Diff of the two buildlogs:

--
--- b1/build.log	2025-04-30 17:32:56.086843456 +0000
+++ b2/build.log	2025-04-30 17:37:02.077615625 +0000
@@ -1,6 +1,6 @@
 I: pbuilder: network access will be disabled during build
-I: Current time: Wed Apr 30 05:28:26 -12 2025
-I: pbuilder-time-stamp: 1746034106
+I: Current time: Wed Jun  3 13:55:58 +14 2026
+I: pbuilder-time-stamp: 1780444558
 I: Building the build Environment
 I: extracting base tarball [/var/cache/pbuilder/unstable-reproducible-base.tgz]
 I: copying local configuration
@@ -24,52 +24,84 @@
 dpkg-source: info: applying 0001-Don-t-hard-fail-on-slow-systems.-624.patch
 I: Not using root during the build.
 I: Installing the build-deps
-I: user script /srv/workspace/pbuilder/1214693/tmp/hooks/D02_print_environment starting
+I: user script /srv/workspace/pbuilder/4060338/tmp/hooks/D01_modify_environment starting
+debug: Running on ionos5-amd64.
+I: Changing host+domainname to test build reproducibility
+I: Adding a custom variable just for the fun of it...
+I: Changing /bin/sh to bash
+'/bin/sh' -> '/bin/bash'
+lrwxrwxrwx 1 root root 9 Jun  2 23:56 /bin/sh -> /bin/bash
+I: Setting pbuilder2's login shell to /bin/bash
+I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other
+I: user script /srv/workspace/pbuilder/4060338/tmp/hooks/D01_modify_environment finished
+I: user script /srv/workspace/pbuilder/4060338/tmp/hooks/D02_print_environment starting
 I: set
-  BUILDDIR='/build/reproducible-path'
-  BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other'
-  BUILDUSERNAME='pbuilder1'
-  BUILD_ARCH='amd64'
-  DEBIAN_FRONTEND='noninteractive'
-  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=40 '
-  DISTRIBUTION='unstable'
-  HOME='/root'
-  HOST_ARCH='amd64'
+  BASH=/bin/sh
+  BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath
+  BASH_ALIASES=()
+  BASH_ARGC=()
+  BASH_ARGV=()
+  BASH_CMDS=()
+  BASH_LINENO=([0]="12" [1]="0")
+  BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:.
+  BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment")
+  BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="x86_64-pc-linux-gnu")
+  BASH_VERSION='5.2.37(1)-release'
+  BUILDDIR=/build/reproducible-path
+  BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other'
+  BUILDUSERNAME=pbuilder2
+  BUILD_ARCH=amd64
+  DEBIAN_FRONTEND=noninteractive
+  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=42 '
+  DIRSTACK=()
+  DISTRIBUTION=unstable
+  EUID=0
+  FUNCNAME=([0]="Echo" [1]="main")
+  GROUPS=()
+  HOME=/root
+  HOSTNAME=i-capture-the-hostname
+  HOSTTYPE=x86_64
+  HOST_ARCH=amd64
   IFS=' 	
   '
-  INVOCATION_ID='536a2605dfbc41879c73d77d392d7dd9'
-  LANG='C'
-  LANGUAGE='en_US:en'
-  LC_ALL='C'
-  MAIL='/var/mail/root'
-  OPTIND='1'
-  PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games'
-  PBCURRENTCOMMANDLINEOPERATION='build'
-  PBUILDER_OPERATION='build'
-  PBUILDER_PKGDATADIR='/usr/share/pbuilder'
-  PBUILDER_PKGLIBDIR='/usr/lib/pbuilder'
-  PBUILDER_SYSCONFDIR='/etc'
-  PPID='1214693'
-  PS1='# '
-  PS2='> '
+  INVOCATION_ID=75165acabc604f16b574fde93f72a6c9
+  LANG=C
+  LANGUAGE=et_EE:et
+  LC_ALL=C
+  MACHTYPE=x86_64-pc-linux-gnu
+  MAIL=/var/mail/root
+  OPTERR=1
+  OPTIND=1
+  OSTYPE=linux-gnu
+  PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path
+  PBCURRENTCOMMANDLINEOPERATION=build
+  PBUILDER_OPERATION=build
+  PBUILDER_PKGDATADIR=/usr/share/pbuilder
+  PBUILDER_PKGLIBDIR=/usr/lib/pbuilder
+  PBUILDER_SYSCONFDIR=/etc
+  PIPESTATUS=([0]="0")
+  POSIXLY_CORRECT=y
+  PPID=4060338
   PS4='+ '
-  PWD='/'
-  SHELL='/bin/bash'
-  SHLVL='2'
-  SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.xelUTyrM/pbuilderrc_avrh --distribution unstable --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.xelUTyrM/b1 --logfile b1/build.log gitsign_0.13.0-1.dsc'
-  SUDO_GID='111'
-  SUDO_UID='106'
-  SUDO_USER='jenkins'
-  TERM='unknown'
-  TZ='/usr/share/zoneinfo/Etc/GMT+12'
-  USER='root'
-  _='/usr/bin/systemd-run'
-  http_proxy='http://46.16.76.132:3128'
+  PWD=/
+  SHELL=/bin/bash
+  SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix
+  SHLVL=3
+  SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.xelUTyrM/pbuilderrc_DGeq --distribution unstable --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.xelUTyrM/b2 --logfile b2/build.log gitsign_0.13.0-1.dsc'
+  SUDO_GID=110
+  SUDO_UID=105
+  SUDO_USER=jenkins
+  TERM=unknown
+  TZ=/usr/share/zoneinfo/Etc/GMT-14
+  UID=0
+  USER=root
+  _='I: set'
+  http_proxy=http://213.165.73.152:3128
 I: uname -a
-  Linux ionos11-amd64 6.1.0-34-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.135-1 (2025-04-25) x86_64 GNU/Linux
+  Linux i-capture-the-hostname 6.12.12+bpo-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.12-1~bpo12+1 (2025-02-23) x86_64 GNU/Linux
 I: ls -l /bin
-  lrwxrwxrwx 1 root root 7 Mar  4 11:20 /bin -> usr/bin
-I: user script /srv/workspace/pbuilder/1214693/tmp/hooks/D02_print_environment finished
+  lrwxrwxrwx 1 root root 7 Mar  4  2025 /bin -> usr/bin
+I: user script /srv/workspace/pbuilder/4060338/tmp/hooks/D02_print_environment finished
  -> Attempting to satisfy build-dependencies
  -> Creating pbuilder-satisfydepends-dummy package
 Package: pbuilder-satisfydepends-dummy
@@ -712,7 +744,7 @@
 Get: 577 http://deb.debian.org/debian unstable/main amd64 golang-gitlab-gitlab-org-api-client-go-dev all 0.123.0-2 [286 kB]
 Get: 578 http://deb.debian.org/debian unstable/main amd64 golang-github-sigstore-cosign-dev all 2.5.0-2 [325 kB]
 Get: 579 http://deb.debian.org/debian unstable/main amd64 help2man amd64 1.49.3 [198 kB]
-Fetched 265 MB in 28s (9361 kB/s)
+Fetched 265 MB in 4s (68.5 MB/s)
 Preconfiguring packages ...
 Selecting previously unselected package golang-golang-x-sys-dev.
 (Reading database ... 
(Reading database ... 5%
(Reading database ... 10%
(Reading database ... 15%
(Reading database ... 20%
(Reading database ... 25%
(Reading database ... 30%
(Reading database ... 35%
(Reading database ... 40%
(Reading database ... 45%
(Reading database ... 50%
(Reading database ... 55%
(Reading database ... 60%
(Reading database ... 65%
(Reading database ... 70%
(Reading database ... 75%
(Reading database ... 80%
(Reading database ... 85%
(Reading database ... 90%
(Reading database ... 95%
(Reading database ... 100%
(Reading database ... 19839 files and directories currently installed.)
@@ -2568,8 +2600,8 @@
 Setting up tzdata (2025b-2) ...
 
 Current default time zone: 'Etc/UTC'
-Local time is now:      Wed Apr 30 17:31:01 UTC 2025.
-Universal Time is now:  Wed Apr 30 17:31:01 UTC 2025.
+Local time is now:      Tue Jun  2 23:58:06 UTC 2026.
+Universal Time is now:  Tue Jun  2 23:58:06 UTC 2026.
 Run 'dpkg-reconfigure tzdata' if you wish to change it.
 
 Setting up golang-github-coreos-go-semver-dev (0.3.0-1) ...
@@ -3056,7 +3088,11 @@
 Building tag database...
  -> Finished parsing the build-deps
 I: Building the package
-I: Running cd /build/reproducible-path/gitsign-0.13.0/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S  > ../gitsign_0.13.0-1_source.changes
+I: user script /srv/workspace/pbuilder/4060338/tmp/hooks/A99_set_merged_usr starting
+Not re-configuring usrmerge for unstable
+I: user script /srv/workspace/pbuilder/4060338/tmp/hooks/A99_set_merged_usr finished
+hostname: Name or service not known
+I: Running cd /build/reproducible-path/gitsign-0.13.0/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S  > ../gitsign_0.13.0-1_source.changes
 dpkg-buildpackage: info: source package gitsign
 dpkg-buildpackage: info: source version 0.13.0-1
 dpkg-buildpackage: info: source distribution unstable
@@ -3074,87 +3110,87 @@
    dh_autoreconf -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_configure -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_build -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go install -trimpath -v -p 40 github.com/sigstore/gitsign github.com/sigstore/gitsign/cmd/gitsign-credential-cache github.com/sigstore/gitsign/docs/cli github.com/sigstore/gitsign/internal github.com/sigstore/gitsign/internal/attest github.com/sigstore/gitsign/internal/cache github.com/sigstore/gitsign/internal/cache/api github.com/sigstore/gitsign/internal/cache/service github.com/sigstore/gitsign/internal/cert github.com/sigstore/gitsign/internal/commands/attest github.com/sigstore/gitsign/internal/commands/initialize github.com/sigstore/gitsign/internal/commands/root github.com/sigstore/gitsign/internal/commands/show github.com/sigstore/gitsign/internal/commands/verify github.com/sigstore/gitsign/internal/commands/verify-tag github.com/sigstore/gitsign/internal/commands/version github.com/sigstore/gitsign/internal/config github.com/sigstore/gitsign/internal/fork/ietf-cms github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp github.com/sigstore/gitsign/internal/fulcio github.com/sigstore/gitsign/internal/fulcio/fulcioroots github.com/sigstore/gitsign/internal/git github.com/sigstore/gitsign/internal/git/gittest github.com/sigstore/gitsign/internal/gitsign github.com/sigstore/gitsign/internal/gpg github.com/sigstore/gitsign/internal/io github.com/sigstore/gitsign/internal/rekor github.com/sigstore/gitsign/internal/rekor/oid github.com/sigstore/gitsign/internal/signature github.com/sigstore/gitsign/internal/signerverifier github.com/sigstore/gitsign/pkg/fulcio github.com/sigstore/gitsign/pkg/git github.com/sigstore/gitsign/pkg/gitsign github.com/sigstore/gitsign/pkg/predicate github.com/sigstore/gitsign/pkg/rekor github.com/sigstore/gitsign/pkg/version
-unicode/utf8
-cmp
-internal/msan
-vendor/golang.org/x/crypto/internal/alias
+	cd _build && go install -trimpath -v -p 42 github.com/sigstore/gitsign github.com/sigstore/gitsign/cmd/gitsign-credential-cache github.com/sigstore/gitsign/docs/cli github.com/sigstore/gitsign/internal github.com/sigstore/gitsign/internal/attest github.com/sigstore/gitsign/internal/cache github.com/sigstore/gitsign/internal/cache/api github.com/sigstore/gitsign/internal/cache/service github.com/sigstore/gitsign/internal/cert github.com/sigstore/gitsign/internal/commands/attest github.com/sigstore/gitsign/internal/commands/initialize github.com/sigstore/gitsign/internal/commands/root github.com/sigstore/gitsign/internal/commands/show github.com/sigstore/gitsign/internal/commands/verify github.com/sigstore/gitsign/internal/commands/verify-tag github.com/sigstore/gitsign/internal/commands/version github.com/sigstore/gitsign/internal/config github.com/sigstore/gitsign/internal/fork/ietf-cms github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp github.com/sigstore/gitsign/internal/fulcio github.com/sigstore/gitsign/internal/fulcio/fulcioroots github.com/sigstore/gitsign/internal/git github.com/sigstore/gitsign/internal/git/gittest github.com/sigstore/gitsign/internal/gitsign github.com/sigstore/gitsign/internal/gpg github.com/sigstore/gitsign/internal/io github.com/sigstore/gitsign/internal/rekor github.com/sigstore/gitsign/internal/rekor/oid github.com/sigstore/gitsign/internal/signature github.com/sigstore/gitsign/internal/signerverifier github.com/sigstore/gitsign/pkg/fulcio github.com/sigstore/gitsign/pkg/git github.com/sigstore/gitsign/pkg/gitsign github.com/sigstore/gitsign/pkg/predicate github.com/sigstore/gitsign/pkg/rekor github.com/sigstore/gitsign/pkg/version
 internal/coverage/rtcov
-golang.org/x/crypto/internal/alias
+internal/goarch
+internal/goexperiment
 internal/godebugs
+internal/byteorder
+github.com/ProtonMail/go-crypto/internal/byteutil
+vendor/golang.org/x/crypto/internal/alias
+go.opencensus.io/internal/tagencoding
+github.com/go-git/go-git/plumbing/color
+unicode/utf8
+google.golang.org/grpc/serviceconfig
+cmp
+crypto/internal/fips140/alias
+internal/profilerecord
 internal/itoa
+google.golang.org/protobuf/internal/flags
 github.com/pjbgf/sha1cd/internal
-go.opencensus.io
-internal/asan
-internal/goos
-google.golang.org/grpc/serviceconfig
-vendor/golang.org/x/crypto/cryptobyte/asn1
+github.com/aws/aws-sdk-go-v2/internal/sdkio
+image/color
 github.com/pjbgf/sha1cd/ubc
+golang.org/x/crypto/internal/alias
+internal/msan
 internal/nettrace
-unicode/utf16
-github.com/ProtonMail/go-crypto/internal/byteutil
-image/color
+encoding
 log/internal
-internal/profilerecord
-go.opencensus.io/internal/tagencoding
-unicode
-internal/goarch
-google.golang.org/protobuf/internal/flags
-internal/byteorder
-github.com/go-git/go-git/plumbing/color
+golang.org/x/crypto/cryptobyte/asn1
+github.com/awslabs/amazon-ecr-credential-helper/ecr-login/version
+vendor/golang.org/x/crypto/cryptobyte/asn1
+go.opencensus.io
+internal/unsafeheader
 container/list
-internal/goexperiment
-encoding
+internal/asan
+internal/goos
 go.opencensus.io/trace/internal
-internal/unsafeheader
-crypto/internal/fips140/alias
-golang.org/x/crypto/cryptobyte/asn1
+unicode/utf16
 math/bits
-internal/runtime/syscall
-crypto/internal/boring/sig
+unicode
 internal/runtime/atomic
-internal/cpu
+crypto/internal/boring/sig
+internal/abi
+internal/runtime/syscall
 sync/atomic
-github.com/aws/aws-sdk-go-v2/internal/sdkio
-github.com/awslabs/amazon-ecr-credential-helper/ecr-login/version
+internal/cpu
+internal/runtime/math
+github.com/docker/cli/cli/config/types
 github.com/google/go-containerregistry/pkg/v1/types
 github.com/klauspost/compress/internal/cpuinfo
 github.com/klauspost/compress/internal/le
+internal/runtime/sys
 github.com/google/go-containerregistry/pkg/compression
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/common
-go.mongodb.org/mongo-driver/bson/bsonoptions
 go.mongodb.org/mongo-driver/bson/bsontype
-crypto/internal/fips140/subtle
-internal/runtime/sys
+go.mongodb.org/mongo-driver/bson/bsonoptions
 github.com/sigstore/rekor/pkg/pki/identity
 golang.org/x/exp/constraints
-log/slog/internal
+github.com/sigstore/cosign/pkg/types
 go.opentelemetry.io/otel/metric/embedded
-internal/runtime/math
-github.com/transparency-dev/merkle
 go.opentelemetry.io/otel/trace/embedded
-internal/abi
+github.com/transparency-dev/merkle
 github.com/theupdateframework/go-tuf/v0/internal/sets
+log/slog/internal
 k8s.io/apimachinery/pkg/selection
-github.com/sigstore/cosign/pkg/types
 k8s.io/apimachinery/pkg/types
-github.com/docker/cli/cli/config/types
 github.com/google/go-cmp/cmp/internal/flags
 github.com/tink-crypto/tink-go/internal
 github.com/tink-crypto/tink-go/internal/internalapi
 github.com/tink-crypto/tink-go/key
+crypto/internal/fips140/subtle
 github.com/aws/aws-sdk-go/aws/client/metadata
 github.com/googleapis/gax-go/v2/internal
 crypto/internal/fips140deps/byteorder
 internal/chacha8rand
-github.com/pelletier/go-toml/v2/internal/characters
 github.com/golang/groupcache/lru
 google.golang.org/protobuf/internal/set
+github.com/pelletier/go-toml/v2/internal/characters
 golang.org/x/crypto/salsa20/salsa
 golang.org/x/exp/slices
-internal/runtime/exithook
 crypto/internal/fips140deps/cpu
 internal/bytealg
+internal/runtime/exithook
 math
 internal/stringslite
 internal/race
@@ -3164,10 +3200,10 @@
 github.com/aws/aws-sdk-go/internal/sdkmath
 go.opentelemetry.io/otel/internal
 runtime
+iter
+weak
 crypto/subtle
 k8s.io/klog/internal/dbg
-weak
-iter
 internal/reflectlite
 sync
 maps
@@ -3176,811 +3212,811 @@
 sort
 internal/singleflight
 internal/bisect
-google.golang.org/protobuf/internal/pragma
-github.com/josharian/intern
+internal/testlog
 unique
-go.uber.org/zap/internal/pool
+github.com/josharian/intern
+google.golang.org/protobuf/internal/pragma
 log/slog/internal/buffer
-github.com/sigstore/cosign/cmd/cosign/cli/sign/privacy
+go.uber.org/zap/internal/pool
 github.com/aws/aws-sdk-go/internal/sync/singleflight
-internal/testlog
+github.com/sigstore/cosign/cmd/cosign/cli/sign/privacy
 github.com/spf13/viper/internal/encoding
 runtime/cgo
+io
 internal/oserror
 path
 math/rand/v2
-github.com/sassoftware/relic/signers/sigerrors
+strconv
 google.golang.org/grpc/internal/buffer
-github.com/hashicorp/hcl/hcl/strconv
-golang.org/x/crypto/cast5
-io
 vendor/golang.org/x/net/dns/dnsmessage
-strconv
+github.com/sassoftware/relic/signers/sigerrors
+golang.org/x/crypto/cast5
+github.com/hashicorp/hcl/hcl/strconv
 internal/godebug
-bytes
-strings
 syscall
+container/heap
 crypto/internal/randutil
-go.step.sm/crypto/internal/utils/utfbom
+bytes
+internal/saferio
 github.com/google/go-containerregistry/internal/and
-container/heap
+github.com/aws/smithy-go/transport/http/internal/io
 github.com/gogo/protobuf/sortkeys
 golang.org/x/mod/semver
-internal/saferio
+strings
 github.com/aws/aws-sdk-go/internal/sdkio
+github.com/cloudflare/circl/internal/sha3
+go.step.sm/crypto/internal/utils/utfbom
 k8s.io/apimachinery/pkg/util/sets
 hash
-github.com/cloudflare/circl/internal/sha3
-github.com/aws/smithy-go/transport/http/internal/io
-hash/fnv
 hash/adler32
+hash/fnv
 hash/crc32
+crypto/internal/fips140deps/godebug
+math/rand
+crypto
+encoding/base32
 golang.org/x/crypto/openpgp/errors
-github.com/x448/float16
 net/netip
 golang.org/x/crypto/blowfish
-crypto
-encoding/base32
+github.com/x448/float16
 reflect
 github.com/cloudflare/circl/sign
 golang.org/x/crypto/openpgp/s2k
-github.com/aws/smithy-go/io
 vendor/golang.org/x/text/transform
-golang.org/x/text/transform
 github.com/syndtr/goleveldb/leveldb/comparer
-crypto/internal/fips140deps/godebug
-math/rand
+golang.org/x/text/transform
+github.com/aws/smithy-go/io
+google.golang.org/grpc/internal/grpcrand
+golang.org/x/text/runes
 net/http/internal/ascii
 crypto/internal/impl
 github.com/aws/aws-sdk-go-v2/internal/strings
-k8s.io/klog/internal/severity
+crypto/internal/fips140
 net/http/internal/testcert
-github.com/theupdateframework/go-tuf/v0/internal/roles
+bufio
+go/build/constraint
 github.com/munnerz/goautoneg
+k8s.io/klog/internal/severity
+html
 github.com/aws/aws-sdk-go/internal/strings
 github.com/aws/aws-sdk-go/internal/sdkuri
+github.com/theupdateframework/go-tuf/v0/internal/roles
 go.step.sm/crypto/internal/emoji
-go/build/constraint
-bufio
-html
 regexp/syntax
-crypto/internal/fips140
-golang.org/x/text/runes
-crypto/tls/internal/fips140tls
 crypto/internal/fips140/sha256
 crypto/internal/fips140/sha512
 crypto/internal/fips140/sha3
-google.golang.org/grpc/internal/grpcrand
+crypto/tls/internal/fips140tls
 compress/bzip2
 image
 crypto/internal/fips140/hmac
 crypto/sha3
+internal/syscall/execenv
+internal/syscall/unix
+time
+regexp
 crypto/internal/fips140/check
 crypto/internal/fips140hash
-crypto/internal/fips140/edwards25519/field
-crypto/internal/fips140/nistec/fiat
-crypto/internal/fips140/bigmod
+image/internal/imageutil
 crypto/internal/fips140/aes
 crypto/internal/fips140/hkdf
 crypto/internal/fips140/tls12
-crypto/internal/fips140/tls13
-image/internal/imageutil
+crypto/internal/fips140/bigmod
+crypto/internal/fips140/nistec/fiat
+crypto/internal/fips140/edwards25519/field
 image/jpeg
-regexp
+crypto/internal/fips140/tls13
 crypto/internal/fips140/edwards25519
-internal/syscall/execenv
-internal/syscall/unix
-time
 github.com/go-git/go-git/internal/url
 google.golang.org/api/internal/third_party/uritemplates
 k8s.io/apimachinery/pkg/version
-google.golang.org/grpc/backoff
 google.golang.org/grpc/keepalive
 context
+google.golang.org/grpc/backoff
+io/fs
 github.com/aws/aws-sdk-go-v2/internal/timeconv
+github.com/google/go-containerregistry/internal/retry/wait
 github.com/aws/smithy-go/ptr
-github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.1
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.2
-io/fs
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v1
-go.uber.org/zap/buffer
 k8s.io/klog/internal/clock
-k8s.io/utils/clock
+go.uber.org/zap/buffer
+github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.1
+github.com/sigstore/gitsign/pkg/predicate
 github.com/google/go-cmp/cmp/internal/diff
-github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/common
 github.com/jonboulle/clockwork
-github.com/sigstore/gitsign/pkg/predicate
-github.com/google/go-containerregistry/internal/retry/wait
+github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/common
+k8s.io/utils/clock
 github.com/aws/aws-sdk-go/internal/sdkrand
 internal/poll
-crypto/internal/fips140/nistec
 go.uber.org/zap/internal/bufferpool
 k8s.io/utils/clock/testing
 go.uber.org/zap/internal/stacktrace
 google.golang.org/grpc/internal/backoff
+github.com/aws/aws-sdk-go-v2/internal/sdk
 golang.org/x/net/context
-github.com/aws/smithy-go/context
 google.golang.org/grpc/internal/grpcsync
+github.com/aws/smithy-go/context
 go.opentelemetry.io/otel/internal/baggage
-github.com/aws/aws-sdk-go-v2/internal/sdk
 github.com/tink-crypto/tink-go/tink
-github.com/jbenet/go-context/io
-github.com/go-git/go-git/utils/ioutil
+internal/filepathlite
 github.com/spf13/afero/internal/common
 embed
-internal/filepathlite
+github.com/jbenet/go-context/io
+crypto/internal/fips140/nistec
+github.com/go-git/go-git/utils/ioutil
 google.golang.org/protobuf/internal/editiondefaults
+os
 internal/fmtsort
 go.opentelemetry.io/otel/internal/attribute
 github.com/google/go-cmp/cmp/internal/function
-encoding/binary
 sigs.k8s.io/structured-merge-diff/schema
+encoding/binary
 github.com/modern-go/reflect2
-os
 encoding/base64
-github.com/google/gofuzz/bytesource
+github.com/cespare/xxhash
 golang.org/x/crypto/internal/poly1305
-github.com/klauspost/compress/internal/snapref
-filippo.io/edwards25519/field
-github.com/golang/snappy
 vendor/golang.org/x/crypto/internal/poly1305
-github.com/cespare/xxhash
+github.com/klauspost/compress/internal/snapref
+github.com/google/gofuzz/bytesource
 github.com/tink-crypto/tink-go/internal/outputprefix
+github.com/golang/snappy
+filippo.io/edwards25519/field
 golang.org/x/sys/unix
+golang.org/x/crypto/nacl/secretbox
 encoding/pem
 golang.org/x/crypto/openpgp/armor
-golang.org/x/crypto/nacl/secretbox
 filippo.io/edwards25519
 crypto/internal/sysrand
+google.golang.org/protobuf/internal/detrand
+fmt
 io/ioutil
-path/filepath
 vendor/golang.org/x/sys/cpu
-google.golang.org/protobuf/internal/detrand
-github.com/go-git/go-billy/v5
 google.golang.org/grpc/internal/envconfig
-internal/sysinfo
+path/filepath
 go.uber.org/zap/internal/exit
-fmt
 k8s.io/klog/internal/buffer
-golang.org/x/sys/cpu
 internal/lazyregexp
+internal/sysinfo
+github.com/go-git/go-billy/v5
 os/signal
+golang.org/x/sys/cpu
 net
 crypto/internal/entropy
 crypto/internal/fips140/drbg
-golang.org/x/crypto/blake2b
 golang.org/x/crypto/sha3
-crypto/internal/fips140only
+golang.org/x/crypto/blake2b
 crypto/internal/fips140/ecdh
+crypto/internal/fips140only
 crypto/internal/fips140/ed25519
 crypto/internal/fips140/ecdsa
 crypto/internal/fips140/mlkem
-crypto/internal/fips140/rsa
 crypto/internal/fips140/aes/gcm
+crypto/internal/fips140/rsa
 github.com/go-git/go-billy/v5/helper/polyfill
+os/exec
 github.com/shibumi/go-pathspec
-github.com/spf13/afero/mem
-github.com/go-git/go-billy/v5/util
 k8s.io/client-go/util/homedir
-os/exec
+github.com/go-git/go-billy/v5/util
+github.com/spf13/afero/mem
 crypto/rc4
 crypto/md5
 github.com/go-git/go-billy/v5/helper/chroot
-golang.org/x/crypto/argon2
 crypto/cipher
-github.com/mitchellh/go-homedir
+golang.org/x/crypto/argon2
 github.com/skratchdot/open-golang/open
+github.com/mitchellh/go-homedir
+crypto/internal/boring
 vendor/golang.org/x/crypto/chacha20
+github.com/ProtonMail/go-crypto/eax
 crypto/des
-crypto/internal/boring
 golang.org/x/crypto/chacha20
-github.com/ProtonMail/go-crypto/eax
-encoding/hex
 github.com/sigstore/cosign/pkg/cosign/env
 github.com/sigstore/cosign/pkg/providers
+encoding/hex
 log
+crypto/aes
 net/url
-compress/flate
-mime/quotedprintable
 encoding/json
-mime
+crypto/ecdh
+crypto/sha512
+compress/flate
+crypto/hmac
 vendor/golang.org/x/net/http2/hpack
+math/big
+crypto/sha256
+go/token
 net/http/internal
+go.opencensus.io/trace/tracestate
+go.opencensus.io/resource
+go.opencensus.io/internal
+mime
+runtime/trace
 text/tabwriter
+golang.org/x/net/http2/hpack
 os/user
-text/template/parse
-math/big
-google.golang.org/grpc/attributes
-github.com/ProtonMail/go-crypto/openpgp/errors
-vendor/golang.org/x/text/unicode/norm
-github.com/zeebo/errs
-google.golang.org/protobuf/internal/errors
 google.golang.org/protobuf/internal/version
-go/token
+github.com/zeebo/errs
+mime/quotedprintable
+text/template/parse
 google.golang.org/grpc/internal/idle
-github.com/pjbgf/sha1cd
+google.golang.org/grpc/attributes
 google.golang.org/grpc/internal/grpclog
-golang.org/x/net/http2/hpack
-golang.org/x/text/unicode/norm
-go.opencensus.io/trace/tracestate
-runtime/trace
-go.opencensus.io/internal
-go.opencensus.io/resource
-dario.cat/mergo
+google.golang.org/protobuf/internal/errors
 github.com/go-jose/go-jose/json
-crypto/aes
-github.com/sigstore/cosign/pkg/providers/filesystem
-github.com/sigstore/cosign/pkg/providers/envvar
-crypto/ecdh
-crypto/sha512
-crypto/hmac
-crypto/sha256
-google.golang.org/protobuf/encoding/protowire
 crypto/sha1
+dario.cat/mergo
+vendor/golang.org/x/text/unicode/norm
+golang.org/x/text/unicode/norm
+github.com/ProtonMail/go-crypto/openpgp/errors
+github.com/ProtonMail/go-crypto/openpgp/aes/keywrap
+github.com/pjbgf/sha1cd
 encoding/gob
 github.com/src-d/gcfg/token
-github.com/ProtonMail/go-crypto/openpgp/aes/keywrap
-github.com/ProtonMail/go-crypto/openpgp/armor
-vendor/golang.org/x/crypto/chacha20poly1305
 github.com/src-d/gcfg/types
 gopkg.in/warnings.v0
+vendor/golang.org/x/crypto/chacha20poly1305
 github.com/go-git/go-git/internal/revision
-go.opencensus.io/metric/metricdata
-github.com/ProtonMail/go-crypto/ocb
 github.com/go-git/go-git/plumbing/filemode
+google.golang.org/protobuf/encoding/protowire
+github.com/sigstore/cosign/pkg/providers/envvar
+github.com/sigstore/cosign/pkg/providers/filesystem
 github.com/emirpasic/gods/utils
 github.com/go-git/go-git/utils/merkletrie/noder
+golang.org/x/crypto/pbkdf2
+github.com/ProtonMail/go-crypto/ocb
+golang.org/x/crypto/hkdf
 github.com/go-git/go-git/plumbing/protocol/packp/capability
 golang.org/x/sys/execabs
+golang.org/x/crypto/ssh/internal/bcrypt_pbkdf
 runtime/debug
+github.com/ProtonMail/go-crypto/openpgp/armor
 github.com/aws/smithy-go
 github.com/aws/aws-sdk-go-v2/aws/ratelimit
-golang.org/x/crypto/pbkdf2
-golang.org/x/crypto/hkdf
 github.com/aws/aws-sdk-go-v2/feature/ec2/imds/internal/config
-go.opencensus.io/metric/metricproducer
-golang.org/x/crypto/ssh/internal/bcrypt_pbkdf
-github.com/src-d/gcfg/scanner
-google.golang.org/protobuf/reflect/protoreflect
 github.com/aws/smithy-go/encoding
-github.com/go-git/go-git/utils/merkletrie/internal/frame
-github.com/emirpasic/gods/containers
 encoding/xml
+go.opencensus.io/metric/metricdata
 github.com/aws/aws-sdk-go-v2/internal/ini
-github.com/go-git/go-git/plumbing/hash
+github.com/emirpasic/gods/containers
 github.com/pkg/errors
+github.com/opencontainers/go-digest
 github.com/google/go-containerregistry/internal/retry
 github.com/klauspost/compress/fse
-github.com/opencontainers/go-digest
-github.com/opencontainers/image-spec/specs-go
-github.com/containerd/stargz-snapshotter/estargz/errorutil
+github.com/go-git/go-git/utils/merkletrie/internal/frame
+google.golang.org/protobuf/reflect/protoreflect
+golang.org/x/crypto/curve25519
+github.com/src-d/gcfg/scanner
 golang.org/x/net/internal/timeseries
+vendor/golang.org/x/text/unicode/bidi
 golang.org/x/text/unicode/bidi
 github.com/spiffe/go-spiffe/v2/logger
+go.opencensus.io/metric/metricproducer
+github.com/emirpasic/gods/lists
 github.com/go-git/go-git/utils/trace
-vendor/golang.org/x/text/unicode/bidi
-github.com/go-git/go-git/utils/merkletrie
 github.com/aws/smithy-go/logging
-github.com/ProtonMail/go-crypto/openpgp/internal/algorithm
+github.com/emirpasic/gods/trees
+github.com/go-git/go-git/utils/merkletrie
 github.com/google/go-containerregistry/pkg/logs
+github.com/opencontainers/image-spec/specs-go
+github.com/containerd/stargz-snapshotter/estargz/errorutil
 golang.org/x/sync/errgroup
-github.com/go-git/go-git/plumbing
+github.com/aws/smithy-go/auth
 flag
-github.com/emirpasic/gods/lists
 encoding/csv
-github.com/emirpasic/gods/trees
 database/sql/driver
-github.com/aws/smithy-go/middleware
-github.com/spiffe/go-spiffe/v2/spiffeid
-github.com/sergi/go-diff/diffmatchpatch
-golang.org/x/crypto/curve25519
-github.com/aws/smithy-go/auth
-github.com/google/go-containerregistry/internal/redact
-github.com/go-git/go-git/plumbing/format/pktline
-github.com/opencontainers/image-spec/specs-go/v1
 github.com/go-openapi/analysis/internal/debug
-gopkg.in/yaml.v3
-compress/gzip
-compress/zlib
-github.com/go-openapi/jsonreference/internal
 github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer
 go.uber.org/zap/internal/color
 golang.org/x/crypto/scrypt
+gopkg.in/yaml.v3
 github.com/nozzle/throttler
-github.com/ProtonMail/go-crypto/openpgp/s2k
 github.com/sigstore/cosign/internal/pkg/oci/remote
+github.com/opencontainers/image-spec/specs-go/v1
+github.com/go-git/go-git/plumbing/format/pktline
 github.com/sigstore/cosign/internal/ui
 github.com/spf13/jwalterweatherman
+github.com/ProtonMail/go-crypto/openpgp/internal/algorithm
+github.com/go-git/go-git/plumbing/hash
+github.com/spiffe/go-spiffe/v2/spiffeid
+github.com/sergi/go-diff/diffmatchpatch
+github.com/aws/smithy-go/middleware
+github.com/google/go-containerregistry/internal/redact
+github.com/go-openapi/jsonreference/internal
 github.com/subosito/gotenv
 github.com/hashicorp/hcl/hcl/token
-github.com/aws/aws-sdk-go-v2/internal/sync/singleflight
-github.com/go-git/go-git/plumbing/protocol/packp/sideband
-github.com/aws/smithy-go/internal/sync/singleflight
-github.com/sigstore/sigstore-go/pkg/util
-gopkg.in/ini.v1
 github.com/pelletier/go-toml/v2/internal/danger
+gopkg.in/ini.v1
 github.com/go-openapi/runtime/logger
+github.com/go-git/go-git/plumbing
 github.com/opentracing/opentracing-go/log
-runtime/pprof
-github.com/google/go-containerregistry/internal/gzip
-internal/profile
 go.opentelemetry.io/otel/baggage
-github.com/go-git/go-git/utils/sync
 github.com/transparency-dev/merkle/compact
 github.com/transparency-dev/merkle/rfc6962
 github.com/sigstore/cosign/internal/pkg/now
+github.com/go-git/go-git/plumbing/protocol/packp/sideband
+github.com/ProtonMail/go-crypto/openpgp/s2k
+compress/gzip
+compress/zlib
 github.com/theupdateframework/go-tuf/v0/internal/fsutil
-github.com/hashicorp/hcl/hcl/ast
-github.com/hashicorp/hcl/hcl/scanner
-github.com/klauspost/compress/huff0
-github.com/hashicorp/hcl/json/token
-github.com/go-git/go-git/plumbing/cache
-github.com/go-git/go-git/utils/binary
-github.com/go-git/go-git/plumbing/format/diff
-github.com/go-git/go-git/utils/merkletrie/filesystem
 github.com/pelletier/go-toml/v2/unstable
-github.com/syndtr/goleveldb/leveldb/util
 github.com/syndtr/goleveldb/leveldb/storage
-github.com/oklog/ulid
+github.com/syndtr/goleveldb/leveldb/util
 github.com/google/go-querystring/query
-golang.org/x/time/rate
-github.com/hashicorp/hcl/json/scanner
+github.com/klauspost/compress/huff0
+github.com/hashicorp/hcl/hcl/ast
+github.com/hashicorp/hcl/hcl/scanner
+github.com/hashicorp/hcl/json/token
 github.com/transparency-dev/merkle/proof
+github.com/aws/aws-sdk-go-v2/internal/sync/singleflight
+golang.org/x/time/rate
+github.com/aws/smithy-go/internal/sync/singleflight
+github.com/sigstore/sigstore-go/pkg/util
 github.com/google/gofuzz
 k8s.io/apimachinery/third_party/forked/golang/reflect
-vendor/golang.org/x/text/secure/bidirule
-testing
-golang.org/x/text/secure/bidirule
+runtime/pprof
+github.com/google/go-containerregistry/internal/gzip
+internal/profile
 k8s.io/apimachinery/pkg/fields
 k8s.io/apimachinery/pkg/util/errors
+github.com/go-git/go-git/utils/sync
+github.com/hashicorp/hcl/json/scanner
+github.com/oklog/ulid
+github.com/go-git/go-git/plumbing/cache
+golang.org/x/text/secure/bidirule
+github.com/go-git/go-git/utils/binary
+github.com/go-git/go-git/plumbing/format/diff
+github.com/go-git/go-git/utils/merkletrie/filesystem
 go/scanner
-github.com/go-git/go-git/plumbing/format/index
-github.com/go-git/go-git/plumbing/format/idxfile
-k8s.io/apimachinery/pkg/conversion/queryparams
+vendor/golang.org/x/text/secure/bidirule
+github.com/syndtr/goleveldb/leveldb/cache
+github.com/syndtr/goleveldb/leveldb/filter
 go/doc/comment
+testing
+github.com/aws/aws-sdk-go-v2/internal/context
+k8s.io/apimachinery/pkg/conversion/queryparams
+github.com/hashicorp/hcl/hcl/parser
 k8s.io/apimachinery/pkg/util/naming
+github.com/go-git/go-git/plumbing/format/index
+github.com/go-git/go-git/plumbing/format/idxfile
 github.com/modern-go/concurrent
-github.com/hashicorp/hcl/hcl/parser
 sigs.k8s.io/yaml/goyaml.v2
 k8s.io/utils/ptr
-github.com/syndtr/goleveldb/leveldb/cache
 github.com/hashicorp/hcl/json/parser
-github.com/syndtr/goleveldb/leveldb/filter
-github.com/go-git/go-git/utils/diff
-github.com/aws/aws-sdk-go-v2/internal/context
-k8s.io/apimachinery/pkg/util/version
-vendor/golang.org/x/net/idna
 k8s.io/apimachinery/pkg/util/validation/field
-golang.org/x/net/idna
-k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json
-github.com/pelletier/go-toml/v2/internal/tracker
+k8s.io/apimachinery/pkg/util/version
 github.com/aws/aws-sdk-go-v2/internal/middleware
 k8s.io/client-go/pkg/version
+k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json
 github.com/davecgh/go-spew/spew
-text/template
 k8s.io/client-go/tools/metrics
+golang.org/x/net/idna
 k8s.io/client-go/util/flowcontrol
 k8s.io/kube-openapi/pkg/cached
+k8s.io/apimachinery/pkg/conversion
+github.com/syndtr/goleveldb/leveldb/opt
+text/template
+github.com/pelletier/go-toml/v2/internal/tracker
+github.com/go-git/go-git/utils/diff
+go/ast
 github.com/emicklei/go-restful/log
 k8s.io/apimachinery/third_party/forked/golang/json
 github.com/google/go-cmp/cmp/internal/value
+github.com/go-jose/go-jose/v3/json
+gopkg.in/square/go-jose.v2/json
+github.com/common-nighthawk/go-figure
+github.com/sigstore/gitsign/internal/config
+github.com/google/trillian/types/internal/tls
+golang.org/x/sync/singleflight
 github.com/go-git/go-git/plumbing/storer
 github.com/go-git/go-git/utils/merkletrie/index
-github.com/common-nighthawk/go-figure
 google.golang.org/protobuf/internal/encoding/messageset
 google.golang.org/protobuf/internal/genid
+vendor/golang.org/x/net/idna
 google.golang.org/protobuf/internal/order
 google.golang.org/protobuf/internal/strs
 google.golang.org/protobuf/runtime/protoiface
 google.golang.org/protobuf/internal/descfmt
 google.golang.org/protobuf/internal/descopts
-github.com/hashicorp/hcl
 github.com/hashicorp/hcl/hcl/printer
-github.com/syndtr/goleveldb/leveldb/opt
-k8s.io/apimachinery/pkg/conversion
-google.golang.org/protobuf/internal/protolazy
-go/ast
-github.com/go-jose/go-jose/v3/json
 google.golang.org/protobuf/reflect/protoregistry
-github.com/cyphar/filepath-securejoin
-golang.org/x/term
-github.com/go-git/go-git/plumbing/format/packfile
-github.com/fsnotify/fsnotify/internal
-gopkg.in/square/go-jose.v2/json
-github.com/sigstore/gitsign/internal/config
-github.com/google/trillian/types/internal/tls
-golang.org/x/sync/singleflight
+github.com/hashicorp/hcl
+github.com/jellydator/ttlcache
+github.com/syndtr/goleveldb/leveldb/errors
 github.com/aws/aws-sdk-go/aws/awserr
-google.golang.org/protobuf/internal/encoding/text
-google.golang.org/protobuf/internal/encoding/json
 github.com/googleapis/gax-go/v2/callctx
-github.com/syndtr/goleveldb/leveldb/errors
-github.com/google/go-cmp/cmp
-github.com/jellydator/ttlcache
 go.step.sm/crypto/internal/bcrypt_pbkdf
-github.com/fsnotify/fsnotify
-github.com/aws/aws-sdk-go/internal/ini
+google.golang.org/protobuf/internal/protolazy
 github.com/syndtr/goleveldb/leveldb/iterator
 github.com/syndtr/goleveldb/leveldb/journal
+github.com/go-git/go-git/plumbing/format/packfile
 go.step.sm/crypto/internal/utils
 go.step.sm/crypto/fingerprint
 github.com/sigstore/gitsign/pkg/version
-github.com/mattn/go-tty
-github.com/russross/blackfriday/v2
 github.com/sigstore/gitsign/internal/cache/api
-github.com/aws/aws-sdk-go-v2/aws/protocol/xml
-google.golang.org/grpc/grpclog
+github.com/russross/blackfriday/v2
+github.com/google/go-cmp/cmp
+github.com/aws/aws-sdk-go/internal/ini
+google.golang.org/protobuf/internal/encoding/json
+google.golang.org/protobuf/internal/encoding/text
+golang.org/x/term
+github.com/cyphar/filepath-securejoin
+github.com/fsnotify/fsnotify/internal
+github.com/mattn/go-tty
 github.com/emirpasic/gods/lists/arraylist
 github.com/aws/aws-sdk-go-v2/aws/middleware/private/metrics
+google.golang.org/grpc/grpclog
 github.com/aws/aws-sdk-go-v2/aws/protocol/restjson
 github.com/jmespath/go-jmespath
-google.golang.org/protobuf/proto
-github.com/sirupsen/logrus
-github.com/docker/docker-credential-helpers/credentials
 github.com/secure-systems-lab/go-securesystemslib/cjson
+github.com/docker/docker-credential-helpers/credentials
 github.com/google/go-containerregistry/pkg/v1
+github.com/sirupsen/logrus
 github.com/mailru/easyjson/jlexer
+github.com/aws/aws-sdk-go-v2/aws/protocol/xml
 github.com/blang/semver
+go.uber.org/atomic
+log/slog
+github.com/spf13/viper/internal/encoding/hcl
+google.golang.org/protobuf/proto
+github.com/spf13/viper/internal/encoding/json
+github.com/pelletier/go-toml/v2
+go.opentelemetry.io/otel/attribute
+go.opentelemetry.io/otel/codes
+github.com/fsnotify/fsnotify
+github.com/theupdateframework/go-tuf/v0/data
+github.com/syndtr/goleveldb/leveldb/memdb
+github.com/syndtr/goleveldb/leveldb/table
+github.com/emirpasic/gods/trees/binaryheap
+github.com/gogo/protobuf/proto
+sigs.k8s.io/json/internal/golang/encoding/json
+github.com/docker/docker-credential-helpers/client
+go.opencensus.io/tag
+k8s.io/apimachinery/pkg/util/dump
+k8s.io/apimachinery/pkg/util/framer
 crypto/rand
 crypto/elliptic
-crypto/internal/boring/bbig
 encoding/asn1
 crypto/dsa
-go.opencensus.io/tag
+crypto/internal/boring/bbig
+google.golang.org/grpc/connectivity
+google.golang.org/protobuf/internal/encoding/defval
 github.com/ProtonMail/go-crypto/openpgp/internal/encoding
-github.com/go-git/go-billy/v5/osfs
-github.com/aws/smithy-go/time
-github.com/aws/smithy-go/document
-github.com/aws/smithy-go/encoding/json
-github.com/aws/smithy-go/encoding/xml
-github.com/emirpasic/gods/trees/binaryheap
 crypto/ed25519
 crypto/internal/hpke
 crypto/rsa
 go.opencensus.io/trace
 github.com/cloudflare/circl/math
-github.com/ProtonMail/go-crypto/openpgp/elgamal
 github.com/aws/aws-sdk-go-v2/internal/rand
-google.golang.org/grpc/connectivity
+github.com/ProtonMail/go-crypto/openpgp/elgamal
+github.com/aws/smithy-go/time
 github.com/aws/smithy-go/rand
-google.golang.org/protobuf/internal/encoding/defval
+github.com/aws/smithy-go/document
+github.com/aws/smithy-go/encoding/json
+github.com/aws/smithy-go/encoding/xml
+github.com/docker/cli/cli/config/credentials
+github.com/google/go-containerregistry/internal/verify
+github.com/klauspost/compress/zstd
+github.com/google/go-containerregistry/pkg/v1/match
+github.com/google/go-containerregistry/pkg/v1/stream
+github.com/src-d/gcfg
+go.opencensus.io/stats/internal
 github.com/aws/aws-sdk-go-v2/service/sso/types
 github.com/aws/aws-sdk-go-v2/service/ssooidc/types
 github.com/aws/aws-sdk-go-v2/service/sts/types
-go.opencensus.io/stats/internal
+go.opencensus.io/stats
+github.com/go-git/go-git/plumbing/format/objfile
+github.com/go-git/go-git/internal/path_util
 github.com/aws/aws-sdk-go-v2/service/ecr/types
-github.com/aws/aws-sdk-go-v2/service/ecrpublic/types
-github.com/docker/docker-credential-helpers/client
+github.com/kevinburke/ssh_config
+github.com/aws/aws-sdk-go-v2/internal/shareddefaults
 github.com/aws/smithy-go/waiter
-go.opencensus.io/stats
-github.com/klauspost/compress/zstd
+github.com/aws/aws-sdk-go-v2/service/ecrpublic/types
+github.com/docker/docker/pkg/homedir
+archive/tar
+go.uber.org/multierr
+google.golang.org/protobuf/internal/filedesc
+google.golang.org/protobuf/encoding/prototext
+github.com/vbatts/tar-split/archive/tar
+html/template
 go.mongodb.org/mongo-driver/bson/primitive
-github.com/google/go-containerregistry/internal/verify
-go.uber.org/atomic
-github.com/google/go-containerregistry/pkg/v1/match
-github.com/google/go-containerregistry/pkg/v1/stream
-golang.org/x/crypto/ed25519
-github.com/secure-systems-lab/go-securesystemslib/encrypted
+github.com/go-git/go-billy/v5/osfs
 github.com/ProtonMail/go-crypto/bitcurves
 github.com/ProtonMail/go-crypto/brainpool
+github.com/awslabs/amazon-ecr-credential-helper/ecr-login/config
+github.com/docker/cli/cli/config/configfile
+golang.org/x/crypto/ed25519
+github.com/secure-systems-lab/go-securesystemslib/encrypted
 golang.org/x/crypto/openpgp/elgamal
 github.com/google/certificate-transparency-go/asn1
-github.com/jedisct1/go-minisign
-log/slog
+golang.org/x/oauth2/jws
 github.com/dustin/go-humanize
-github.com/src-d/gcfg
 github.com/google/go-containerregistry/pkg/v1/static
-html/template
+github.com/sigstore/sigstore/pkg/signature/options
+github.com/jedisct1/go-minisign
 golang.org/x/mod/sumdb/note
+go.opentelemetry.io/otel/metric
+go.uber.org/zap/zapcore
 go.opencensus.io/stats/view
-github.com/sigstore/sigstore/pkg/signature/options
-golang.org/x/oauth2/jws
-github.com/go-git/go-git/plumbing/format/objfile
-github.com/spf13/viper/internal/encoding/hcl
-github.com/spf13/viper/internal/encoding/json
-github.com/pelletier/go-toml/v2
-go.opentelemetry.io/otel/attribute
-go.opentelemetry.io/otel/codes
-github.com/syndtr/goleveldb/leveldb/memdb
-github.com/theupdateframework/go-tuf/v0/data
-github.com/syndtr/goleveldb/leveldb/table
-github.com/docker/cli/cli/config/credentials
+go.opentelemetry.io/otel/trace
+go.opentelemetry.io/otel/semconv/v1.17.0
+github.com/theupdateframework/go-tuf/v0/util
 golang.org/x/crypto/nacl/box
-github.com/spf13/viper/internal/encoding/yaml
+github.com/syndtr/goleveldb/leveldb
 gopkg.in/inf.v0
-github.com/gogo/protobuf/proto
-sigs.k8s.io/json/internal/golang/encoding/json
 github.com/fxamacker/cbor
-go.mongodb.org/mongo-driver/x/bsonx/bsoncore
-github.com/json-iterator/go
-go.uber.org/multierr
-google.golang.org/protobuf/internal/filedesc
-google.golang.org/protobuf/encoding/prototext
-github.com/go-git/go-git/internal/path_util
-github.com/kevinburke/ssh_config
-github.com/aws/aws-sdk-go-v2/internal/shareddefaults
-github.com/awslabs/amazon-ecr-credential-helper/ecr-login/config
-github.com/docker/cli/cli/config/configfile
-github.com/docker/docker/pkg/homedir
 go/doc
-github.com/vbatts/tar-split/archive/tar
-archive/tar
 go/parser
-go.uber.org/zap/zapcore
-github.com/google/gnostic-models/jsonschema
-github.com/theupdateframework/go-tuf/v0/util
-vendor/golang.org/x/crypto/cryptobyte
-github.com/sigstore/cosign/internal/pkg/cosign/payload/size
-crypto/x509/pkix
-golang.org/x/crypto/cryptobyte
-k8s.io/apimachinery/pkg/util/framer
-k8s.io/apimachinery/pkg/util/dump
+github.com/docker/cli/cli/config
 github.com/evanphx/json-patch/v5
+github.com/json-iterator/go
+github.com/spf13/viper/internal/encoding/yaml
+github.com/google/gnostic-models/jsonschema
 github.com/segmentio/ksuid
 github.com/sigstore/sigstore/pkg/oauth
 github.com/tink-crypto/tink-go/subtle/random
-github.com/tink-crypto/tink-go/internal/signature/ecdsa
 github.com/tink-crypto/tink-go/subtle
 github.com/aws/aws-sdk-go-v2/service/kms/types
-go.opentelemetry.io/otel/metric
-go.opentelemetry.io/otel/trace
-go.opentelemetry.io/otel/semconv/v1.17.0
-github.com/aws/aws-sdk-go/internal/shareddefaults
+vendor/golang.org/x/crypto/cryptobyte
+go.mongodb.org/mongo-driver/x/bsonx/bsoncore
+crypto/x509/pkix
+golang.org/x/crypto/cryptobyte
 github.com/go-git/go-git/plumbing/format/config
+github.com/tink-crypto/tink-go/internal/signature/ecdsa
+github.com/sigstore/cosign/internal/pkg/cosign/payload/size
+github.com/aws/aws-sdk-go/internal/shareddefaults
 github.com/aws/aws-sdk-go/aws/awsutil
 github.com/aws/aws-sdk-go/aws/endpoints
 go.step.sm/crypto/x25519
-github.com/docker/cli/cli/config
 go.step.sm/crypto/randutil
-github.com/aws/aws-sdk-go/aws/credentials
-sigs.k8s.io/yaml
 github.com/sigstore/gitsign/internal/io
+github.com/aws/aws-sdk-go/aws/credentials
 github.com/patrickmn/go-cache
 github.com/cpuguy83/go-md2man/v2/md2man
-github.com/google/certificate-transparency-go/x509/pkix
-github.com/syndtr/goleveldb/leveldb
-crypto/ecdsa
-github.com/go-git/go-git/config
-github.com/go-git/go-git/plumbing/format/gitignore
 github.com/go-logr/logr
 k8s.io/klog/internal/sloghandler
-github.com/cloudflare/circl/internal/conv
+sigs.k8s.io/yaml
+github.com/go-git/go-git/config
+github.com/go-git/go-git/plumbing/format/gitignore
+github.com/spf13/viper/internal/encoding/toml
+k8s.io/klog/internal/serialize
+github.com/go-logr/logr/funcr
+github.com/google/certificate-transparency-go/x509/pkix
 github.com/aws/aws-sdk-go/aws/credentials/processcreds
 k8s.io/apimachinery/pkg/util/mergepatch
-github.com/cloudflare/circl/math/fp25519
+github.com/cloudflare/circl/internal/conv
+crypto/ecdsa
+k8s.io/klog
+github.com/go-git/go-git/storage
 github.com/cloudflare/circl/math/mlsbset
 github.com/cloudflare/circl/math/fp448
-k8s.io/klog/internal/serialize
-github.com/go-logr/logr/funcr
-github.com/spf13/viper/internal/encoding/toml
-github.com/go-git/go-git/storage
-k8s.io/klog
-github.com/spf13/cast
+github.com/cloudflare/circl/math/fp25519
 github.com/go-git/go-git/storage/memory
 github.com/go-git/go-git/storage/filesystem/dotgit
+github.com/spf13/cast
+github.com/go-logr/stdr
 github.com/cloudflare/circl/dh/x25519
 github.com/cloudflare/circl/sign/ed25519
-github.com/cloudflare/circl/dh/x448
+go.uber.org/zap/internal
+github.com/go-git/go-git/plumbing/protocol/packp
 github.com/cloudflare/circl/ecc/goldilocks
+github.com/cloudflare/circl/dh/x448
+sigs.k8s.io/json
+github.com/ProtonMail/go-crypto/openpgp/x25519
+k8s.io/apimachinery/pkg/util/json
+github.com/spf13/viper/internal/encoding/dotenv
+github.com/spf13/viper/internal/encoding/ini
+github.com/go-git/go-git/storage/filesystem
 go.mongodb.org/mongo-driver/bson/bsonrw
-github.com/go-logr/stdr
+github.com/ProtonMail/go-crypto/openpgp/ed25519
+k8s.io/apimachinery/pkg/util/yaml
 github.com/spiffe/go-spiffe/v2/internal/cryptoutil
 github.com/go-jose/go-jose/cipher
-github.com/go-jose/go-jose/v3/cipher
-golang.org/x/crypto/openpgp/packet
 github.com/google/certificate-transparency-go/tls
+github.com/go-jose/go-jose/v3/cipher
 gopkg.in/square/go-jose.v2/cipher
-go.uber.org/zap/internal
+golang.org/x/crypto/openpgp/packet
 github.com/tink-crypto/tink-go/signature/subtle
-github.com/go-git/go-git/plumbing/protocol/packp
 google.golang.org/protobuf/internal/encoding/tag
 google.golang.org/protobuf/encoding/protojson
 github.com/spiffe/go-spiffe/v2/internal/jwtutil
-github.com/ProtonMail/go-crypto/openpgp/x25519
-github.com/spf13/viper/internal/encoding/dotenv
-github.com/spf13/viper/internal/encoding/ini
-google.golang.org/protobuf/internal/impl
-sigs.k8s.io/json
-github.com/ProtonMail/go-crypto/openpgp/ed25519
-github.com/go-git/go-git/storage/filesystem
-k8s.io/apimachinery/pkg/util/json
 github.com/cloudflare/circl/sign/ed448
-k8s.io/apimachinery/pkg/util/yaml
-github.com/ProtonMail/go-crypto/openpgp/ed448
+github.com/go-git/go-git/plumbing/transport
+google.golang.org/protobuf/internal/impl
 github.com/ProtonMail/go-crypto/openpgp/x448
+github.com/ProtonMail/go-crypto/openpgp/ed448
 github.com/ProtonMail/go-crypto/openpgp/internal/ecc
-github.com/go-git/go-git/plumbing/transport
 github.com/go-git/go-git/plumbing/transport/internal/common
 github.com/google/go-containerregistry/internal/zstd
 github.com/containerd/stargz-snapshotter/estargz
-golang.org/x/crypto/openpgp
-k8s.io/apimachinery/pkg/runtime/serializer/cbor/internal/modes
-github.com/ProtonMail/go-crypto/openpgp/ecdsa
-github.com/ProtonMail/go-crypto/openpgp/ecdh
-github.com/ProtonMail/go-crypto/openpgp/eddsa
 github.com/google/go-containerregistry/internal/compression
+github.com/ProtonMail/go-crypto/openpgp/eddsa
+github.com/ProtonMail/go-crypto/openpgp/ecdh
+github.com/ProtonMail/go-crypto/openpgp/ecdsa
 github.com/google/go-containerregistry/pkg/v1/partial
 github.com/ProtonMail/go-crypto/openpgp/packet
+k8s.io/apimachinery/pkg/runtime/serializer/cbor/internal/modes
+golang.org/x/crypto/openpgp
+github.com/google/go-containerregistry/pkg/v1/empty
 sigs.k8s.io/structured-merge-diff/value
 go.mongodb.org/mongo-driver/bson/bsoncodec
-github.com/google/go-containerregistry/pkg/v1/empty
 k8s.io/apimachinery/pkg/runtime/serializer/cbor/direct
-vendor/golang.org/x/net/http/httpproxy
-google.golang.org/grpc/internal
-net/textproto
 google.golang.org/grpc/internal/resolver/dns/internal
+vendor/golang.org/x/net/http/httpproxy
 github.com/go-git/go-git/plumbing/transport/git
+google.golang.org/grpc/internal
 golang.org/x/net/internal/socks
-github.com/google/go-containerregistry/pkg/name
+k8s.io/client-go/util/connrotation
+google.golang.org/grpc/internal/syscall
+k8s.io/utils/internal/third_party/forked/golang/net
 crypto/x509
 github.com/mitchellh/mapstructure
-github.com/google/uuid
-google.golang.org/grpc/internal/syscall
+net/textproto
 github.com/mailru/easyjson/buffer
+github.com/google/go-containerregistry/pkg/name
+github.com/google/uuid
 github.com/google/certificate-transparency-go/x509
 github.com/spf13/pflag
-k8s.io/utils/internal/third_party/forked/golang/net
-k8s.io/client-go/util/connrotation
 k8s.io/utils/net
 github.com/mailru/easyjson/jwriter
 google.golang.org/grpc/metadata
 google.golang.org/grpc/codes
-sigs.k8s.io/structured-merge-diff/fieldpath
-github.com/sigstore/sigstore/pkg/signature/payload
-github.com/google/go-containerregistry/pkg/authn
 golang.org/x/net/proxy
-google.golang.org/grpc/internal/balancerload
-google.golang.org/grpc/tap
-google.golang.org/grpc/stats
-google.golang.org/grpc/internal/grpcutil
-github.com/ProtonMail/go-crypto/openpgp
+github.com/google/go-containerregistry/pkg/authn
+github.com/sigstore/sigstore/pkg/signature/payload
 vendor/golang.org/x/net/http/httpguts
 golang.org/x/net/http/httpguts
-mime/multipart
 net/mail
+mime/multipart
+google.golang.org/grpc/internal/balancerload
+google.golang.org/grpc/internal/grpcutil
+google.golang.org/grpc/stats
+google.golang.org/grpc/tap
 k8s.io/apimachinery/pkg/util/validation
 google.golang.org/grpc/encoding
 github.com/google/go-containerregistry/pkg/authn/github
 k8s.io/apimachinery/pkg/labels
-github.com/go-git/go-git/plumbing/object
-k8s.io/apimachinery/pkg/api/resource
 k8s.io/apimachinery/pkg/runtime/schema
 k8s.io/apimachinery/pkg/util/intstr
-go.mongodb.org/mongo-driver/bson
-github.com/google/go-containerregistry/internal/estargz
-sigs.k8s.io/structured-merge-diff/typed
-github.com/google/go-containerregistry/pkg/v1/tarball
+k8s.io/apimachinery/pkg/api/resource
+github.com/ProtonMail/go-crypto/openpgp
+sigs.k8s.io/structured-merge-diff/fieldpath
+github.com/go-git/go-git/plumbing/object
 github.com/spf13/cobra
-github.com/google/certificate-transparency-go
+github.com/google/go-containerregistry/internal/estargz
 github.com/spiffe/go-spiffe/v2/internal/pemutil
-github.com/go-jose/go-jose/v3
-github.com/go-jose/go-jose
 github.com/spiffe/go-spiffe/v2/internal/x509util
-github.com/asaskevich/govalidator
-gopkg.in/square/go-jose.v2
+k8s.io/client-go/util/keyutil
 github.com/sigstore/gitsign/internal
 github.com/github/smimesign/ietf-cms/oid
-github.com/secure-systems-lab/go-securesystemslib/signerverifier
-k8s.io/client-go/util/keyutil
-crypto/tls
-github.com/digitorus/pkcs7
 github.com/theupdateframework/go-tuf/v0/pkg/keys
-golang.org/x/crypto/ssh
 github.com/sigstore/sigstore/pkg/cryptoutils
-github.com/google/certificate-transparency-go/gossip/minimal/x509ext
-github.com/sigstore/cosign/pkg/cosign/fulcioverifier/ctutil
-github.com/google/go-containerregistry/pkg/v1/mutate
-github.com/sigstore/gitsign/internal/gpg
+github.com/digitorus/pkcs7
+github.com/asaskevich/govalidator
+github.com/go-jose/go-jose
+github.com/google/certificate-transparency-go
+gopkg.in/square/go-jose.v2
+golang.org/x/crypto/ssh
+crypto/tls
+github.com/go-jose/go-jose/v3
+github.com/secure-systems-lab/go-securesystemslib/signerverifier
+github.com/google/go-containerregistry/pkg/v1/tarball
 github.com/spiffe/go-spiffe/v2/bundle/x509bundle
 github.com/github/smimesign/ietf-cms/protocol
+github.com/sigstore/gitsign/internal/gpg
+go.mongodb.org/mongo-driver/bson
 github.com/spiffe/go-spiffe/v2/svid/x509svid
 github.com/sigstore/sigstore-go/pkg/fulcio/certificate
-github.com/google/go-containerregistry/pkg/v1/layout
-github.com/go-git/go-git/plumbing/revlist
-github.com/sigstore/gitsign/internal/git/gittest
-github.com/go-git/go-git/plumbing/transport/server
-sigs.k8s.io/structured-merge-diff/merge
-k8s.io/client-go/applyconfigurations/internal
+sigs.k8s.io/structured-merge-diff/typed
+github.com/sigstore/cosign/pkg/cosign/fulcioverifier/ctutil
+github.com/google/certificate-transparency-go/gossip/minimal/x509ext
+github.com/google/go-containerregistry/pkg/v1/mutate
 github.com/digitorus/timestamp
 github.com/theupdateframework/go-tuf/v0/internal/signer
 github.com/theupdateframework/go-tuf/v0/verify
 github.com/theupdateframework/go-tuf/v0/sign
-github.com/sigstore/timestamp-authority/pkg/verification
-github.com/go-git/go-git/plumbing/transport/file
-sigs.k8s.io/release-utils/version
 github.com/sigstore/gitsign/internal/commands/version
+sigs.k8s.io/release-utils/version
 github.com/spf13/cobra/doc
+github.com/go-git/go-git/plumbing/revlist
+github.com/sigstore/gitsign/internal/git/gittest
+github.com/sigstore/timestamp-authority/pkg/verification
 github.com/theupdateframework/go-tuf/v0/pkg/targets
+github.com/google/go-containerregistry/pkg/v1/layout
+github.com/go-git/go-git/plumbing/transport/server
 github.com/theupdateframework/go-tuf/v0
+github.com/go-jose/go-jose/v3/jwt
 github.com/spiffe/go-spiffe/v2/bundle/jwtbundle
 github.com/go-jose/go-jose/jwt
-google.golang.org/protobuf/internal/filetype
-github.com/go-jose/go-jose/v3/jwt
+github.com/go-git/go-git/plumbing/transport/file
 github.com/spiffe/go-spiffe/v2/bundle/spiffebundle
+sigs.k8s.io/structured-merge-diff/merge
+k8s.io/client-go/applyconfigurations/internal
 github.com/spiffe/go-spiffe/v2/svid/jwtsvid
+google.golang.org/protobuf/internal/filetype
 google.golang.org/protobuf/runtime/protoimpl
-google.golang.org/protobuf/types/known/durationpb
+google.golang.org/protobuf/protoadapt
 google.golang.org/protobuf/types/known/timestamppb
+google.golang.org/protobuf/types/known/durationpb
 google.golang.org/protobuf/types/known/anypb
-github.com/sigstore/protobuf-specs/gen/pb-go/dsse
 google.golang.org/protobuf/types/known/structpb
-github.com/tink-crypto/tink-go/proto/ed25519_go_proto
+github.com/sigstore/protobuf-specs/gen/pb-go/dsse
+github.com/tink-crypto/tink-go/proto/common_go_proto
 google.golang.org/genproto/googleapis/rpc/code
 google.golang.org/protobuf/types/known/fieldmaskpb
 github.com/tink-crypto/tink-go/proto/tink_go_proto
-github.com/tink-crypto/tink-go/proto/common_go_proto
-google.golang.org/protobuf/protoadapt
+github.com/tink-crypto/tink-go/proto/ed25519_go_proto
 google.golang.org/protobuf/types/descriptorpb
-google.golang.org/grpc/internal/pretty
 google.golang.org/grpc/encoding/proto
-github.com/golang/protobuf/ptypes/timestamp
-github.com/google/certificate-transparency-go/client/configpb
+google.golang.org/grpc/internal/pretty
 github.com/golang/protobuf/ptypes/duration
 google.golang.org/genproto/googleapis/rpc/errdetails
-github.com/tink-crypto/tink-go/proto/ecdsa_go_proto
 google.golang.org/genproto/googleapis/rpc/status
 github.com/google/gnostic-models/extensions
 github.com/googleapis/gax-go/v2/apierror/internal/proto
+github.com/tink-crypto/tink-go/proto/ecdsa_go_proto
+github.com/golang/protobuf/ptypes/timestamp
+github.com/google/certificate-transparency-go/client/configpb
 github.com/tink-crypto/tink-go/core/cryptofmt
 github.com/tink-crypto/tink-go/core/registry
 github.com/in-toto/attestation/go/v1
-google.golang.org/grpc/binarylog/grpc_binarylog_v1
 github.com/tink-crypto/tink-go/internal/primitiveset
-google.golang.org/grpc/internal/status
+google.golang.org/grpc/binarylog/grpc_binarylog_v1
 github.com/tink-crypto/tink-go/internal/protoserialization
 github.com/tink-crypto/tink-go/internal/registryconfig
+google.golang.org/grpc/internal/status
+golang.org/x/crypto/ssh/knownhosts
+github.com/secure-systems-lab/go-securesystemslib/dsse
+go.step.sm/crypto/keyutil
+golang.org/x/crypto/ssh/agent
 google.golang.org/grpc/status
 github.com/tink-crypto/tink-go/keyset
+github.com/in-toto/in-toto-golang/in_toto
+go.step.sm/crypto/pemutil
+github.com/skeema/knownhosts
 google.golang.org/grpc/internal/binarylog
 github.com/tink-crypto/tink-go/insecurecleartextkeyset
-golang.org/x/crypto/ssh/knownhosts
-github.com/secure-systems-lab/go-securesystemslib/dsse
-golang.org/x/crypto/ssh/agent
-go.step.sm/crypto/keyutil
+github.com/xanzy/ssh-agent
 google.golang.org/protobuf/internal/editionssupport
 google.golang.org/protobuf/types/gofeaturespb
 google.golang.org/genproto/googleapis/api/annotations
 github.com/sigstore/rekor/pkg/signer/tink
-go.step.sm/crypto/pemutil
-github.com/skeema/knownhosts
-github.com/in-toto/in-toto-golang/in_toto
+github.com/go-git/go-git/plumbing/transport/ssh
 google.golang.org/protobuf/reflect/protodesc
 github.com/sigstore/protobuf-specs/gen/pb-go/common/v1
-github.com/xanzy/ssh-agent
-github.com/go-git/go-git/plumbing/transport/ssh
+github.com/sigstore/cosign/pkg/cosign/attestation
 github.com/sigstore/protobuf-specs/gen/pb-go/rekor/v1
 github.com/sigstore/protobuf-specs/gen/pb-go/trustroot/v1
 github.com/sigstore/sigstore/pkg/signature
-github.com/sigstore/protobuf-specs/gen/pb-go/bundle/v1
 net/http/httptrace
 google.golang.org/api/transport/cert
 google.golang.org/grpc/internal/credentials
 k8s.io/client-go/util/cert
 github.com/coreos/go-systemd/activation
 github.com/sassoftware/relic/lib/x509tools
-github.com/golang/protobuf/proto
+github.com/sigstore/protobuf-specs/gen/pb-go/bundle/v1
 net/http
 google.golang.org/grpc/credentials
-github.com/sigstore/cosign/pkg/cosign/attestation
+github.com/golang/protobuf/proto
 google.golang.org/grpc/credentials/insecure
 google.golang.org/grpc/peer
 google.golang.org/grpc/resolver
 google.golang.org/grpc/internal/channelz
 github.com/sigstore/rekor/pkg/pki/minisign
 github.com/sigstore/rekor/pkg/pki/x509
-github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/encoding
-github.com/sigstore/cosign/pkg/cosign/pivkey
 github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/internal/signerverifier
 github.com/sigstore/gitsign/internal/signerverifier
-github.com/sigstore/sigstore/pkg/signature/dsse
+github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/encoding
+github.com/sigstore/cosign/pkg/cosign/pivkey
 github.com/sigstore/cosign/pkg/cosign/pkcs11key
+github.com/sigstore/sigstore/pkg/signature/dsse
 github.com/theupdateframework/go-tuf/metadata
-github.com/sassoftware/relic/lib/pkcs7
 github.com/sigstore/sigstore/pkg/signature/kms/cliplugin
 google.golang.org/grpc/internal/metadata
-google.golang.org/grpc/internal/resolver/passthrough
-google.golang.org/grpc/internal/transport/networktype
 google.golang.org/grpc/balancer/grpclb/state
+google.golang.org/grpc/internal/transport/networktype
+google.golang.org/grpc/internal/resolver/passthrough
+github.com/sassoftware/relic/lib/pkcs7
 google.golang.org/grpc/internal/resolver/unix
 google.golang.org/grpc/internal/resolver/dns
 github.com/sigstore/sigstore/pkg/signature/kms
@@ -3996,493 +4032,493 @@
 google.golang.org/grpc/internal/balancer/gracefulswitch
 go.opencensus.io/trace/propagation
 cloud.google.com/go/compute/metadata
-golang.org/x/oauth2/internal
 google.golang.org/api/googleapi/transport
-github.com/aws/smithy-go/endpoints
-github.com/go-git/go-git/plumbing/transport/http
-github.com/docker/distribution/registry/client/auth/challenge
+golang.org/x/oauth2/internal
 golang.org/x/net/trace
+github.com/go-git/go-git/plumbing/transport/http
 net/http/httputil
 github.com/aws/smithy-go/encoding/httpbinding
+github.com/aws/smithy-go/endpoints
+github.com/docker/distribution/registry/client/auth/challenge
 expvar
-github.com/go-openapi/errors
-net/http/pprof
 github.com/sigstore/rekor/pkg/pki/pgp
+net/http/pprof
 github.com/sigstore/cosign/pkg/blob
-net/http/httptest
-github.com/go-chi/chi
-github.com/theupdateframework/go-tuf/v0/client
+github.com/go-openapi/errors
 github.com/sigstore/rekor/pkg/pki/ssh
+github.com/google/certificate-transparency-go/x509util
+github.com/go-chi/chi
 github.com/theupdateframework/go-tuf/metadata/fetcher
-github.com/go-openapi/runtime/middleware/denco
+github.com/sigstore/cosign/pkg/providers/github
+github.com/sigstore/rekor/pkg/util
 github.com/go-openapi/swag
+go.uber.org/zap
+golang.org/x/net/http2
 github.com/go-openapi/runtime/middleware/header
-github.com/sigstore/cosign/pkg/providers/github
-github.com/google/certificate-transparency-go/x509util
 github.com/magiconair/properties
-github.com/sigstore/fulcio/pkg/api
-github.com/google/gnostic-models/compiler
-go.opentelemetry.io/otel/propagation
-golang.org/x/net/http2
-go.uber.org/zap
-github.com/emicklei/go-restful
+github.com/sigstore/cosign/internal/pkg/cosign/tsa/client
+github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp
 golang.org/x/net/context/ctxhttp
-github.com/opentracing/opentracing-go
-github.com/spf13/afero
-k8s.io/apimachinery/pkg/util/runtime
+go.opentelemetry.io/otel/propagation
 go.opentelemetry.io/otel/semconv/internal/v2
+github.com/spf13/afero
 github.com/hashicorp/go-cleanhttp
-github.com/sigstore/rekor/pkg/util
-github.com/google/go-github/github
-github.com/sigstore/cosign/internal/pkg/cosign/tsa/client
-github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp
+k8s.io/apimachinery/pkg/util/runtime
+github.com/theupdateframework/go-tuf/v0/client
+net/http/httptest
+github.com/go-openapi/runtime/middleware/denco
+github.com/opentracing/opentracing-go
+github.com/sigstore/fulcio/pkg/api
+github.com/emicklei/go-restful
+github.com/google/gnostic-models/compiler
 github.com/aws/aws-sdk-go/aws
+github.com/google/go-github/github
+google.golang.org/api/googleapi
+github.com/theupdateframework/go-tuf/metadata/config
 go.opencensus.io/plugin/ochttp/propagation/b3
 google.golang.org/api/transport/http/internal/propagation
-github.com/theupdateframework/go-tuf/metadata/config
-github.com/google/certificate-transparency-go/jsonclient
-google.golang.org/api/googleapi
+github.com/theupdateframework/go-tuf/metadata/updater
 net/rpc
 k8s.io/apimachinery/pkg/runtime
+github.com/google/certificate-transparency-go/jsonclient
 k8s.io/client-go/features
-github.com/hashicorp/go-retryablehttp
 k8s.io/apimachinery/pkg/util/wait
-k8s.io/client-go/util/workqueue
-go.opentelemetry.io/otel/internal/global
-github.com/theupdateframework/go-tuf/metadata/updater
+github.com/hashicorp/go-retryablehttp
 go.opencensus.io/plugin/ochttp
-github.com/opentracing/opentracing-go/ext
-github.com/sigstore/rekor/pkg/pki
-github.com/go-openapi/strfmt
+k8s.io/client-go/util/workqueue
 golang.org/x/oauth2
 github.com/sigstore/gitsign/internal/fork/ietf-cms
+go.opentelemetry.io/otel/internal/global
+github.com/sigstore/rekor/pkg/pki
+github.com/opentracing/opentracing-go/ext
 github.com/googleapis/gax-go/v2/apierror
-github.com/go-git/go-git/plumbing/transport/client
+github.com/go-openapi/strfmt
 github.com/google/gnostic-models/openapiv3
 github.com/google/gnostic-models/openapiv2
 go.opentelemetry.io/otel/semconv/v1.17.0/httpconv
+github.com/go-git/go-git/plumbing/transport/client
 github.com/theupdateframework/go-tuf/v0/client/leveldbstore
 github.com/google/certificate-transparency-go/client
-github.com/google/certificate-transparency-go/loglist3
-github.com/go-git/go-git
-github.com/sigstore/sigstore/pkg/tuf
-github.com/aws/smithy-go/transport/http
-github.com/spf13/viper/internal/encoding/javaproperties
-github.com/google/go-containerregistry/pkg/v1/remote/transport
-github.com/go-chi/chi/middleware
 github.com/aws/aws-sdk-go/aws/auth/bearer
 github.com/aws/aws-sdk-go/aws/request
+github.com/aws/smithy-go/transport/http
+github.com/go-git/go-git
+github.com/google/go-containerregistry/pkg/v1/remote/transport
 golang.org/x/oauth2/authhandler
 golang.org/x/oauth2/google/internal/impersonate
 golang.org/x/oauth2/google/internal/stsexchange
 golang.org/x/oauth2/jwt
 google.golang.org/api/internal/impersonate
+github.com/google/certificate-transparency-go/loglist3
 github.com/coreos/go-oidc/v3/oidc
-gitlab.com/gitlab-org/api/client-go
-github.com/google/certificate-transparency-go/ctutil
-golang.org/x/oauth2/google/externalaccount
+github.com/sigstore/sigstore/pkg/tuf
+github.com/spf13/viper/internal/encoding/javaproperties
 golang.org/x/oauth2/google/internal/externalaccountauthorizeduser
+github.com/go-chi/chi/middleware
+golang.org/x/oauth2/google/externalaccount
+gitlab.com/gitlab-org/api/client-go
 github.com/sigstore/sigstore-go/pkg/tuf
+github.com/google/certificate-transparency-go/ctutil
+github.com/google/go-containerregistry/pkg/v1/remote
+github.com/sigstore/gitsign/internal/cache
 github.com/sigstore/sigstore/pkg/oauthflow
-github.com/sigstore/gitsign/internal/fulcio/fulcioroots
 github.com/sigstore/sigstore/pkg/fulcioroots
-github.com/google/go-containerregistry/pkg/v1/remote
+github.com/sigstore/gitsign/internal/fulcio/fulcioroots
 github.com/aws/smithy-go/auth/bearer
 github.com/aws/aws-sdk-go-v2/internal/auth
 github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn
-github.com/aws/aws-sdk-go-v2/aws/protocol/query
 github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding
 github.com/aws/smithy-go/private/requestcompression
+github.com/aws/aws-sdk-go-v2/aws/protocol/query
+github.com/spf13/viper
 go.opentelemetry.io/otel
 github.com/sigstore/cosign/internal/pkg/cosign/fulcio/fulcioroots
-github.com/sigstore/gitsign/internal/cache
-github.com/aws/aws-sdk-go-v2/aws
-golang.org/x/oauth2/google
-github.com/spf13/viper
-github.com/sigstore/rekor/pkg/log
-github.com/sigstore/sigstore-go/pkg/root
-github.com/go-openapi/jsonpointer
-github.com/aws/aws-sdk-go/aws/client
 github.com/aws/aws-sdk-go/aws/corehandlers
+github.com/aws/aws-sdk-go/aws/client
 github.com/aws/aws-sdk-go/aws/csm
+github.com/sigstore/sigstore-go/pkg/root
 github.com/aws/aws-sdk-go/private/protocol
-github.com/go-openapi/runtime
-github.com/sigstore/gitsign/pkg/fulcio
-k8s.io/apimachinery/pkg/runtime/serializer/recognizer
-k8s.io/apimachinery/pkg/runtime/serializer/streaming
-k8s.io/client-go/tools/clientcmd/api
+github.com/go-openapi/jsonpointer
+github.com/aws/aws-sdk-go-v2/aws
+golang.org/x/oauth2/google
+github.com/sigstore/rekor/pkg/log
 github.com/aws/aws-sdk-go/aws/ec2metadata
-k8s.io/apimachinery/pkg/runtime/serializer/json
-github.com/sigstore/gitsign/internal/fulcio
 github.com/go-openapi/jsonreference
+github.com/sigstore/gitsign/pkg/fulcio
 github.com/aws/aws-sdk-go/private/protocol/rest
-github.com/aws/aws-sdk-go/private/protocol/query/queryutil
-github.com/aws/aws-sdk-go/private/protocol/json/jsonutil
 github.com/aws/aws-sdk-go/private/protocol/xml/xmlutil
+github.com/aws/aws-sdk-go/private/protocol/json/jsonutil
+github.com/aws/aws-sdk-go/private/protocol/query/queryutil
 github.com/google/go-containerregistry/pkg/v1/google
-k8s.io/kube-openapi/pkg/internal
 github.com/go-openapi/spec
-github.com/sigstore/gitsign/internal/commands/show
-github.com/sigstore/gitsign/internal/cache/service
-k8s.io/client-go/tools/clientcmd/api/v1
-github.com/aws/aws-sdk-go-v2/aws/middleware
+k8s.io/kube-openapi/pkg/internal
+github.com/sigstore/gitsign/internal/fulcio
+github.com/go-openapi/runtime
 github.com/aws/aws-sdk-go-v2/credentials
 github.com/aws/aws-sdk-go-v2/credentials/processcreds
 github.com/aws/aws-sdk-go-v2/aws/defaults
 github.com/aws/aws-sdk-go-v2/aws/signer/internal/v4
 github.com/aws/aws-sdk-go-v2/internal/configsources
 github.com/aws/aws-sdk-go-v2/internal/endpoints
+github.com/aws/aws-sdk-go-v2/aws/middleware
 github.com/aws/aws-sdk-go-v2/internal/endpoints/v2
 github.com/awslabs/amazon-ecr-credential-helper/ecr-login/cache
-github.com/sigstore/gitsign/cmd/gitsign-credential-cache
 github.com/aws/aws-sdk-go/aws/credentials/ec2rolecreds
-github.com/go-openapi/runtime/security
-github.com/go-openapi/runtime/yamlpc
 github.com/aws/aws-sdk-go/aws/credentials/endpointcreds
+github.com/aws/aws-sdk-go/private/protocol/query
+github.com/sigstore/gitsign/internal/cache/service
+github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints
 github.com/aws/aws-sdk-go-v2/service/ssooidc/internal/endpoints
 github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints
 github.com/aws/aws-sdk-go-v2/service/ecr/internal/endpoints
-github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints
 github.com/aws/aws-sdk-go-v2/service/ecrpublic/internal/endpoints
 github.com/aws/aws-sdk-go-v2/service/kms/internal/endpoints
-github.com/aws/aws-sdk-go/private/protocol/query
-k8s.io/apimachinery/pkg/util/net
 github.com/aws/aws-sdk-go/private/protocol/jsonrpc
-google.golang.org/grpc/internal/transport
 github.com/aws/aws-sdk-go/aws/signer/v4
-github.com/aws/aws-sdk-go/aws/defaults
+k8s.io/apimachinery/pkg/runtime/serializer/streaming
+k8s.io/client-go/tools/clientcmd/api
+k8s.io/apimachinery/pkg/runtime/serializer/recognizer
+github.com/sigstore/gitsign/cmd/gitsign-credential-cache
+k8s.io/apimachinery/pkg/runtime/serializer/json
 github.com/aws/aws-sdk-go-v2/aws/transport/http
 github.com/aws/aws-sdk-go-v2/aws/retry
 github.com/aws/aws-sdk-go-v2/aws/signer/v4
+github.com/aws/aws-sdk-go/aws/defaults
 github.com/aws/aws-sdk-go/private/protocol/restjson
-github.com/aws/aws-sdk-go/service/sso
+github.com/sigstore/gitsign/internal/commands/show
 github.com/aws/aws-sdk-go/service/sts
-github.com/aws/aws-sdk-go/service/ssooidc
+github.com/go-openapi/runtime/security
+github.com/go-openapi/runtime/yamlpc
 github.com/aws/aws-sdk-go/service/kms
+k8s.io/client-go/tools/clientcmd/api/v1
+github.com/aws/aws-sdk-go/service/sso
+github.com/aws/aws-sdk-go/service/ssooidc
 github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client
-github.com/aws/aws-sdk-go-v2/feature/ec2/imds
-k8s.io/apimachinery/pkg/watch
 github.com/aws/aws-sdk-go-v2/internal/auth/smithy
-k8s.io/client-go/transport
 github.com/aws/aws-sdk-go-v2/service/internal/presigned-url
-github.com/aws/aws-sdk-go/service/sts/stsiface
-github.com/aws/aws-sdk-go/service/sso/ssoiface
-github.com/aws/aws-sdk-go/aws/credentials/ssocreds
-github.com/go-openapi/analysis/internal/flatten/normalize
-github.com/go-openapi/analysis/internal/flatten/operations
-github.com/go-openapi/analysis/internal/flatten/schutils
-github.com/go-openapi/analysis/internal/flatten/replace
+github.com/aws/aws-sdk-go-v2/feature/ec2/imds
 github.com/aws/aws-sdk-go-v2/service/sso
 github.com/aws/aws-sdk-go-v2/service/ssooidc
-github.com/aws/aws-sdk-go-v2/service/sts
-github.com/aws/aws-sdk-go/aws/credentials/stscreds
+github.com/aws/aws-sdk-go-v2/service/ecr
 github.com/aws/aws-sdk-go-v2/service/ecrpublic
+github.com/aws/aws-sdk-go-v2/service/sts
 github.com/aws/aws-sdk-go-v2/service/kms
-github.com/aws/aws-sdk-go-v2/service/ecr
-github.com/go-openapi/analysis/internal/flatten/sortref
-github.com/aws/aws-sdk-go-v2/credentials/endpointcreds
-github.com/aws/aws-sdk-go/aws/session
+k8s.io/apimachinery/pkg/util/net
+google.golang.org/grpc/internal/transport
 github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds
+github.com/aws/aws-sdk-go/service/sts/stsiface
+github.com/aws/aws-sdk-go/aws/credentials/stscreds
+k8s.io/apimachinery/pkg/watch
+k8s.io/client-go/transport
+github.com/aws/aws-sdk-go-v2/credentials/endpointcreds
+github.com/aws/aws-sdk-go/service/sso/ssoiface
+github.com/go-openapi/analysis/internal/flatten/normalize
+github.com/go-openapi/analysis/internal/flatten/replace
+github.com/go-openapi/analysis/internal/flatten/schutils
+github.com/go-openapi/analysis/internal/flatten/operations
+github.com/aws/aws-sdk-go/aws/credentials/ssocreds
+github.com/go-openapi/analysis/internal/flatten/sortref
 k8s.io/apimachinery/pkg/apis/meta/v1
+github.com/aws/aws-sdk-go/aws/session
 github.com/go-openapi/analysis
+github.com/aws/aws-sdk-go-v2/credentials/ssocreds
 google.golang.org/grpc
 github.com/go-openapi/loads
-k8s.io/kube-openapi/pkg/util/proto
-k8s.io/kube-openapi/pkg/validation/spec
 github.com/go-openapi/runtime/middleware/untyped
 github.com/go-openapi/validate
-github.com/aws/aws-sdk-go-v2/credentials/ssocreds
-github.com/aws/aws-sdk-go/service/kms/kmsiface
 github.com/aws/aws-sdk-go-v2/credentials/stscreds
-google.golang.org/api/internal
-github.com/spiffe/go-spiffe/v2/proto/spiffe/workload
-github.com/tink-crypto/tink-go-awskms/integration/awskms
-github.com/googleapis/gax-go/v2
-github.com/google/trillian
-k8s.io/kube-openapi/pkg/schemaconv
-k8s.io/kube-openapi/pkg/spec3
+github.com/aws/aws-sdk-go/service/kms/kmsiface
 github.com/aws/aws-sdk-go-v2/config
+k8s.io/kube-openapi/pkg/util/proto
+k8s.io/kube-openapi/pkg/validation/spec
+github.com/tink-crypto/tink-go-awskms/integration/awskms
 github.com/go-openapi/runtime/middleware
 github.com/sigstore/rekor/pkg/generated/models
-google.golang.org/api/internal/gensupport
+google.golang.org/api/internal
+github.com/spiffe/go-spiffe/v2/proto/spiffe/workload
+github.com/google/trillian
+github.com/googleapis/gax-go/v2
 google.golang.org/api/transport/internal/dca
 google.golang.org/api/option
+google.golang.org/api/internal/gensupport
 github.com/spiffe/go-spiffe/v2/workloadapi
+k8s.io/kube-openapi/pkg/schemaconv
+k8s.io/kube-openapi/pkg/spec3
 k8s.io/apimachinery/pkg/api/errors
-k8s.io/apimachinery/pkg/apis/meta/v1/validation
-k8s.io/api/networking/v1alpha1
-k8s.io/api/rbac/v1beta1
-k8s.io/api/rbac/v1alpha1
-k8s.io/api/policy/v1
-k8s.io/apimachinery/pkg/api/equality
+k8s.io/apimachinery/pkg/runtime/serializer/protobuf
 k8s.io/api/apidiscovery/v2
-k8s.io/api/rbac/v1
-k8s.io/api/flowcontrol/v1beta1
-k8s.io/api/flowcontrol/v1beta2
-k8s.io/client-go/pkg/apis/clientauthentication
-k8s.io/api/flowcontrol/v1beta3
-k8s.io/api/policy/v1beta1
 k8s.io/apimachinery/pkg/apis/meta/v1/unstructured
-k8s.io/apimachinery/pkg/runtime/serializer/protobuf
-k8s.io/apimachinery/pkg/api/meta
-k8s.io/api/apiserverinternal/v1alpha1
-k8s.io/api/apidiscovery/v2beta1
-k8s.io/api/admissionregistration/v1
 k8s.io/api/coordination/v1
-k8s.io/api/authorization/v1
-k8s.io/api/flowcontrol/v1
 k8s.io/api/certificates/v1alpha1
-k8s.io/api/core/v1
+k8s.io/api/authorization/v1
+k8s.io/api/apidiscovery/v2beta1
+k8s.io/api/admissionregistration/v1
 k8s.io/api/authentication/v1
+k8s.io/api/policy/v1
+k8s.io/api/networking/v1alpha1
+k8s.io/apimachinery/pkg/api/equality
+k8s.io/api/flowcontrol/v1
+k8s.io/api/rbac/v1alpha1
+k8s.io/apimachinery/pkg/apis/meta/v1/validation
+k8s.io/client-go/pkg/apis/clientauthentication
 k8s.io/client-go/rest/watch
+google.golang.org/api/option/internaloption
 k8s.io/apimachinery/pkg/apis/meta/v1beta1
+k8s.io/api/apiserverinternal/v1alpha1
+k8s.io/api/flowcontrol/v1beta2
+k8s.io/apimachinery/pkg/api/meta
+google.golang.org/api/transport/http
+k8s.io/api/rbac/v1
+k8s.io/api/rbac/v1beta1
+k8s.io/api/flowcontrol/v1beta3
+k8s.io/api/flowcontrol/v1beta1
+k8s.io/api/policy/v1beta1
+k8s.io/api/core/v1
+github.com/go-openapi/runtime/client
 k8s.io/client-go/pkg/apis/clientauthentication/v1
 k8s.io/client-go/pkg/apis/clientauthentication/v1beta1
-github.com/google/trillian/types
-google.golang.org/api/option/internaloption
-google.golang.org/api/transport/http
+k8s.io/apimachinery/pkg/apis/meta/internalversion
 k8s.io/api/coordination/v1alpha2
 k8s.io/api/coordination/v1beta1
+google.golang.org/api/idtoken
+google.golang.org/api/impersonate
+google.golang.org/api/cloudkms/v1
+github.com/google/trillian/types
+k8s.io/apimachinery/pkg/apis/meta/internalversion/validation
 k8s.io/apimachinery/pkg/runtime/serializer/versioning
 k8s.io/apimachinery/pkg/runtime/serializer/cbor
 k8s.io/apimachinery/pkg/util/strategicpatch
-github.com/sigstore/cosign/pkg/providers/spiffe
-k8s.io/apimachinery/pkg/apis/meta/internalversion
 k8s.io/client-go/pkg/apis/clientauthentication/install
-github.com/go-openapi/runtime/client
-google.golang.org/api/idtoken
-google.golang.org/api/impersonate
-google.golang.org/api/cloudkms/v1
+k8s.io/client-go/util/watchlist
+github.com/sigstore/cosign/pkg/providers/spiffe
+github.com/sigstore/cosign/pkg/providers/google
+k8s.io/api/authentication/v1alpha1
+k8s.io/api/authentication/v1beta1
 k8s.io/apimachinery/pkg/runtime/serializer
 k8s.io/client-go/tools/clientcmd/api/latest
+github.com/sigstore/cosign/pkg/providers/all
 k8s.io/apimachinery/pkg/api/validation
 k8s.io/apimachinery/pkg/api/meta/testrestmapper
 k8s.io/client-go/util/consistencydetector
-k8s.io/apimachinery/pkg/apis/meta/internalversion/validation
-k8s.io/api/authentication/v1alpha1
-k8s.io/api/authentication/v1beta1
-k8s.io/client-go/util/watchlist
-k8s.io/kube-openapi/pkg/common
+k8s.io/api/authorization/v1beta1
 k8s.io/client-go/plugin/pkg/client/auth/exec
-k8s.io/apimachinery/pkg/util/managedfields/internal
-github.com/sigstore/cosign/pkg/providers/google
+github.com/sigstore/rekor/pkg/types
 github.com/sigstore/rekor/pkg/generated/client/index
 github.com/sigstore/rekor/pkg/generated/client/pubkey
-github.com/sigstore/rekor/pkg/types
-github.com/sigstore/rekor/pkg/generated/client/tlog
 github.com/sigstore/rekor/pkg/generated/client/entries
-github.com/sigstore/cosign/pkg/providers/all
-k8s.io/api/authorization/v1beta1
+github.com/sigstore/rekor/pkg/generated/client/tlog
+k8s.io/kube-openapi/pkg/common
+k8s.io/apimachinery/pkg/util/managedfields/internal
 k8s.io/client-go/rest
-k8s.io/kube-openapi/pkg/handler3
 github.com/tink-crypto/tink-go-gcpkms/integration/gcpkms
 github.com/sigstore/rekor/pkg/generated/client
-k8s.io/api/admissionregistration/v1alpha1
-k8s.io/api/admissionregistration/v1beta1
-github.com/awslabs/amazon-ecr-credential-helper/ecr-login/api
 github.com/sigstore/rekor/pkg/tle
 github.com/sigstore/rekor/pkg/types/dsse
 github.com/sigstore/rekor/pkg/types/hashedrekord
 github.com/sigstore/rekor/pkg/types/intoto
 github.com/sigstore/rekor/pkg/types/rekord
+k8s.io/kube-openapi/pkg/handler3
+github.com/sigstore/cosign/pkg/cosign/bundle
+k8s.io/api/admissionregistration/v1alpha1
+k8s.io/api/admissionregistration/v1beta1
 github.com/sigstore/rekor/pkg/verify
 github.com/sigstore/rekor/pkg/client
-github.com/sigstore/cosign/pkg/cosign/bundle
-k8s.io/apimachinery/pkg/util/managedfields
-github.com/awslabs/amazon-ecr-credential-helper/ecr-login
 github.com/sigstore/cosign/pkg/oci
-github.com/sigstore/rekor/pkg/types/hashedrekord/v0.0.1
 github.com/sigstore/rekor/pkg/types/dsse/v0.0.1
+github.com/sigstore/rekor/pkg/types/hashedrekord/v0.0.1
 github.com/sigstore/rekor/pkg/types/intoto/v0.0.2
 github.com/sigstore/rekor/pkg/types/intoto/v0.0.1
-github.com/sigstore/cosign/pkg/oci/internal/signature
 github.com/sigstore/cosign/internal/pkg/cosign
 github.com/sigstore/cosign/pkg/oci/empty
+github.com/sigstore/cosign/pkg/oci/internal/signature
 github.com/sigstore/rekor/pkg/types/rekord/v0.0.1
-github.com/sigstore/sigstore/pkg/signature/kms/aws
 github.com/sigstore/cosign/pkg/oci/signed
-github.com/sigstore/sigstore-go/pkg/tlog
 github.com/sigstore/gitsign/internal/rekor/oid
+k8s.io/apimachinery/pkg/util/managedfields
+github.com/sigstore/sigstore-go/pkg/tlog
+github.com/sigstore/cosign/pkg/oci/layout
+github.com/sigstore/cosign/pkg/oci/static
+k8s.io/client-go/util/apply
+k8s.io/client-go/plugin/pkg/client/auth/gcp
 k8s.io/client-go/plugin/pkg/client/auth/azure
 k8s.io/client-go/plugin/pkg/client/auth/oidc
-k8s.io/client-go/plugin/pkg/client/auth/gcp
 k8s.io/client-go/tools/auth
-k8s.io/client-go/testing
-k8s.io/client-go/openapi
-k8s.io/client-go/util/apply
-github.com/sigstore/cosign/pkg/oci/static
-github.com/sigstore/cosign/pkg/oci/layout
 k8s.io/client-go/tools/clientcmd
-k8s.io/client-go/plugin/pkg/client/auth
+github.com/sigstore/sigstore-go/pkg/verify
 github.com/sigstore/cosign/internal/pkg/cosign/payload
 github.com/sigstore/cosign/pkg/oci/mutate
-github.com/sigstore/sigstore-go/pkg/verify
-github.com/sigstore/rekor/pkg/signer
-github.com/sigstore/cosign/internal/pkg/cosign/fulcio
+k8s.io/client-go/plugin/pkg/client/auth
+github.com/awslabs/amazon-ecr-credential-helper/ecr-login/api
+github.com/awslabs/amazon-ecr-credential-helper/ecr-login
+k8s.io/client-go/openapi
+k8s.io/client-go/testing
 github.com/sigstore/cosign/pkg/oci/walk
-github.com/sigstore/cosign/pkg/cosign/remote
 github.com/sigstore/cosign/internal/pkg/cosign/tsa
+github.com/sigstore/cosign/internal/pkg/cosign/fulcio
+github.com/sigstore/cosign/pkg/cosign/remote
 github.com/sigstore/sigstore-go/pkg/bundle
-github.com/sigstore/rekor/pkg/sharding
+github.com/sigstore/sigstore/pkg/signature/kms/aws
 github.com/sigstore/cosign/pkg/oci/remote
-k8s.io/client-go/gentype
+github.com/sigstore/rekor/pkg/signer
 github.com/sigstore/cosign/pkg/cosign
-github.com/sigstore/cosign/pkg/cosign/git/gitlab
+k8s.io/client-go/gentype
+github.com/sigstore/rekor/pkg/sharding
+github.com/sigstore/cosign/pkg/cosign/git/github
 github.com/sigstore/cosign/internal/pkg/cosign/rekor
 github.com/sigstore/gitsign/internal/cert
-github.com/sigstore/cosign/pkg/cosign/git/github
 github.com/sigstore/gitsign/pkg/rekor
+github.com/sigstore/cosign/pkg/cosign/git/gitlab
 github.com/sigstore/gitsign/internal/rekor
-github.com/sigstore/gitsign/pkg/git
 github.com/sigstore/gitsign/internal/signature
+github.com/sigstore/gitsign/pkg/git
 github.com/sigstore/cosign/pkg/cosign/git
 github.com/sigstore/gitsign/pkg/gitsign
 github.com/sigstore/gitsign/internal/git
-k8s.io/api/discovery/v1
+k8s.io/api/apps/v1beta1
+k8s.io/api/autoscaling/v2
+k8s.io/api/certificates/v1
+k8s.io/api/autoscaling/v1
+k8s.io/api/batch/v1
+k8s.io/api/autoscaling/v2beta2
 k8s.io/api/autoscaling/v2beta1
+k8s.io/api/events/v1
+k8s.io/api/apps/v1
 k8s.io/api/certificates/v1beta1
-k8s.io/api/discovery/v1beta1
-k8s.io/api/autoscaling/v2beta2
+k8s.io/api/events/v1beta1
 k8s.io/api/apps/v1beta2
-k8s.io/api/autoscaling/v1
-k8s.io/api/node/v1
+k8s.io/api/discovery/v1beta1
+k8s.io/api/discovery/v1
 k8s.io/api/node/v1alpha1
-k8s.io/api/autoscaling/v2
+k8s.io/api/networking/v1beta1
 k8s.io/api/scheduling/v1
-k8s.io/api/events/v1
-k8s.io/api/apps/v1beta1
-k8s.io/api/events/v1beta1
-k8s.io/client-go/tools/reference
-k8s.io/api/storagemigration/v1alpha1
-k8s.io/api/apps/v1
-k8s.io/api/scheduling/v1alpha1
 k8s.io/api/node/v1beta1
+k8s.io/api/scheduling/v1alpha1
+k8s.io/api/scheduling/v1beta1
 k8s.io/api/networking/v1
 k8s.io/api/resource/v1beta1
-k8s.io/api/resource/v1alpha3
-k8s.io/api/scheduling/v1beta1
-k8s.io/api/certificates/v1
-k8s.io/api/networking/v1beta1
 k8s.io/api/storage/v1
+k8s.io/api/resource/v1alpha3
+k8s.io/api/node/v1
+k8s.io/client-go/tools/reference
+k8s.io/api/storagemigration/v1alpha1
 k8s.io/api/storage/v1alpha1
-k8s.io/api/batch/v1
 k8s.io/api/storage/v1beta1
 k8s.io/api/batch/v1beta1
 k8s.io/api/extensions/v1beta1
 k8s.io/client-go/kubernetes/scheme
 k8s.io/client-go/kubernetes/typed/authentication/v1alpha1
 k8s.io/client-go/kubernetes/typed/authentication/v1beta1
-k8s.io/client-go/kubernetes/typed/authentication/v1
-k8s.io/client-go/kubernetes/typed/authorization/v1beta1
-k8s.io/client-go/discovery
 k8s.io/client-go/kubernetes/typed/authorization/v1
+k8s.io/client-go/discovery
+k8s.io/client-go/kubernetes/typed/authorization/v1beta1
+k8s.io/client-go/kubernetes/typed/authentication/v1
 k8s.io/client-go/applyconfigurations/meta/v1
-k8s.io/client-go/applyconfigurations/apiserverinternal/v1alpha1
-k8s.io/client-go/applyconfigurations/certificates/v1
 k8s.io/client-go/applyconfigurations/certificates/v1alpha1
-k8s.io/client-go/applyconfigurations/certificates/v1beta1
-k8s.io/client-go/applyconfigurations/coordination/v1beta1
+k8s.io/client-go/applyconfigurations/certificates/v1
+k8s.io/client-go/applyconfigurations/coordination/v1
 k8s.io/client-go/applyconfigurations/coordination/v1alpha2
+k8s.io/client-go/applyconfigurations/coordination/v1beta1
+k8s.io/client-go/applyconfigurations/certificates/v1beta1
+k8s.io/client-go/applyconfigurations/networking/v1alpha1
+k8s.io/client-go/applyconfigurations/policy/v1beta1
 k8s.io/client-go/applyconfigurations/scheduling/v1
 k8s.io/client-go/applyconfigurations/scheduling/v1alpha1
-k8s.io/client-go/applyconfigurations/policy/v1
-k8s.io/client-go/applyconfigurations/autoscaling/v2beta1
 k8s.io/client-go/applyconfigurations/scheduling/v1beta1
+k8s.io/client-go/applyconfigurations/policy/v1
 k8s.io/client-go/applyconfigurations/autoscaling/v1
-k8s.io/client-go/applyconfigurations/policy/v1beta1
-k8s.io/client-go/applyconfigurations/rbac/v1beta1
+k8s.io/client-go/applyconfigurations/admissionregistration/v1
 k8s.io/client-go/applyconfigurations/rbac/v1alpha1
-k8s.io/client-go/applyconfigurations/networking/v1alpha1
-k8s.io/client-go/applyconfigurations/coordination/v1
-k8s.io/client-go/applyconfigurations/storagemigration/v1alpha1
+k8s.io/client-go/applyconfigurations/autoscaling/v2beta1
 k8s.io/client-go/applyconfigurations/flowcontrol/v1beta3
+k8s.io/client-go/applyconfigurations/storagemigration/v1alpha1
 k8s.io/client-go/applyconfigurations/rbac/v1
-k8s.io/client-go/applyconfigurations/autoscaling/v2beta2
-k8s.io/client-go/applyconfigurations/admissionregistration/v1
-k8s.io/client-go/applyconfigurations/flowcontrol/v1beta1
 k8s.io/client-go/applyconfigurations/flowcontrol/v1beta2
 k8s.io/client-go/applyconfigurations/autoscaling/v2
 k8s.io/client-go/applyconfigurations/flowcontrol/v1
+k8s.io/client-go/applyconfigurations/flowcontrol/v1beta1
+k8s.io/client-go/applyconfigurations/autoscaling/v2beta2
+k8s.io/client-go/applyconfigurations/apiserverinternal/v1alpha1
+k8s.io/client-go/applyconfigurations/rbac/v1beta1
 k8s.io/client-go/applyconfigurations/core/v1
-k8s.io/client-go/kubernetes/typed/apiserverinternal/v1alpha1
+k8s.io/client-go/kubernetes/typed/scheduling/v1beta1
 k8s.io/client-go/kubernetes/typed/coordination/v1
-k8s.io/client-go/kubernetes/typed/coordination/v1alpha2
-k8s.io/client-go/kubernetes/typed/scheduling/v1alpha1
 k8s.io/client-go/kubernetes/typed/coordination/v1beta1
-k8s.io/client-go/kubernetes/typed/policy/v1beta1
-k8s.io/client-go/kubernetes/typed/scheduling/v1beta1
+k8s.io/client-go/kubernetes/typed/coordination/v1alpha2
+k8s.io/client-go/kubernetes/typed/policy/v1
+k8s.io/client-go/kubernetes/typed/rbac/v1alpha1
+k8s.io/client-go/kubernetes/typed/networking/v1alpha1
 k8s.io/client-go/kubernetes/typed/certificates/v1alpha1
+k8s.io/client-go/kubernetes/typed/autoscaling/v1
+k8s.io/client-go/kubernetes/typed/certificates/v1beta1
+k8s.io/client-go/kubernetes/typed/scheduling/v1alpha1
 k8s.io/client-go/kubernetes/typed/certificates/v1
-k8s.io/client-go/kubernetes/typed/networking/v1alpha1
 k8s.io/client-go/kubernetes/typed/scheduling/v1
 k8s.io/client-go/kubernetes/typed/storagemigration/v1alpha1
-k8s.io/client-go/kubernetes/typed/certificates/v1beta1
-k8s.io/client-go/kubernetes/typed/rbac/v1
-k8s.io/client-go/kubernetes/typed/policy/v1
-k8s.io/client-go/kubernetes/typed/autoscaling/v1
+k8s.io/client-go/kubernetes/typed/policy/v1beta1
+k8s.io/client-go/kubernetes/typed/apiserverinternal/v1alpha1
 k8s.io/client-go/kubernetes/typed/flowcontrol/v1
-k8s.io/client-go/kubernetes/typed/rbac/v1beta1
-k8s.io/client-go/kubernetes/typed/rbac/v1alpha1
-k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta3
-k8s.io/client-go/kubernetes/typed/autoscaling/v2beta2
+k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta2
 k8s.io/client-go/kubernetes/typed/autoscaling/v2beta1
+k8s.io/client-go/kubernetes/typed/rbac/v1
+k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta3
 k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta1
+k8s.io/client-go/kubernetes/typed/rbac/v1beta1
+k8s.io/client-go/kubernetes/typed/autoscaling/v2beta2
+k8s.io/client-go/kubernetes/typed/autoscaling/v2
 k8s.io/client-go/kubernetes/typed/admissionregistration/v1
 k8s.io/client-go/applyconfigurations/admissionregistration/v1alpha1
 k8s.io/client-go/applyconfigurations/admissionregistration/v1beta1
-k8s.io/client-go/kubernetes/typed/autoscaling/v2
-k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta2
 k8s.io/client-go/kubernetes/typed/admissionregistration/v1alpha1
 k8s.io/client-go/kubernetes/typed/admissionregistration/v1beta1
 k8s.io/client-go/applyconfigurations/events/v1beta1
 k8s.io/client-go/applyconfigurations/events/v1
-k8s.io/client-go/applyconfigurations/node/v1
-k8s.io/client-go/applyconfigurations/discovery/v1beta1
-k8s.io/client-go/applyconfigurations/node/v1beta1
 k8s.io/client-go/applyconfigurations/node/v1alpha1
+k8s.io/client-go/applyconfigurations/node/v1beta1
+k8s.io/client-go/applyconfigurations/discovery/v1beta1
+k8s.io/client-go/applyconfigurations/node/v1
 k8s.io/client-go/applyconfigurations/discovery/v1
 k8s.io/client-go/applyconfigurations/storage/v1alpha1
-k8s.io/client-go/applyconfigurations/networking/v1
-k8s.io/client-go/applyconfigurations/apps/v1beta1
 k8s.io/client-go/kubernetes/typed/core/v1
-k8s.io/client-go/applyconfigurations/networking/v1beta1
+k8s.io/client-go/applyconfigurations/apps/v1beta2
+k8s.io/client-go/applyconfigurations/apps/v1beta1
 k8s.io/client-go/applyconfigurations/apps/v1
 k8s.io/client-go/applyconfigurations/storage/v1
-k8s.io/client-go/applyconfigurations/extensions/v1beta1
+k8s.io/client-go/applyconfigurations/networking/v1beta1
 k8s.io/client-go/applyconfigurations/batch/v1
-k8s.io/client-go/applyconfigurations/apps/v1beta2
 k8s.io/client-go/applyconfigurations/storage/v1beta1
 k8s.io/client-go/applyconfigurations/resource/v1alpha3
+k8s.io/client-go/applyconfigurations/networking/v1
+k8s.io/client-go/applyconfigurations/extensions/v1beta1
 k8s.io/client-go/applyconfigurations/resource/v1beta1
+k8s.io/client-go/kubernetes/typed/events/v1beta1
 k8s.io/client-go/kubernetes/typed/events/v1
-k8s.io/client-go/kubernetes/typed/node/v1alpha1
 k8s.io/client-go/kubernetes/typed/node/v1
-k8s.io/client-go/kubernetes/typed/discovery/v1beta1
-k8s.io/client-go/kubernetes/typed/events/v1beta1
 k8s.io/client-go/kubernetes/typed/discovery/v1
+k8s.io/client-go/kubernetes/typed/node/v1alpha1
 k8s.io/client-go/kubernetes/typed/node/v1beta1
+k8s.io/client-go/kubernetes/typed/discovery/v1beta1
 k8s.io/client-go/kubernetes/typed/storage/v1alpha1
-k8s.io/client-go/kubernetes/typed/networking/v1
 k8s.io/client-go/kubernetes/typed/networking/v1beta1
-k8s.io/client-go/kubernetes/typed/storage/v1
-k8s.io/client-go/kubernetes/typed/resource/v1alpha3
-k8s.io/client-go/kubernetes/typed/batch/v1
 k8s.io/client-go/applyconfigurations/batch/v1beta1
-k8s.io/client-go/kubernetes/typed/apps/v1
+k8s.io/client-go/kubernetes/typed/batch/v1
 k8s.io/client-go/kubernetes/typed/resource/v1beta1
-k8s.io/client-go/kubernetes/typed/storage/v1beta1
-k8s.io/client-go/kubernetes/typed/apps/v1beta2
+k8s.io/client-go/kubernetes/typed/networking/v1
+k8s.io/client-go/kubernetes/typed/resource/v1alpha3
 k8s.io/client-go/kubernetes/typed/apps/v1beta1
+k8s.io/client-go/kubernetes/typed/apps/v1beta2
 k8s.io/client-go/kubernetes/typed/extensions/v1beta1
+k8s.io/client-go/kubernetes/typed/storage/v1beta1
+k8s.io/client-go/kubernetes/typed/storage/v1
+k8s.io/client-go/kubernetes/typed/apps/v1
 k8s.io/client-go/kubernetes/typed/batch/v1beta1
 k8s.io/client-go/kubernetes
 github.com/sigstore/cosign/pkg/cosign/kubernetes
 github.com/sigstore/cosign/pkg/signature
 github.com/sigstore/cosign/cmd/cosign/cli/options
-github.com/sigstore/cosign/cmd/cosign/cli/rekor
 github.com/sigstore/cosign/cmd/cosign/cli/fulcio
-github.com/sigstore/cosign/cmd/cosign/cli/initialize
 github.com/sigstore/gitsign/internal/gitsign
+github.com/sigstore/cosign/cmd/cosign/cli/rekor
+github.com/sigstore/cosign/cmd/cosign/cli/initialize
 github.com/sigstore/gitsign/internal/commands/initialize
 github.com/sigstore/cosign/cmd/cosign/cli/fulcio/fulcioverifier
 github.com/sigstore/cosign/cmd/cosign/cli/sign
@@ -4494,7 +4530,7 @@
 github.com/sigstore/gitsign
 github.com/sigstore/gitsign/docs/cli
    dh_auto_test -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go test -vet=off -v -p 40 github.com/sigstore/gitsign github.com/sigstore/gitsign/cmd/gitsign-credential-cache github.com/sigstore/gitsign/docs/cli github.com/sigstore/gitsign/internal github.com/sigstore/gitsign/internal/attest github.com/sigstore/gitsign/internal/cache github.com/sigstore/gitsign/internal/cache/api github.com/sigstore/gitsign/internal/cache/service github.com/sigstore/gitsign/internal/cert github.com/sigstore/gitsign/internal/commands/attest github.com/sigstore/gitsign/internal/commands/initialize github.com/sigstore/gitsign/internal/commands/root github.com/sigstore/gitsign/internal/commands/show github.com/sigstore/gitsign/internal/commands/verify github.com/sigstore/gitsign/internal/commands/verify-tag github.com/sigstore/gitsign/internal/commands/version github.com/sigstore/gitsign/internal/config github.com/sigstore/gitsign/internal/fork/ietf-cms github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp github.com/sigstore/gitsign/internal/fulcio github.com/sigstore/gitsign/internal/fulcio/fulcioroots github.com/sigstore/gitsign/internal/git github.com/sigstore/gitsign/internal/git/gittest github.com/sigstore/gitsign/internal/gitsign github.com/sigstore/gitsign/internal/gpg github.com/sigstore/gitsign/internal/io github.com/sigstore/gitsign/internal/rekor github.com/sigstore/gitsign/internal/rekor/oid github.com/sigstore/gitsign/internal/signature github.com/sigstore/gitsign/internal/signerverifier github.com/sigstore/gitsign/pkg/fulcio github.com/sigstore/gitsign/pkg/git github.com/sigstore/gitsign/pkg/gitsign github.com/sigstore/gitsign/pkg/predicate github.com/sigstore/gitsign/pkg/rekor github.com/sigstore/gitsign/pkg/version
+	cd _build && go test -vet=off -v -p 42 github.com/sigstore/gitsign github.com/sigstore/gitsign/cmd/gitsign-credential-cache github.com/sigstore/gitsign/docs/cli github.com/sigstore/gitsign/internal github.com/sigstore/gitsign/internal/attest github.com/sigstore/gitsign/internal/cache github.com/sigstore/gitsign/internal/cache/api github.com/sigstore/gitsign/internal/cache/service github.com/sigstore/gitsign/internal/cert github.com/sigstore/gitsign/internal/commands/attest github.com/sigstore/gitsign/internal/commands/initialize github.com/sigstore/gitsign/internal/commands/root github.com/sigstore/gitsign/internal/commands/show github.com/sigstore/gitsign/internal/commands/verify github.com/sigstore/gitsign/internal/commands/verify-tag github.com/sigstore/gitsign/internal/commands/version github.com/sigstore/gitsign/internal/config github.com/sigstore/gitsign/internal/fork/ietf-cms github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp github.com/sigstore/gitsign/internal/fulcio github.com/sigstore/gitsign/internal/fulcio/fulcioroots github.com/sigstore/gitsign/internal/git github.com/sigstore/gitsign/internal/git/gittest github.com/sigstore/gitsign/internal/gitsign github.com/sigstore/gitsign/internal/gpg github.com/sigstore/gitsign/internal/io github.com/sigstore/gitsign/internal/rekor github.com/sigstore/gitsign/internal/rekor/oid github.com/sigstore/gitsign/internal/signature github.com/sigstore/gitsign/internal/signerverifier github.com/sigstore/gitsign/pkg/fulcio github.com/sigstore/gitsign/pkg/git github.com/sigstore/gitsign/pkg/gitsign github.com/sigstore/gitsign/pkg/predicate github.com/sigstore/gitsign/pkg/rekor github.com/sigstore/gitsign/pkg/version
 ?   	github.com/sigstore/gitsign	[no test files]
 ?   	github.com/sigstore/gitsign/cmd/gitsign-credential-cache	[no test files]
 ?   	github.com/sigstore/gitsign/docs/cli	[no test files]
@@ -4528,17 +4564,17 @@
     --- PASS: TestAttestTreeRef/new_commit_same_tree (0.00s)
     --- PASS: TestAttestTreeRef/new_commit_new_tree (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/attest	0.045s
+ok  	github.com/sigstore/gitsign/internal/attest	0.043s
 === RUN   TestCache
-Get ionos11-amd64@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
-Store ionos11-amd64@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
-Get ionos11-amd64@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
+Get i-capture-the-hostname@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
+Store i-capture-the-hostname@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
+Get i-capture-the-hostname@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
 gitsign-credential-cache: found credential!
-Get ionos11-amd64@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
+Get i-capture-the-hostname@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
 gitsign-credential-cache: found credential!
---- PASS: TestCache (0.37s)
+--- PASS: TestCache (0.65s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/cache	0.381s
+ok  	github.com/sigstore/gitsign/internal/cache	0.657s
 ?   	github.com/sigstore/gitsign/internal/cache/api	[no test files]
 ?   	github.com/sigstore/gitsign/internal/cache/service	[no test files]
 ?   	github.com/sigstore/gitsign/internal/cert	[no test files]
@@ -4552,14 +4588,14 @@
     --- PASS: TestShow/fulcio-cert (0.00s)
     --- PASS: TestShow/gpg (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/commands/show	0.013s
+ok  	github.com/sigstore/gitsign/internal/commands/show	0.011s
 ?   	github.com/sigstore/gitsign/internal/commands/verify	[no test files]
 ?   	github.com/sigstore/gitsign/internal/commands/verify-tag	[no test files]
 ?   	github.com/sigstore/gitsign/internal/commands/version	[no test files]
 === RUN   TestGet
 --- PASS: TestGet (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/config	0.012s
+ok  	github.com/sigstore/gitsign/internal/config	0.008s
 === RUN   TestSign
 --- PASS: TestSign (0.00s)
 === RUN   TestSignDetached
@@ -4571,7 +4607,7 @@
 === RUN   TestAddTimestamps
 --- PASS: TestAddTimestamps (0.02s)
 === RUN   TestTimestampsVerifications
---- PASS: TestTimestampsVerifications (0.69s)
+--- PASS: TestTimestampsVerifications (0.42s)
 === RUN   TestVerify
 --- PASS: TestVerify (0.00s)
 === RUN   TestVerifyGPGSMAttached
@@ -4589,7 +4625,7 @@
 === RUN   TestVerifyDSAWithSHA1
 --- PASS: TestVerifyDSAWithSHA1 (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/fork/ietf-cms	2.267s
+ok  	github.com/sigstore/gitsign/internal/fork/ietf-cms	2.773s
 === RUN   TestRequestDo
 --- PASS: TestRequestDo (0.00s)
 === RUN   TestRequestMatches
@@ -4615,24 +4651,24 @@
 === RUN   TestParseTimestampGlobalSign
 --- PASS: TestParseTimestampGlobalSign (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp	0.011s
+ok  	github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp	0.009s
 ?   	github.com/sigstore/gitsign/internal/fulcio	[no test files]
 === RUN   TestNew
 === RUN   TestNew/FromFile
 === RUN   TestNew/Static
 === RUN   TestNew/None
---- PASS: TestNew (0.28s)
+--- PASS: TestNew (0.38s)
     --- PASS: TestNew/FromFile (0.00s)
     --- PASS: TestNew/Static (0.00s)
     --- PASS: TestNew/None (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/fulcio/fulcioroots	0.295s
+ok  	github.com/sigstore/gitsign/internal/fulcio/fulcioroots	0.381s
 ?   	github.com/sigstore/gitsign/internal/git	[no test files]
 ?   	github.com/sigstore/gitsign/internal/git/gittest	[no test files]
 === RUN   TestVerify
 --- PASS: TestVerify (0.01s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/gitsign	0.046s
+ok  	github.com/sigstore/gitsign/internal/gitsign	0.043s
 ?   	github.com/sigstore/gitsign/internal/gpg	[no test files]
 ?   	github.com/sigstore/gitsign/internal/io	[no test files]
 ?   	github.com/sigstore/gitsign/internal/rekor	[no test files]
@@ -4641,7 +4677,7 @@
 === RUN   TestConvert
 --- PASS: TestConvert (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/rekor/oid	0.020s
+ok  	github.com/sigstore/gitsign/internal/rekor/oid	0.016s
 === RUN   TestMatchSAN
 === RUN   TestMatchSAN/email_match
 === RUN   TestMatchSAN/uri_match
@@ -4664,7 +4700,7 @@
 === RUN   TestGetCert
 --- PASS: TestGetCert (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/pkg/fulcio	0.013s
+ok  	github.com/sigstore/gitsign/pkg/fulcio	0.011s
 === RUN   TestObjectHash
 === RUN   TestObjectHash/tag
 === RUN   TestObjectHash/commit
@@ -4678,7 +4714,7 @@
 === RUN   TestSignVerify/detached(false)
 === RUN   TestSignVerify/detached(false)/VerifySignature
 === RUN   TestSignVerify/detached(false)/CertVerifier.Verify
---- PASS: TestSignVerify (0.51s)
+--- PASS: TestSignVerify (0.19s)
     --- PASS: TestSignVerify/detached(true) (0.00s)
         --- PASS: TestSignVerify/detached(true)/VerifySignature (0.00s)
         --- PASS: TestSignVerify/detached(true)/CertVerifier.Verify (0.00s)
@@ -4686,7 +4722,7 @@
         --- PASS: TestSignVerify/detached(false)/VerifySignature (0.00s)
         --- PASS: TestSignVerify/detached(false)/CertVerifier.Verify (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/pkg/git	0.537s
+ok  	github.com/sigstore/gitsign/pkg/git	0.211s
 ?   	github.com/sigstore/gitsign/pkg/gitsign	[no test files]
 ?   	github.com/sigstore/gitsign/pkg/predicate	[no test files]
 ?   	github.com/sigstore/gitsign/pkg/rekor	[no test files]
@@ -4695,7 +4731,7 @@
 === RUN   TestEnv
 --- PASS: TestEnv (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/pkg/version	0.007s
+ok  	github.com/sigstore/gitsign/pkg/version	0.004s
    create-stamp debian/debhelper-build-stamp
    dh_testroot -O--builddirectory=_build -O--buildsystem=golang
    dh_prep -O--builddirectory=_build -O--buildsystem=golang
@@ -4753,12 +4789,14 @@
 dpkg-buildpackage: info: binary-only upload (no source included)
 dpkg-genchanges: info: including full source code in upload
 I: copying local configuration
+I: user script /srv/workspace/pbuilder/4060338/tmp/hooks/B01_cleanup starting
+I: user script /srv/workspace/pbuilder/4060338/tmp/hooks/B01_cleanup finished
 I: unmounting dev/ptmx filesystem
 I: unmounting dev/pts filesystem
 I: unmounting dev/shm filesystem
 I: unmounting proc filesystem
 I: unmounting sys filesystem
 I: cleaning the build env 
-I: removing directory /srv/workspace/pbuilder/1214693 and its subdirectories
-I: Current time: Wed Apr 30 05:32:55 -12 2025
-I: pbuilder-time-stamp: 1746034375
+I: removing directory /srv/workspace/pbuilder/4060338 and its subdirectories
+I: Current time: Wed Jun  3 14:00:01 +14 2026
+I: pbuilder-time-stamp: 1780444801