s.io/client-go/gentype
-k8s.io/client-go/plugin/pkg/client/auth/azure
-k8s.io/client-go/plugin/pkg/client/auth/gcp
-k8s.io/client-go/tools/auth
-k8s.io/client-go/plugin/pkg/client/auth/oidc
-k8s.io/client-go/tools/clientcmd
+github.com/sigstore/rekor/pkg/client
+google.golang.org/api/transport/internal/dca
+google.golang.org/api/option
+github.com/spiffe/go-spiffe/v2/workloadapi
+k8s.io/apimachinery/pkg/apis/meta/internalversion
+cuelang.org/go/pkg/tool/cli
+github.com/sigstore/cosign/pkg/oci/mutate
+k8s.io/client-go/pkg/apis/clientauthentication/install
+github.com/sigstore/cosign/internal/pkg/cosign/payload
+cuelang.org/go/pkg/tool/exec
+k8s.io/client-go/plugin/pkg/client/auth/exec
+k8s.io/kube-openapi/pkg/handler3
+k8s.io/apimachinery/pkg/apis/meta/internalversion/validation
+google.golang.org/api/option/internaloption
+k8s.io/client-go/util/watchlist
 github.com/awslabs/amazon-ecr-credential-helper/ecr-login/api
-k8s.io/client-go/plugin/pkg/client/auth
+google.golang.org/api/transport/http
+cuelang.org/go/pkg/tool/file
+cuelang.org/go/pkg/tool/http
+cuelang.org/go/pkg/tool/os
+cuelang.org/go/pkg/uuid
 github.com/sigstore/cosign/pkg/cosign/remote
+github.com/sigstore/cosign/pkg/cosign
+k8s.io/apimachinery/pkg/api/validation
+github.com/awslabs/amazon-ecr-credential-helper/ecr-login
+k8s.io/client-go/rest
+k8s.io/client-go/util/consistencydetector
 github.com/sigstore/cosign/internal/pkg/cosign/fulcio
 github.com/sigstore/cosign/internal/pkg/cosign/tsa
 github.com/sigstore/cosign/pkg/oci/walk
-github.com/awslabs/amazon-ecr-credential-helper/ecr-login
+google.golang.org/api/idtoken
+google.golang.org/api/impersonate
+cuelang.org/go/encoding/openapi
+cuelang.org/go/encoding/yaml
 github.com/sigstore/sigstore-go/pkg/bundle
-github.com/sigstore/cosign/pkg/cosign
-k8s.io/client-go/openapi
+github.com/sigstore/cosign/pkg/oci/platform
+github.com/sigstore/cosign/pkg/providers/spiffe
+k8s.io/apimachinery/pkg/util/managedfields/internal
+cuelang.org/go/pkg
+cuelang.org/go/cue/cuecontext
+cuelang.org/go/encoding/protobuf
 github.com/sigstore/sigstore/pkg/signature/kms/aws
-github.com/sigstore/cosign/pkg/cosign/cue
+github.com/sigstore/cosign/pkg/providers/google
+github.com/sigstore/cosign/pkg/providers/all
+k8s.io/client-go/gentype
 github.com/sigstore/cosign/pkg/cosign/git/github
 github.com/sigstore/cosign/pkg/cosign/git/gitlab
+k8s.io/client-go/plugin/pkg/client/auth/azure
+k8s.io/client-go/plugin/pkg/client/auth/gcp
+k8s.io/client-go/plugin/pkg/client/auth/oidc
+k8s.io/client-go/tools/auth
 github.com/sigstore/cosign/internal/pkg/cosign/rekor
-github.com/sigstore/cosign/cmd/cosign/errors
 github.com/sigstore/cosign/cmd/cosign/cli/trustedroot
+github.com/sigstore/cosign/cmd/cosign/errors
+cuelang.org/go/internal/filetypes
+cuelang.org/go/internal/mod/modresolve
+k8s.io/apimachinery/pkg/util/managedfields
+k8s.io/client-go/tools/clientcmd
+k8s.io/client-go/plugin/pkg/client/auth
 github.com/sigstore/cosign/pkg/cosign/git
+cuelang.org/go/internal/encoding
+cuelang.org/go/internal/cueconfig
+k8s.io/client-go/openapi
+cuelang.org/go/mod/modfile
+cuelang.org/go/mod/modregistry
+cuelang.org/go/internal/mod/modload
+cuelang.org/go/mod/modcache
+cuelang.org/go/mod/modconfig
+cuelang.org/go/cue/load
+github.com/sigstore/cosign/pkg/cosign/cue
+k8s.io/api/autoscaling/v2
+k8s.io/api/autoscaling/v2beta1
+k8s.io/api/apps/v1beta2
+k8s.io/api/apps/v1
+k8s.io/api/autoscaling/v2beta2
+k8s.io/api/batch/v1
+k8s.io/api/certificates/v1
 k8s.io/api/certificates/v1beta1
-k8s.io/api/apps/v1beta1
 k8s.io/api/discovery/v1
 k8s.io/api/discovery/v1beta1
-k8s.io/api/apps/v1
-k8s.io/api/autoscaling/v2beta2
-k8s.io/api/autoscaling/v2beta1
 k8s.io/api/autoscaling/v1
+k8s.io/api/apps/v1beta1
+k8s.io/api/events/v1
+k8s.io/api/networking/v1beta1
+k8s.io/api/node/v1
 k8s.io/api/events/v1beta1
-k8s.io/api/batch/v1
-k8s.io/api/autoscaling/v2
-k8s.io/api/apps/v1beta2
 k8s.io/api/node/v1alpha1
+k8s.io/api/networking/v1
+k8s.io/api/resource/v1alpha3
 k8s.io/api/node/v1beta1
-k8s.io/api/node/v1
-k8s.io/api/events/v1
-k8s.io/api/certificates/v1
-k8s.io/client-go/tools/reference
 k8s.io/api/scheduling/v1
 k8s.io/api/scheduling/v1alpha1
 k8s.io/api/scheduling/v1beta1
-k8s.io/api/networking/v1
-k8s.io/api/storagemigration/v1alpha1
+k8s.io/api/storage/v1
 k8s.io/api/storage/v1alpha1
-k8s.io/api/networking/v1beta1
-k8s.io/api/resource/v1alpha3
 k8s.io/api/storage/v1beta1
-k8s.io/api/storage/v1
+k8s.io/api/storagemigration/v1alpha1
+k8s.io/client-go/tools/reference
 k8s.io/api/batch/v1beta1
 k8s.io/api/extensions/v1beta1
 k8s.io/client-go/kubernetes/scheme
 k8s.io/client-go/kubernetes/typed/authentication/v1
-k8s.io/client-go/kubernetes/typed/authentication/v1beta1
-k8s.io/client-go/kubernetes/typed/authorization/v1beta1
 k8s.io/client-go/kubernetes/typed/authentication/v1alpha1
-k8s.io/client-go/discovery
+k8s.io/client-go/kubernetes/typed/authentication/v1beta1
 k8s.io/client-go/kubernetes/typed/authorization/v1
+k8s.io/client-go/discovery
+k8s.io/client-go/kubernetes/typed/authorization/v1beta1
 k8s.io/client-go/applyconfigurations/meta/v1
-k8s.io/client-go/applyconfigurations/certificates/v1
-k8s.io/client-go/applyconfigurations/coordination/v1alpha1
-k8s.io/client-go/applyconfigurations/certificates/v1alpha1
+k8s.io/client-go/applyconfigurations/apiserverinternal/v1alpha1
 k8s.io/client-go/applyconfigurations/autoscaling/v1
-k8s.io/client-go/applyconfigurations/coordination/v1beta1
-k8s.io/client-go/applyconfigurations/coordination/v1
-k8s.io/client-go/applyconfigurations/certificates/v1beta1
+k8s.io/client-go/applyconfigurations/admissionregistration/v1
+k8s.io/client-go/applyconfigurations/autoscaling/v2beta1
 k8s.io/client-go/applyconfigurations/policy/v1beta1
-k8s.io/client-go/applyconfigurations/networking/v1alpha1
-k8s.io/client-go/applyconfigurations/scheduling/v1
-k8s.io/client-go/applyconfigurations/policy/v1
-k8s.io/client-go/applyconfigurations/scheduling/v1alpha1
-k8s.io/client-go/applyconfigurations/scheduling/v1beta1
-k8s.io/client-go/applyconfigurations/apiserverinternal/v1alpha1
-k8s.io/client-go/applyconfigurations/storagemigration/v1alpha1
-k8s.io/client-go/applyconfigurations/rbac/v1beta1
+k8s.io/client-go/applyconfigurations/certificates/v1
 k8s.io/client-go/applyconfigurations/autoscaling/v2beta2
-k8s.io/client-go/applyconfigurations/flowcontrol/v1beta3
-k8s.io/client-go/applyconfigurations/rbac/v1alpha1
-k8s.io/client-go/applyconfigurations/rbac/v1
-k8s.io/client-go/applyconfigurations/autoscaling/v2beta1
-k8s.io/client-go/applyconfigurations/flowcontrol/v1
 k8s.io/client-go/applyconfigurations/autoscaling/v2
+k8s.io/client-go/applyconfigurations/certificates/v1alpha1
+k8s.io/client-go/applyconfigurations/certificates/v1beta1
+k8s.io/client-go/applyconfigurations/coordination/v1beta1
+k8s.io/client-go/applyconfigurations/coordination/v1
+k8s.io/client-go/applyconfigurations/coordination/v1alpha1
 k8s.io/client-go/applyconfigurations/flowcontrol/v1beta1
+k8s.io/client-go/applyconfigurations/flowcontrol/v1beta3
 k8s.io/client-go/applyconfigurations/flowcontrol/v1beta2
-k8s.io/client-go/applyconfigurations/admissionregistration/v1
+k8s.io/client-go/applyconfigurations/networking/v1alpha1
+k8s.io/client-go/applyconfigurations/flowcontrol/v1
+k8s.io/client-go/applyconfigurations/policy/v1
 k8s.io/client-go/applyconfigurations/core/v1
-k8s.io/client-go/kubernetes/typed/coordination/v1beta1
-k8s.io/client-go/kubernetes/typed/scheduling/v1alpha1
 k8s.io/client-go/kubernetes/typed/certificates/v1alpha1
-k8s.io/client-go/kubernetes/typed/certificates/v1
 k8s.io/client-go/kubernetes/typed/coordination/v1
-k8s.io/client-go/kubernetes/typed/storagemigration/v1alpha1
-k8s.io/client-go/kubernetes/typed/scheduling/v1beta1
+k8s.io/client-go/kubernetes/typed/autoscaling/v2beta2
+k8s.io/client-go/kubernetes/typed/policy/v1beta1
 k8s.io/client-go/kubernetes/typed/coordination/v1alpha1
-k8s.io/client-go/kubernetes/typed/scheduling/v1
-k8s.io/client-go/kubernetes/typed/apiserverinternal/v1alpha1
 k8s.io/client-go/kubernetes/typed/networking/v1alpha1
-k8s.io/client-go/kubernetes/typed/policy/v1
+k8s.io/client-go/kubernetes/typed/autoscaling/v2beta1
+k8s.io/client-go/kubernetes/typed/coordination/v1beta1
 k8s.io/client-go/kubernetes/typed/certificates/v1beta1
-k8s.io/client-go/kubernetes/typed/policy/v1beta1
+k8s.io/client-go/kubernetes/typed/flowcontrol/v1
 k8s.io/client-go/kubernetes/typed/autoscaling/v1
-k8s.io/client-go/kubernetes/typed/autoscaling/v2beta1
-k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta3
-k8s.io/client-go/kubernetes/typed/rbac/v1
-k8s.io/client-go/kubernetes/typed/rbac/v1alpha1
-k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta2
 k8s.io/client-go/kubernetes/typed/autoscaling/v2
-k8s.io/client-go/kubernetes/typed/rbac/v1beta1
+k8s.io/client-go/kubernetes/typed/certificates/v1
+k8s.io/client-go/kubernetes/typed/apiserverinternal/v1alpha1
+k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta2
+k8s.io/client-go/kubernetes/typed/policy/v1
+k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta3
 k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta1
-k8s.io/client-go/kubernetes/typed/autoscaling/v2beta2
-k8s.io/client-go/kubernetes/typed/flowcontrol/v1
-k8s.io/client-go/applyconfigurations/admissionregistration/v1alpha1
+k8s.io/client-go/applyconfigurations/rbac/v1
 k8s.io/client-go/kubernetes/typed/admissionregistration/v1
+k8s.io/client-go/applyconfigurations/admissionregistration/v1alpha1
 k8s.io/client-go/applyconfigurations/admissionregistration/v1beta1
+k8s.io/client-go/applyconfigurations/rbac/v1alpha1
+k8s.io/client-go/applyconfigurations/rbac/v1beta1
+k8s.io/client-go/applyconfigurations/scheduling/v1
+k8s.io/client-go/applyconfigurations/scheduling/v1alpha1
+k8s.io/client-go/applyconfigurations/scheduling/v1beta1
+k8s.io/client-go/applyconfigurations/storagemigration/v1alpha1
+k8s.io/client-go/kubernetes/typed/rbac/v1
+k8s.io/client-go/kubernetes/typed/scheduling/v1alpha1
+k8s.io/client-go/kubernetes/typed/scheduling/v1
 k8s.io/client-go/kubernetes/typed/admissionregistration/v1alpha1
+k8s.io/client-go/kubernetes/typed/storagemigration/v1alpha1
+k8s.io/client-go/kubernetes/typed/scheduling/v1beta1
+k8s.io/client-go/kubernetes/typed/rbac/v1alpha1
 k8s.io/client-go/kubernetes/typed/admissionregistration/v1beta1
-k8s.io/client-go/applyconfigurations/discovery/v1beta1
-k8s.io/client-go/applyconfigurations/events/v1beta1
+k8s.io/client-go/kubernetes/typed/rbac/v1beta1
+k8s.io/client-go/applyconfigurations/apps/v1beta1
+k8s.io/client-go/applyconfigurations/apps/v1beta2
+k8s.io/client-go/applyconfigurations/batch/v1
+k8s.io/client-go/applyconfigurations/node/v1
+k8s.io/client-go/applyconfigurations/networking/v1beta1
+k8s.io/client-go/applyconfigurations/apps/v1
 k8s.io/client-go/applyconfigurations/node/v1alpha1
 k8s.io/client-go/applyconfigurations/node/v1beta1
-k8s.io/client-go/applyconfigurations/events/v1
-k8s.io/client-go/applyconfigurations/node/v1
-k8s.io/client-go/applyconfigurations/apps/v1beta1
+k8s.io/client-go/applyconfigurations/networking/v1
+k8s.io/client-go/kubernetes/typed/core/v1
 k8s.io/client-go/applyconfigurations/discovery/v1
-k8s.io/client-go/applyconfigurations/storage/v1alpha1
-k8s.io/client-go/applyconfigurations/batch/v1
+k8s.io/client-go/applyconfigurations/discovery/v1beta1
+k8s.io/client-go/applyconfigurations/events/v1
+k8s.io/client-go/applyconfigurations/extensions/v1beta1
+k8s.io/client-go/applyconfigurations/events/v1beta1
 k8s.io/client-go/applyconfigurations/storage/v1
+k8s.io/client-go/applyconfigurations/storage/v1alpha1
 k8s.io/client-go/applyconfigurations/storage/v1beta1
-k8s.io/client-go/applyconfigurations/networking/v1
-k8s.io/client-go/applyconfigurations/networking/v1beta1
-k8s.io/client-go/kubernetes/typed/core/v1
-k8s.io/client-go/applyconfigurations/apps/v1beta2
 k8s.io/client-go/applyconfigurations/resource/v1alpha3
-k8s.io/client-go/applyconfigurations/apps/v1
-k8s.io/client-go/applyconfigurations/extensions/v1beta1
-k8s.io/client-go/kubernetes/typed/node/v1
 k8s.io/client-go/kubernetes/typed/events/v1beta1
-k8s.io/client-go/kubernetes/typed/discovery/v1
 k8s.io/client-go/kubernetes/typed/node/v1beta1
-k8s.io/client-go/kubernetes/typed/events/v1
-k8s.io/client-go/kubernetes/typed/node/v1alpha1
 k8s.io/client-go/kubernetes/typed/storage/v1alpha1
+k8s.io/client-go/kubernetes/typed/discovery/v1
+k8s.io/client-go/kubernetes/typed/node/v1alpha1
 k8s.io/client-go/kubernetes/typed/discovery/v1beta1
-k8s.io/client-go/kubernetes/typed/networking/v1
+k8s.io/client-go/kubernetes/typed/events/v1
 k8s.io/client-go/kubernetes/typed/networking/v1beta1
-k8s.io/client-go/kubernetes/typed/storage/v1
 k8s.io/client-go/kubernetes/typed/resource/v1alpha3
-k8s.io/client-go/kubernetes/typed/apps/v1beta1
+k8s.io/client-go/kubernetes/typed/node/v1
+k8s.io/client-go/kubernetes/typed/networking/v1
 k8s.io/client-go/kubernetes/typed/batch/v1
+k8s.io/client-go/kubernetes/typed/apps/v1beta1
 k8s.io/client-go/applyconfigurations/batch/v1beta1
 k8s.io/client-go/kubernetes/typed/storage/v1beta1
 k8s.io/client-go/kubernetes/typed/apps/v1
-k8s.io/client-go/kubernetes/typed/apps/v1beta2
 k8s.io/client-go/kubernetes/typed/extensions/v1beta1
+k8s.io/client-go/kubernetes/typed/apps/v1beta2
+k8s.io/client-go/kubernetes/typed/storage/v1
 k8s.io/client-go/kubernetes/typed/batch/v1beta1
 k8s.io/client-go/kubernetes
 github.com/sigstore/cosign/pkg/cosign/kubernetes
 github.com/sigstore/cosign/pkg/signature
-github.com/sigstore/cosign/cmd/cosign/cli/publickey
 github.com/sigstore/cosign/cmd/cosign/cli/options
+github.com/sigstore/cosign/cmd/cosign/cli/publickey
+github.com/sigstore/cosign/cmd/cosign/cli/rekor
 github.com/sigstore/cosign/cmd/cosign/cli/fulcio
+github.com/sigstore/cosign/pkg/policy
 github.com/sigstore/cosign/cmd/cosign/cli/attach
+github.com/sigstore/cosign/cmd/cosign/cli/generate
 github.com/sigstore/cosign/cmd/cosign/cli/importkeypair
-github.com/sigstore/cosign/cmd/cosign/cli/initialize
+github.com/sigstore/cosign/cmd/cosign/cli/download
 github.com/sigstore/cosign/cmd/cosign/cli/copy
+github.com/sigstore/cosign/cmd/cosign/cli/initialize
 github.com/sigstore/cosign/cmd/cosign/cli/triangulate
-github.com/sigstore/cosign/cmd/cosign/cli/generate
-github.com/sigstore/cosign/cmd/cosign/cli/download
 github.com/sigstore/cosign/cmd/cosign/cli/upload
-github.com/sigstore/cosign/cmd/cosign/cli/rekor
-github.com/sigstore/cosign/pkg/policy
 github.com/sigstore/cosign/cmd/cosign/cli/fulcio/fulcioverifier
 github.com/sigstore/cosign/cmd/cosign/cli/sign
 github.com/sigstore/cosign/cmd/cosign/cli/attest
 github.com/sigstore/cosign/cmd/cosign/cli/verify
-github.com/sigstore/cosign/cmd/cosign/cli/bundle
-github.com/sigstore/cosign/cmd/cosign/cli/manifest
 github.com/sigstore/cosign/cmd/cosign/cli/dockerfile
+github.com/sigstore/cosign/cmd/cosign/cli/manifest
+github.com/sigstore/cosign/cmd/cosign/cli/bundle
 github.com/sigstore/cosign/cmd/cosign/cli
 github.com/sigstore/cosign/cmd/cosign
    dh_auto_test -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go test -vet=off -v -p 42 github.com/sigstore/cosign/cmd/cosign
+	cd _build && go test -vet=off -v -p 20 github.com/sigstore/cosign/cmd/cosign
 ?   	github.com/sigstore/cosign/cmd/cosign	[no test files]
    create-stamp debian/debhelper-build-stamp
    dh_testroot -O--builddirectory=_build -O--buildsystem=golang
@@ -4263,8 +4299,8 @@
    dh_md5sums -O--builddirectory=_build -O--buildsystem=golang
    dh_builddeb -O--builddirectory=_build -O--buildsystem=golang
 dpkg-deb: building package 'cosign' in '../cosign_2.4.3-1_amd64.deb'.
-dpkg-deb: building package 'cosign-dbgsym' in '../cosign-dbgsym_2.4.3-1_amd64.deb'.
 dpkg-deb: building package 'golang-github-sigstore-cosign-dev' in '../golang-github-sigstore-cosign-dev_2.4.3-1_all.deb'.
+dpkg-deb: building package 'cosign-dbgsym' in '../cosign-dbgsym_2.4.3-1_amd64.deb'.
  dpkg-genbuildinfo --build=binary -O../cosign_2.4.3-1_amd64.buildinfo
  dpkg-genchanges --build=binary -O../cosign_2.4.3-1_amd64.changes
 dpkg-genchanges: info: binary-only upload (no source code included)
@@ -4272,12 +4308,14 @@
 dpkg-buildpackage: info: binary-only upload (no source included)
 dpkg-genchanges: info: including full source code in upload
 I: copying local configuration
+I: user script /srv/workspace/pbuilder/2739090/tmp/hooks/B01_cleanup starting
+I: user script /srv/workspace/pbuilder/2739090/tmp/hooks/B01_cleanup finished
 I: unmounting dev/ptmx filesystem
 I: unmounting dev/pts filesystem
 I: unmounting dev/shm filesystem
 I: unmounting proc filesystem
 I: unmounting sys filesystem
 I: cleaning the build env 
-I: removing directory /srv/workspace/pbuilder/3813363 and its subdirectories
-I: Current time: Sun Apr 19 21:12:37 -12 2026
-I: pbuilder-time-stamp: 1776676357
+I: removing directory /srv/workspace/pbuilder/2739090 and its subdirectories
+I: Current time: Tue Mar 18 17:08:45 +14 2025
+I: pbuilder-time-stamp: 1742267325