Diff of the two buildlogs:

--
--- b1/build.log	2025-03-13 03:05:19.120783314 +0000
+++ b2/build.log	2025-03-13 03:34:27.129732722 +0000
@@ -1,6 +1,6 @@
 I: pbuilder: network access will be disabled during build
-I: Current time: Tue Apr 14 21:24:14 -12 2026
-I: pbuilder-time-stamp: 1776245054
+I: Current time: Thu Mar 13 17:05:22 +14 2025
+I: pbuilder-time-stamp: 1741835122
 I: Building the build Environment
 I: extracting base tarball [/var/cache/pbuilder/unstable-reproducible-base.tgz]
 I: copying local configuration
@@ -24,52 +24,84 @@
 dpkg-source: info: applying fix-go-git513.patch
 I: Not using root during the build.
 I: Installing the build-deps
-I: user script /srv/workspace/pbuilder/2648201/tmp/hooks/D02_print_environment starting
+I: user script /srv/workspace/pbuilder/2934915/tmp/hooks/D01_modify_environment starting
+debug: Running on ionos11-amd64.
+I: Changing host+domainname to test build reproducibility
+I: Adding a custom variable just for the fun of it...
+I: Changing /bin/sh to bash
+'/bin/sh' -> '/bin/bash'
+lrwxrwxrwx 1 root root 9 Mar 13 03:05 /bin/sh -> /bin/bash
+I: Setting pbuilder2's login shell to /bin/bash
+I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other
+I: user script /srv/workspace/pbuilder/2934915/tmp/hooks/D01_modify_environment finished
+I: user script /srv/workspace/pbuilder/2934915/tmp/hooks/D02_print_environment starting
 I: set
-  BUILDDIR='/build/reproducible-path'
-  BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other'
-  BUILDUSERNAME='pbuilder1'
-  BUILD_ARCH='amd64'
-  DEBIAN_FRONTEND='noninteractive'
-  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=42 '
-  DISTRIBUTION='unstable'
-  HOME='/root'
-  HOST_ARCH='amd64'
+  BASH=/bin/sh
+  BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath
+  BASH_ALIASES=()
+  BASH_ARGC=()
+  BASH_ARGV=()
+  BASH_CMDS=()
+  BASH_LINENO=([0]="12" [1]="0")
+  BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:.
+  BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment")
+  BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="x86_64-pc-linux-gnu")
+  BASH_VERSION='5.2.37(1)-release'
+  BUILDDIR=/build/reproducible-path
+  BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other'
+  BUILDUSERNAME=pbuilder2
+  BUILD_ARCH=amd64
+  DEBIAN_FRONTEND=noninteractive
+  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=20 '
+  DIRSTACK=()
+  DISTRIBUTION=unstable
+  EUID=0
+  FUNCNAME=([0]="Echo" [1]="main")
+  GROUPS=()
+  HOME=/root
+  HOSTNAME=i-capture-the-hostname
+  HOSTTYPE=x86_64
+  HOST_ARCH=amd64
   IFS=' 	
   '
-  INVOCATION_ID='04f92f45489342bc8b960b66b67f09f7'
-  LANG='C'
-  LANGUAGE='en_US:en'
-  LC_ALL='C'
-  MAIL='/var/mail/root'
-  OPTIND='1'
-  PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games'
-  PBCURRENTCOMMANDLINEOPERATION='build'
-  PBUILDER_OPERATION='build'
-  PBUILDER_PKGDATADIR='/usr/share/pbuilder'
-  PBUILDER_PKGLIBDIR='/usr/lib/pbuilder'
-  PBUILDER_SYSCONFDIR='/etc'
-  PPID='2648201'
-  PS1='# '
-  PS2='> '
+  INVOCATION_ID=20e0c0d292c44ddd85995ad1fcff3c90
+  LANG=C
+  LANGUAGE=et_EE:et
+  LC_ALL=C
+  MACHTYPE=x86_64-pc-linux-gnu
+  MAIL=/var/mail/root
+  OPTERR=1
+  OPTIND=1
+  OSTYPE=linux-gnu
+  PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path
+  PBCURRENTCOMMANDLINEOPERATION=build
+  PBUILDER_OPERATION=build
+  PBUILDER_PKGDATADIR=/usr/share/pbuilder
+  PBUILDER_PKGLIBDIR=/usr/lib/pbuilder
+  PBUILDER_SYSCONFDIR=/etc
+  PIPESTATUS=([0]="0")
+  POSIXLY_CORRECT=y
+  PPID=2934915
   PS4='+ '
-  PWD='/'
-  SHELL='/bin/bash'
-  SHLVL='2'
-  SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.qLL3APWs/pbuilderrc_9J7O --distribution unstable --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.qLL3APWs/b1 --logfile b1/build.log gitsign_0.12.0-4.dsc'
-  SUDO_GID='110'
-  SUDO_UID='105'
-  SUDO_USER='jenkins'
-  TERM='unknown'
-  TZ='/usr/share/zoneinfo/Etc/GMT+12'
-  USER='root'
-  _='/usr/bin/systemd-run'
-  http_proxy='http://213.165.73.152:3128'
+  PWD=/
+  SHELL=/bin/bash
+  SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix
+  SHLVL=3
+  SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.qLL3APWs/pbuilderrc_X9sl --distribution unstable --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.qLL3APWs/b2 --logfile b2/build.log gitsign_0.12.0-4.dsc'
+  SUDO_GID=111
+  SUDO_UID=106
+  SUDO_USER=jenkins
+  TERM=unknown
+  TZ=/usr/share/zoneinfo/Etc/GMT-14
+  UID=0
+  USER=root
+  _='I: set'
+  http_proxy=http://46.16.76.132:3128
 I: uname -a
-  Linux ionos5-amd64 6.12.12+bpo-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.12-1~bpo12+1 (2025-02-23) x86_64 GNU/Linux
+  Linux i-capture-the-hostname 6.1.0-31-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.128-1 (2025-02-07) x86_64 GNU/Linux
 I: ls -l /bin
-  lrwxrwxrwx 1 root root 7 Mar  4  2025 /bin -> usr/bin
-I: user script /srv/workspace/pbuilder/2648201/tmp/hooks/D02_print_environment finished
+  lrwxrwxrwx 1 root root 7 Mar  4 11:20 /bin -> usr/bin
+I: user script /srv/workspace/pbuilder/2934915/tmp/hooks/D02_print_environment finished
  -> Attempting to satisfy build-dependencies
  -> Creating pbuilder-satisfydepends-dummy package
 Package: pbuilder-satisfydepends-dummy
@@ -709,7 +741,7 @@
 Get: 574 http://deb.debian.org/debian unstable/main amd64 golang-github-xanzy-go-gitlab-dev all 0.110.0-1 [274 kB]
 Get: 575 http://deb.debian.org/debian unstable/main amd64 golang-github-sigstore-cosign-dev all 2.4.1-2 [307 kB]
 Get: 576 http://deb.debian.org/debian unstable/main amd64 help2man amd64 1.49.3 [198 kB]
-Fetched 272 MB in 9s (29.3 MB/s)
+Fetched 272 MB in 12s (23.3 MB/s)
 Preconfiguring packages ...
 Selecting previously unselected package golang-golang-x-sys-dev.
 (Reading database ... 
(Reading database ... 5%
(Reading database ... 10%
(Reading database ... 15%
(Reading database ... 20%
(Reading database ... 25%
(Reading database ... 30%
(Reading database ... 35%
(Reading database ... 40%
(Reading database ... 45%
(Reading database ... 50%
(Reading database ... 55%
(Reading database ... 60%
(Reading database ... 65%
(Reading database ... 70%
(Reading database ... 75%
(Reading database ... 80%
(Reading database ... 85%
(Reading database ... 90%
(Reading database ... 95%
(Reading database ... 100%
(Reading database ... 19783 files and directories currently installed.)
@@ -2556,8 +2588,8 @@
 Setting up tzdata (2025a-2) ...
 
 Current default time zone: 'Etc/UTC'
-Local time is now:      Wed Apr 15 09:26:15 UTC 2026.
-Universal Time is now:  Wed Apr 15 09:26:15 UTC 2026.
+Local time is now:      Thu Mar 13 03:16:47 UTC 2025.
+Universal Time is now:  Thu Mar 13 03:16:47 UTC 2025.
 Run 'dpkg-reconfigure tzdata' if you wish to change it.
 
 Setting up golang-github-coreos-go-semver-dev (0.3.0-1) ...
@@ -3041,7 +3073,11 @@
 Building tag database...
  -> Finished parsing the build-deps
 I: Building the package
-I: Running cd /build/reproducible-path/gitsign-0.12.0/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S  > ../gitsign_0.12.0-4_source.changes
+I: user script /srv/workspace/pbuilder/2934915/tmp/hooks/A99_set_merged_usr starting
+Not re-configuring usrmerge for unstable
+I: user script /srv/workspace/pbuilder/2934915/tmp/hooks/A99_set_merged_usr finished
+hostname: Name or service not known
+I: Running cd /build/reproducible-path/gitsign-0.12.0/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S  > ../gitsign_0.12.0-4_source.changes
 dpkg-buildpackage: info: source package gitsign
 dpkg-buildpackage: info: source version 0.12.0-4
 dpkg-buildpackage: info: source distribution unstable
@@ -3059,50 +3095,58 @@
    dh_autoreconf -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_configure -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_build -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go install -trimpath -v -p 42 github.com/sigstore/gitsign github.com/sigstore/gitsign/cmd/gitsign-credential-cache github.com/sigstore/gitsign/docs/cli github.com/sigstore/gitsign/internal github.com/sigstore/gitsign/internal/attest github.com/sigstore/gitsign/internal/cache github.com/sigstore/gitsign/internal/cache/api github.com/sigstore/gitsign/internal/cache/service github.com/sigstore/gitsign/internal/cert github.com/sigstore/gitsign/internal/commands/attest github.com/sigstore/gitsign/internal/commands/initialize github.com/sigstore/gitsign/internal/commands/root github.com/sigstore/gitsign/internal/commands/show github.com/sigstore/gitsign/internal/commands/verify github.com/sigstore/gitsign/internal/commands/version github.com/sigstore/gitsign/internal/config github.com/sigstore/gitsign/internal/fork/ietf-cms github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp github.com/sigstore/gitsign/internal/fulcio github.com/sigstore/gitsign/internal/fulcio/fulcioroots github.com/sigstore/gitsign/internal/git github.com/sigstore/gitsign/internal/git/gittest github.com/sigstore/gitsign/internal/gitsign github.com/sigstore/gitsign/internal/gpg github.com/sigstore/gitsign/internal/io github.com/sigstore/gitsign/internal/rekor github.com/sigstore/gitsign/internal/rekor/oid github.com/sigstore/gitsign/internal/signature github.com/sigstore/gitsign/internal/signerverifier github.com/sigstore/gitsign/pkg/fulcio github.com/sigstore/gitsign/pkg/git github.com/sigstore/gitsign/pkg/gitsign github.com/sigstore/gitsign/pkg/predicate github.com/sigstore/gitsign/pkg/rekor github.com/sigstore/gitsign/pkg/version
-internal/unsafeheader
-internal/godebugs
-internal/asan
-internal/profilerecord
-golang.org/x/crypto/internal/alias
-log/internal
-internal/coverage/rtcov
-github.com/awslabs/amazon-ecr-credential-helper/ecr-login/version
-unicode/utf8
-internal/byteorder
+	cd _build && go install -trimpath -v -p 20 github.com/sigstore/gitsign github.com/sigstore/gitsign/cmd/gitsign-credential-cache github.com/sigstore/gitsign/docs/cli github.com/sigstore/gitsign/internal github.com/sigstore/gitsign/internal/attest github.com/sigstore/gitsign/internal/cache github.com/sigstore/gitsign/internal/cache/api github.com/sigstore/gitsign/internal/cache/service github.com/sigstore/gitsign/internal/cert github.com/sigstore/gitsign/internal/commands/attest github.com/sigstore/gitsign/internal/commands/initialize github.com/sigstore/gitsign/internal/commands/root github.com/sigstore/gitsign/internal/commands/show github.com/sigstore/gitsign/internal/commands/verify github.com/sigstore/gitsign/internal/commands/version github.com/sigstore/gitsign/internal/config github.com/sigstore/gitsign/internal/fork/ietf-cms github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp github.com/sigstore/gitsign/internal/fulcio github.com/sigstore/gitsign/internal/fulcio/fulcioroots github.com/sigstore/gitsign/internal/git github.com/sigstore/gitsign/internal/git/gittest github.com/sigstore/gitsign/internal/gitsign github.com/sigstore/gitsign/internal/gpg github.com/sigstore/gitsign/internal/io github.com/sigstore/gitsign/internal/rekor github.com/sigstore/gitsign/internal/rekor/oid github.com/sigstore/gitsign/internal/signature github.com/sigstore/gitsign/internal/signerverifier github.com/sigstore/gitsign/pkg/fulcio github.com/sigstore/gitsign/pkg/git github.com/sigstore/gitsign/pkg/gitsign github.com/sigstore/gitsign/pkg/predicate github.com/sigstore/gitsign/pkg/rekor github.com/sigstore/gitsign/pkg/version
 internal/goos
-internal/nettrace
 internal/goexperiment
-vendor/golang.org/x/crypto/cryptobyte/asn1
 internal/itoa
-image/color
-golang.org/x/crypto/cryptobyte/asn1
+encoding
 cmp
+internal/unsafeheader
+internal/godebugs
+internal/coverage/rtcov
 math/bits
-internal/cpu
-unicode
-crypto/internal/boring/sig
-internal/runtime/syscall
+internal/asan
 internal/msan
-github.com/aws/aws-sdk-go-v2/internal/sdkio
-google.golang.org/grpc/serviceconfig
-github.com/go-git/go-git/plumbing/color
-github.com/pjbgf/sha1cd/internal
+internal/profilerecord
+internal/byteorder
 internal/goarch
-google.golang.org/protobuf/internal/flags
-go.opencensus.io/trace/internal
-encoding
+unicode/utf8
+unicode
+internal/runtime/syscall
+sync/atomic
+internal/runtime/atomic
+unicode/utf16
+container/list
+internal/cpu
 crypto/internal/fips140/alias
+crypto/internal/boring/sig
+vendor/golang.org/x/crypto/cryptobyte/asn1
+vendor/golang.org/x/crypto/internal/alias
+internal/nettrace
+log/internal
+crypto/internal/fips140deps/byteorder
+internal/chacha8rand
+internal/abi
+internal/runtime/math
+internal/runtime/sys
+crypto/internal/fips140/subtle
+google.golang.org/protobuf/internal/flags
+google.golang.org/grpc/serviceconfig
 go.opencensus.io
+go.opencensus.io/trace/internal
 go.opencensus.io/internal/tagencoding
-vendor/golang.org/x/crypto/internal/alias
-unicode/utf16
 github.com/ProtonMail/go-crypto/internal/byteutil
-github.com/docker/cli/cli/config/types
-sync/atomic
+golang.org/x/crypto/cryptobyte/asn1
+github.com/golang/groupcache/lru
+google.golang.org/protobuf/internal/set
+image/color
+github.com/pjbgf/sha1cd/internal
+github.com/go-git/go-git/plumbing/color
 github.com/pjbgf/sha1cd/ubc
-container/list
-internal/runtime/atomic
+golang.org/x/crypto/internal/alias
+github.com/awslabs/amazon-ecr-credential-helper/ecr-login/version
+github.com/aws/aws-sdk-go-v2/internal/sdkio
+github.com/docker/cli/cli/config/types
 github.com/google/go-containerregistry/pkg/v1/types
 github.com/klauspost/compress/internal/cpuinfo
 github.com/klauspost/compress/internal/le
@@ -3111,974 +3155,966 @@
 go.mongodb.org/mongo-driver/bson/bsonoptions
 go.mongodb.org/mongo-driver/bson/bsontype
 github.com/sigstore/rekor/pkg/pki/identity
+golang.org/x/crypto/salsa20/salsa
 golang.org/x/exp/constraints
+internal/runtime/exithook
 log/slog/internal
 github.com/sigstore/cosign/pkg/types
+internal/bytealg
+crypto/internal/fips140deps/cpu
 go.opentelemetry.io/otel/metric/embedded
+math
 go.opentelemetry.io/otel/trace/embedded
-github.com/transparency-dev/merkle
+github.com/pelletier/go-toml/v2/internal/characters
 github.com/theupdateframework/go-tuf/v0/internal/sets
+github.com/transparency-dev/merkle
 k8s.io/apimachinery/pkg/selection
 k8s.io/utils/strings/slices
-internal/runtime/math
-internal/abi
-internal/chacha8rand
-crypto/internal/fips140deps/byteorder
 k8s.io/apimachinery/pkg/types
-internal/runtime/sys
 github.com/google/go-cmp/cmp/internal/flags
-crypto/internal/fips140/subtle
-github.com/pelletier/go-toml/v2/internal/characters
-github.com/golang/groupcache/lru
-google.golang.org/protobuf/internal/set
-golang.org/x/crypto/salsa20/salsa
 golang.org/x/exp/slices
-internal/bytealg
-crypto/internal/fips140deps/cpu
-math
-internal/runtime/exithook
 internal/stringslite
 internal/race
+internal/runtime/maps
+internal/sync
 github.com/klauspost/compress
 go.opentelemetry.io/otel/internal
-internal/sync
-internal/runtime/maps
 runtime
-crypto/subtle
 internal/reflectlite
-k8s.io/klog/internal/dbg
 iter
-weak
 sync
-maps
+crypto/subtle
+weak
+k8s.io/klog/internal/dbg
 slices
+maps
 errors
 sort
-internal/bisect
 internal/testlog
 internal/singleflight
 unique
 google.golang.org/protobuf/internal/pragma
 github.com/josharian/intern
-go.uber.org/zap/internal/pool
 log/slog/internal/buffer
-github.com/sigstore/cosign/cmd/cosign/cli/sign/privacy
 github.com/spf13/viper/internal/encoding
+github.com/sigstore/cosign/cmd/cosign/cli/sign/privacy
+go.uber.org/zap/internal/pool
+internal/bisect
 runtime/cgo
+io
 internal/oserror
 path
-vendor/golang.org/x/net/dns/dnsmessage
 math/rand/v2
+vendor/golang.org/x/net/dns/dnsmessage
+google.golang.org/grpc/internal/buffer
 golang.org/x/crypto/cast5
-github.com/sassoftware/relic/signers/sigerrors
 github.com/hashicorp/hcl/hcl/strconv
-io
-google.golang.org/grpc/internal/buffer
 strconv
+github.com/sassoftware/relic/signers/sigerrors
 internal/godebug
+strings
+bytes
 syscall
-github.com/google/go-containerregistry/internal/and
-github.com/aws/smithy-go/transport/http/internal/io
 go.step.sm/crypto/internal/utils/utfbom
-hash
-github.com/gogo/protobuf/sortkeys
 github.com/cloudflare/circl/internal/sha3
-bytes
+hash
+github.com/google/go-containerregistry/internal/and
 crypto/internal/randutil
 container/heap
-internal/saferio
-strings
 k8s.io/apimachinery/pkg/util/sets
+github.com/aws/smithy-go/transport/http/internal/io
+internal/saferio
+github.com/gogo/protobuf/sortkeys
+hash/crc32
 crypto/internal/fips140deps/godebug
 math/rand
-hash/crc32
-hash/fnv
 hash/adler32
+hash/fnv
+reflect
 crypto
-golang.org/x/crypto/openpgp/errors
-github.com/x448/float16
-encoding/base32
 golang.org/x/crypto/blowfish
 net/netip
-reflect
+golang.org/x/crypto/openpgp/errors
+encoding/base32
+github.com/x448/float16
 github.com/cloudflare/circl/sign
 golang.org/x/crypto/openpgp/s2k
-google.golang.org/grpc/internal/grpcrand
-vendor/golang.org/x/text/transform
-github.com/syndtr/goleveldb/leveldb/comparer
-golang.org/x/text/transform
 github.com/aws/smithy-go/io
-net/http/internal/ascii
+golang.org/x/text/transform
+github.com/syndtr/goleveldb/leveldb/comparer
+vendor/golang.org/x/text/transform
+google.golang.org/grpc/internal/grpcrand
+golang.org/x/text/runes
 crypto/internal/fips140
+net/http/internal/ascii
+crypto/internal/impl
+regexp/syntax
+html
+github.com/aws/aws-sdk-go-v2/internal/strings
 k8s.io/klog/internal/severity
 github.com/theupdateframework/go-tuf/v0/internal/roles
 net/http/internal/testcert
 go/build/constraint
 github.com/munnerz/goautoneg
-github.com/aws/aws-sdk-go-v2/internal/strings
-go.step.sm/crypto/internal/emoji
-html
 bufio
-regexp/syntax
-crypto/internal/impl
-golang.org/x/text/runes
+go.step.sm/crypto/internal/emoji
 crypto/tls/internal/fips140tls
+crypto/internal/fips140/sha512
 crypto/internal/fips140/sha256
 crypto/internal/fips140/sha3
-crypto/internal/fips140/sha512
-compress/bzip2
 image
-regexp
-image/internal/imageutil
-crypto/sha3
+compress/bzip2
 crypto/internal/fips140/hmac
-image/jpeg
-internal/syscall/execenv
-internal/syscall/unix
-time
+crypto/sha3
 crypto/internal/fips140/check
 crypto/internal/fips140hash
 crypto/internal/fips140/aes
-crypto/internal/fips140/hkdf
-crypto/internal/fips140/tls12
-crypto/internal/fips140/bigmod
 crypto/internal/fips140/edwards25519/field
+crypto/internal/fips140/bigmod
 crypto/internal/fips140/nistec/fiat
+crypto/internal/fips140/hkdf
+crypto/internal/fips140/tls12
 crypto/internal/fips140/tls13
 crypto/internal/fips140/edwards25519
+image/internal/imageutil
+image/jpeg
+regexp
+internal/syscall/unix
+internal/syscall/execenv
+time
 github.com/go-git/go-git/internal/url
 k8s.io/apimachinery/pkg/version
+crypto/internal/fips140/nistec
+internal/fmtsort
+go.opentelemetry.io/otel/internal/attribute
+encoding/binary
+github.com/modern-go/reflect2
+github.com/google/go-cmp/cmp/internal/function
+sigs.k8s.io/structured-merge-diff/schema
+internal/poll
 google.golang.org/grpc/backoff
-io/fs
-github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v1
+context
 google.golang.org/grpc/keepalive
-k8s.io/klog/internal/clock
-k8s.io/utils/clock
+github.com/aws/smithy-go/ptr
 github.com/aws/aws-sdk-go-v2/internal/timeconv
-context
-github.com/sigstore/gitsign/pkg/predicate
-github.com/jonboulle/clockwork
-github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.2
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.1
+github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.2
+github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v1
 go.uber.org/zap/buffer
-github.com/google/go-cmp/cmp/internal/diff
-github.com/aws/smithy-go/ptr
+k8s.io/klog/internal/clock
+k8s.io/utils/clock
 github.com/google/go-containerregistry/internal/retry/wait
-internal/poll
+github.com/google/go-cmp/cmp/internal/diff
+io/fs
+github.com/jonboulle/clockwork
+github.com/sigstore/gitsign/pkg/predicate
 k8s.io/utils/clock/testing
-crypto/internal/fips140/nistec
 go.uber.org/zap/internal/bufferpool
-embed
-github.com/spf13/afero/internal/common
-internal/filepathlite
+go.uber.org/zap/internal/stacktrace
 google.golang.org/grpc/internal/backoff
-golang.org/x/net/context
 google.golang.org/grpc/internal/grpcsync
+golang.org/x/net/context
 github.com/aws/aws-sdk-go-v2/internal/sdk
 github.com/aws/smithy-go/context
 go.opentelemetry.io/otel/internal/baggage
-go.uber.org/zap/internal/stacktrace
 github.com/jbenet/go-context/io
-internal/fmtsort
-go.opentelemetry.io/otel/internal/attribute
-encoding/binary
-sigs.k8s.io/structured-merge-diff/schema
-github.com/google/go-cmp/cmp/internal/function
+internal/filepathlite
+embed
+github.com/spf13/afero/internal/common
+github.com/go-git/go-git/utils/ioutil
 google.golang.org/protobuf/internal/editiondefaults
-github.com/modern-go/reflect2
 os
-github.com/go-git/go-git/utils/ioutil
 encoding/base64
 vendor/golang.org/x/crypto/internal/poly1305
-github.com/cespare/xxhash
 golang.org/x/crypto/internal/poly1305
-github.com/google/gofuzz/bytesource
+github.com/cespare/xxhash
 github.com/klauspost/compress/internal/snapref
-filippo.io/edwards25519/field
+github.com/google/gofuzz/bytesource
 github.com/golang/snappy
 golang.org/x/sys/unix
+filippo.io/edwards25519/field
+golang.org/x/crypto/nacl/secretbox
 encoding/pem
 golang.org/x/crypto/openpgp/armor
-golang.org/x/crypto/nacl/secretbox
 filippo.io/edwards25519
-io/ioutil
+fmt
+vendor/golang.org/x/sys/cpu
+path/filepath
 google.golang.org/protobuf/internal/detrand
+io/ioutil
+google.golang.org/grpc/internal/envconfig
+golang.org/x/sys/cpu
 github.com/go-git/go-billy/v5
 internal/sysinfo
 go.uber.org/zap/internal/exit
-crypto/internal/sysrand
-google.golang.org/grpc/internal/envconfig
-path/filepath
-internal/lazyregexp
+net
 k8s.io/klog/internal/buffer
-golang.org/x/sys/cpu
-vendor/golang.org/x/sys/cpu
-fmt
+internal/lazyregexp
 os/signal
+crypto/internal/sysrand
 crypto/internal/entropy
+github.com/go-git/go-billy/v5/helper/polyfill
+github.com/go-git/go-billy/v5/util
+github.com/shibumi/go-pathspec
 crypto/internal/fips140/drbg
+github.com/spf13/afero/mem
+os/exec
+k8s.io/client-go/util/homedir
 golang.org/x/crypto/blake2b
 golang.org/x/crypto/sha3
+github.com/go-git/go-billy/v5/helper/chroot
 crypto/internal/fips140only
+crypto/internal/fips140/aes/gcm
 crypto/internal/fips140/ecdh
-crypto/internal/fips140/ed25519
-crypto/internal/fips140/ecdsa
 crypto/internal/fips140/rsa
+crypto/internal/fips140/ecdsa
+crypto/internal/fips140/ed25519
 crypto/internal/fips140/mlkem
-crypto/internal/fips140/aes/gcm
-net
-github.com/go-git/go-billy/v5/helper/polyfill
-github.com/shibumi/go-pathspec
-github.com/go-git/go-billy/v5/util
-os/exec
-github.com/spf13/afero/mem
-k8s.io/client-go/util/homedir
 crypto/rc4
 crypto/md5
-github.com/go-git/go-billy/v5/helper/chroot
 golang.org/x/crypto/argon2
-crypto/cipher
-github.com/mitchellh/go-homedir
-github.com/skratchdot/open-golang/open
-crypto/internal/boring
-crypto/des
-golang.org/x/crypto/chacha20
-github.com/ProtonMail/go-crypto/eax
-vendor/golang.org/x/crypto/chacha20
-github.com/sigstore/cosign/pkg/cosign/env
 github.com/sigstore/cosign/pkg/providers
+github.com/sigstore/cosign/pkg/cosign/env
+compress/flate
+encoding/json
+vendor/golang.org/x/text/unicode/norm
 encoding/hex
-log
 net/url
-net/http/internal
+log
+vendor/golang.org/x/net/http2/hpack
 mime
-text/tabwriter
+mime/quotedprintable
+net/http/internal
+math/big
 os/user
+text/template/parse
+crypto/cipher
+github.com/sigstore/cosign/pkg/providers/envvar
+github.com/sigstore/cosign/pkg/providers/filesystem
+text/tabwriter
 google.golang.org/grpc/internal/grpclog
 google.golang.org/grpc/attributes
-text/template/parse
 google.golang.org/protobuf/internal/errors
-mime/quotedprintable
-google.golang.org/protobuf/internal/version
 go/token
-vendor/golang.org/x/net/http2/hpack
+google.golang.org/protobuf/internal/version
 google.golang.org/grpc/internal/idle
-encoding/json
-compress/flate
 golang.org/x/net/http2/hpack
-go.opencensus.io/trace/tracestate
-runtime/trace
-go.opencensus.io/resource
-math/big
-github.com/zeebo/errs
-github.com/ProtonMail/go-crypto/openpgp/errors
-dario.cat/mergo
 golang.org/x/text/unicode/norm
-github.com/pjbgf/sha1cd
-github.com/src-d/gcfg/token
-encoding/gob
-crypto/aes
+google.golang.org/protobuf/encoding/protowire
 go.opencensus.io/internal
-vendor/golang.org/x/text/unicode/norm
-github.com/go-jose/go-jose/json
+go.opencensus.io/trace/tracestate
+crypto/internal/boring
+crypto/des
+vendor/golang.org/x/crypto/chacha20
+google.golang.org/protobuf/reflect/protoreflect
+crypto/aes
 crypto/ecdh
 crypto/sha512
 crypto/hmac
 crypto/sha1
 crypto/sha256
-github.com/sigstore/cosign/pkg/providers/envvar
-github.com/sigstore/cosign/pkg/providers/filesystem
-google.golang.org/protobuf/encoding/protowire
-github.com/src-d/gcfg/types
+golang.org/x/net/internal/timeseries
+vendor/golang.org/x/text/unicode/bidi
+golang.org/x/text/unicode/bidi
+runtime/trace
+go.opencensus.io/resource
 vendor/golang.org/x/crypto/chacha20poly1305
-gopkg.in/warnings.v0
-github.com/ProtonMail/go-crypto/ocb
+github.com/go-jose/go-jose/json
+go.opencensus.io/metric/metricdata
+golang.org/x/crypto/pbkdf2
+github.com/spiffe/go-spiffe/v2/spiffeid
+github.com/zeebo/errs
+github.com/spiffe/go-spiffe/v2/logger
+dario.cat/mergo
+compress/gzip
+github.com/ProtonMail/go-crypto/openpgp/errors
+go.opencensus.io/metric/metricproducer
 github.com/ProtonMail/go-crypto/openpgp/aes/keywrap
+github.com/ProtonMail/go-crypto/eax
+github.com/ProtonMail/go-crypto/ocb
+compress/zlib
+golang.org/x/crypto/hkdf
+github.com/ProtonMail/go-crypto/openpgp/armor
+runtime/pprof
+github.com/cyphar/filepath-securejoin
+github.com/pjbgf/sha1cd
+encoding/gob
+github.com/src-d/gcfg/token
+vendor/golang.org/x/text/secure/bidirule
+github.com/src-d/gcfg/types
+gopkg.in/warnings.v0
+github.com/go-git/go-git/internal/revision
+github.com/go-git/go-git/plumbing/hash
+github.com/ProtonMail/go-crypto/openpgp/internal/algorithm
 github.com/go-git/go-git/plumbing/filemode
+github.com/go-git/go-git/utils/sync
+github.com/go-git/go-git/plumbing
+github.com/src-d/gcfg/scanner
 github.com/emirpasic/gods/utils
+vendor/golang.org/x/net/idna
+github.com/sergi/go-diff/diffmatchpatch
 github.com/go-git/go-git/utils/merkletrie/noder
-github.com/go-git/go-git/internal/revision
-github.com/ProtonMail/go-crypto/openpgp/armor
+golang.org/x/text/secure/bidirule
+github.com/ProtonMail/go-crypto/openpgp/s2k
+github.com/go-git/go-git/utils/trace
 github.com/go-git/go-git/plumbing/protocol/packp/capability
+github.com/emirpasic/gods/containers
+github.com/go-git/go-git/utils/merkletrie/internal/frame
+text/template
+golang.org/x/net/idna
 golang.org/x/sys/execabs
-github.com/src-d/gcfg/scanner
-go.opencensus.io/metric/metricdata
+github.com/go-git/go-git/plumbing/format/pktline
+google.golang.org/protobuf/internal/encoding/messageset
+google.golang.org/protobuf/internal/genid
+google.golang.org/protobuf/internal/order
+google.golang.org/protobuf/internal/strs
+google.golang.org/protobuf/runtime/protoiface
+google.golang.org/protobuf/reflect/protoregistry
+google.golang.org/protobuf/internal/descfmt
+google.golang.org/protobuf/internal/descopts
+github.com/go-git/go-git/plumbing/cache
+github.com/go-git/go-git/utils/binary
+github.com/go-git/go-billy/v5/osfs
+google.golang.org/grpc/grpclog
+github.com/emirpasic/gods/lists
+google.golang.org/protobuf/internal/protolazy
+google.golang.org/protobuf/internal/encoding/text
+google.golang.org/protobuf/internal/encoding/json
+github.com/emirpasic/gods/lists/arraylist
+github.com/go-git/go-git/plumbing/format/index
+github.com/go-git/go-git/plumbing/format/idxfile
+github.com/emirpasic/gods/trees
+github.com/emirpasic/gods/trees/binaryheap
+github.com/go-git/go-git/plumbing/format/diff
+google.golang.org/protobuf/proto
+github.com/go-git/go-git/plumbing/storer
+github.com/go-git/go-git/utils/diff
+google.golang.org/grpc/connectivity
+github.com/go-git/go-git/utils/merkletrie
+github.com/go-git/go-git/plumbing/protocol/packp/sideband
+golang.org/x/crypto/chacha20
+golang.org/x/crypto/curve25519
 golang.org/x/crypto/ssh/internal/bcrypt_pbkdf
+github.com/go-git/go-git/utils/merkletrie/filesystem
+github.com/go-git/go-git/utils/merkletrie/index
+crypto/rand
+crypto/elliptic
+crypto/internal/boring/bbig
+encoding/asn1
+crypto/dsa
+crypto/ed25519
+crypto/internal/hpke
+go.opencensus.io/trace
+crypto/rsa
+google.golang.org/protobuf/internal/encoding/defval
+github.com/ProtonMail/go-crypto/openpgp/internal/encoding
+github.com/cloudflare/circl/math
+github.com/ProtonMail/go-crypto/openpgp/elgamal
+github.com/go-git/go-git/plumbing/format/packfile
+github.com/aws/aws-sdk-go-v2/internal/rand
+github.com/aws/smithy-go/logging
 runtime/debug
 github.com/aws/smithy-go
-github.com/aws/aws-sdk-go-v2/aws/ratelimit
-golang.org/x/crypto/pbkdf2
-golang.org/x/crypto/hkdf
+github.com/aws/smithy-go/time
+github.com/aws/smithy-go/rand
+github.com/aws/smithy-go/middleware
 github.com/aws/aws-sdk-go-v2/feature/ec2/imds/internal/config
+github.com/aws/smithy-go/document
+github.com/aws/aws-sdk-go-v2/aws/ratelimit
 github.com/aws/smithy-go/encoding
-golang.org/x/crypto/curve25519
+github.com/aws/smithy-go/auth
+github.com/go-git/go-git/internal/path_util
 encoding/xml
+github.com/kevinburke/ssh_config
+github.com/aws/aws-sdk-go-v2/internal/shareddefaults
+github.com/aws/aws-sdk-go-v2/aws/protocol/restjson
 github.com/aws/aws-sdk-go-v2/internal/ini
-go.opencensus.io/metric/metricproducer
-github.com/emirpasic/gods/containers
+github.com/jmespath/go-jmespath
+github.com/mitchellh/go-homedir
+github.com/aws/aws-sdk-go-v2/internal/sync/singleflight
+github.com/aws/smithy-go/internal/sync/singleflight
+go.opencensus.io/tag
+github.com/aws/aws-sdk-go-v2/service/sso/types
+github.com/aws/aws-sdk-go-v2/service/ssooidc/types
+github.com/aws/smithy-go/encoding/json
+golang.org/x/oauth2/jws
+github.com/aws/aws-sdk-go-v2/service/sts/types
+github.com/aws/aws-sdk-go-v2/service/ecr/types
+github.com/aws/aws-sdk-go-v2/service/ecrpublic/types
+github.com/sirupsen/logrus
+google.golang.org/protobuf/internal/filedesc
+google.golang.org/protobuf/encoding/prototext
+github.com/docker/docker-credential-helpers/credentials
+html/template
+github.com/ProtonMail/go-crypto/bitcurves
+github.com/ProtonMail/go-crypto/brainpool
 github.com/pkg/errors
+github.com/docker/docker-credential-helpers/client
+github.com/docker/docker/pkg/homedir
+go.opencensus.io/stats/internal
 github.com/opencontainers/go-digest
-github.com/go-git/go-git/utils/merkletrie/internal/frame
+github.com/google/go-containerregistry/pkg/logs
+go.opencensus.io/stats
+vendor/golang.org/x/crypto/cryptobyte
+crypto/x509/pkix
+golang.org/x/crypto/cryptobyte
+github.com/google/go-containerregistry/internal/redact
+github.com/aws/aws-sdk-go-v2/aws/middleware/private/metrics
+go.opencensus.io/stats/view
+github.com/aws/aws-sdk-go-v2/internal/context
+github.com/aws/smithy-go/waiter
+github.com/docker/cli/cli/config/credentials
 github.com/google/go-containerregistry/internal/retry
+github.com/google/go-containerregistry/pkg/v1
+github.com/aws/aws-sdk-go-v2/internal/middleware
+github.com/google/go-containerregistry/internal/gzip
 github.com/klauspost/compress/fse
-google.golang.org/protobuf/reflect/protoreflect
 github.com/opencontainers/image-spec/specs-go
+archive/tar
 github.com/containerd/stargz-snapshotter/estargz/errorutil
-vendor/golang.org/x/text/unicode/bidi
-golang.org/x/net/internal/timeseries
-github.com/spiffe/go-spiffe/v2/logger
-golang.org/x/text/unicode/bidi
-github.com/ProtonMail/go-crypto/openpgp/internal/algorithm
-github.com/go-git/go-git/utils/trace
-github.com/emirpasic/gods/lists
-github.com/emirpasic/gods/trees
-github.com/aws/smithy-go/logging
-github.com/spiffe/go-spiffe/v2/spiffeid
-github.com/sergi/go-diff/diffmatchpatch
-compress/gzip
-compress/zlib
-github.com/google/go-containerregistry/pkg/logs
-github.com/google/go-containerregistry/internal/redact
 golang.org/x/sync/errgroup
-github.com/go-git/go-git/utils/merkletrie
+github.com/vbatts/tar-split/archive/tar
+github.com/opencontainers/image-spec/specs-go/v1
 flag
-github.com/aws/smithy-go/auth
-github.com/go-git/go-git/plumbing/hash
+github.com/secure-systems-lab/go-securesystemslib/cjson
+github.com/src-d/gcfg
 encoding/csv
+crypto/ecdsa
 database/sql/driver
+go.mongodb.org/mongo-driver/bson/primitive
+github.com/mailru/easyjson/jlexer
 gopkg.in/yaml.v3
 github.com/go-openapi/analysis/internal/debug
+github.com/cloudflare/circl/internal/conv
+github.com/google/go-containerregistry/internal/verify
+github.com/google/go-containerregistry/pkg/v1/match
+github.com/go-git/go-git/plumbing/format/objfile
+github.com/google/go-containerregistry/pkg/v1/stream
+github.com/klauspost/compress/huff0
+github.com/cloudflare/circl/math/fp25519
+github.com/cloudflare/circl/math/fp448
+github.com/cloudflare/circl/math/mlsbset
+go.mongodb.org/mongo-driver/x/bsonx/bsoncore
 github.com/go-openapi/jsonreference/internal
-github.com/go-git/go-git/plumbing/format/pktline
-github.com/opencontainers/image-spec/specs-go/v1
+github.com/oklog/ulid
+github.com/awslabs/amazon-ecr-credential-helper/ecr-login/config
+github.com/blang/semver
+github.com/docker/cli/cli/config/configfile
+testing
 github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer
+internal/profile
+go.uber.org/atomic
+github.com/cloudflare/circl/dh/x25519
+github.com/go-git/go-git/plumbing/format/config
+github.com/aws/aws-sdk-go-v2/aws/protocol/xml
+github.com/cloudflare/circl/sign/ed25519
+github.com/aws/smithy-go/encoding/xml
 go.uber.org/zap/internal/color
+github.com/cloudflare/circl/dh/x448
+github.com/cloudflare/circl/ecc/goldilocks
+github.com/docker/cli/cli/config
+golang.org/x/crypto/ed25519
+github.com/go-jose/go-jose/cipher
+github.com/spiffe/go-spiffe/v2/internal/cryptoutil
+github.com/jedisct1/go-minisign
+github.com/spiffe/go-spiffe/v2/internal/jwtutil
+github.com/go-git/go-git/config
+github.com/go-git/go-git/plumbing/format/gitignore
 golang.org/x/crypto/scrypt
-github.com/ProtonMail/go-crypto/openpgp/s2k
+golang.org/x/term
+github.com/sigstore/sigstore/pkg/signature/options
+go.uber.org/multierr
+golang.org/x/crypto/openpgp/elgamal
+github.com/secure-systems-lab/go-securesystemslib/encrypted
+github.com/klauspost/compress/zstd
+github.com/ProtonMail/go-crypto/openpgp/x25519
+go.uber.org/zap/zapcore
+google.golang.org/protobuf/internal/encoding/tag
+google.golang.org/protobuf/encoding/protojson
+github.com/google/certificate-transparency-go/asn1
+golang.org/x/crypto/openpgp/packet
+log/slog
 github.com/nozzle/throttler
-github.com/aws/aws-sdk-go-v2/internal/sync/singleflight
-github.com/aws/smithy-go/internal/sync/singleflight
 github.com/sigstore/cosign/internal/pkg/oci/remote
-github.com/aws/smithy-go/middleware
 github.com/sigstore/cosign/internal/ui
+github.com/dustin/go-humanize
+github.com/go-git/go-git/storage
+github.com/cloudflare/circl/sign/ed448
+google.golang.org/protobuf/internal/impl
+github.com/go-git/go-git/storage/memory
+github.com/go-git/go-git/storage/filesystem/dotgit
+github.com/google/go-containerregistry/pkg/v1/static
+github.com/ProtonMail/go-crypto/openpgp/ed25519
 github.com/sigstore/cosign/internal/pkg/now
 github.com/go-openapi/runtime/logger
 github.com/opentracing/opentracing-go/log
+github.com/ProtonMail/go-crypto/openpgp/ed448
+go.mongodb.org/mongo-driver/bson/bsonrw
+go.opentelemetry.io/otel/attribute
+go.opentelemetry.io/otel/codes
 go.opentelemetry.io/otel/baggage
-runtime/pprof
-github.com/go-git/go-git/plumbing
-github.com/google/go-containerregistry/internal/gzip
-internal/profile
-github.com/go-git/go-git/utils/sync
+github.com/sigstore/cosign/internal/pkg/cosign/payload/size
+golang.org/x/mod/sumdb/note
+github.com/fsnotify/fsnotify/internal
+github.com/spf13/cast
+github.com/go-git/go-git/plumbing/protocol/packp
+github.com/ProtonMail/go-crypto/openpgp/internal/ecc
+github.com/ProtonMail/go-crypto/openpgp/x448
 github.com/spf13/jwalterweatherman
 github.com/subosito/gotenv
+github.com/fsnotify/fsnotify
 github.com/hashicorp/hcl/hcl/token
-github.com/klauspost/compress/huff0
-github.com/pelletier/go-toml/v2/internal/danger
 gopkg.in/ini.v1
-github.com/go-git/go-git/plumbing/protocol/packp/sideband
+github.com/spf13/viper/internal/encoding/json
+github.com/go-logr/logr
+k8s.io/klog/internal/sloghandler
+go.opentelemetry.io/otel/metric
+go.opentelemetry.io/otel/trace
+go.opentelemetry.io/otel/semconv/v1.17.0
+github.com/google/certificate-transparency-go/tls
+github.com/google/certificate-transparency-go/x509/pkix
+k8s.io/klog/internal/serialize
+github.com/go-logr/logr/funcr
+github.com/ProtonMail/go-crypto/openpgp/ecdh
+github.com/ProtonMail/go-crypto/openpgp/ecdsa
+github.com/ProtonMail/go-crypto/openpgp/eddsa
+github.com/hashicorp/hcl/hcl/ast
+github.com/go-git/go-git/plumbing/transport
+github.com/ProtonMail/go-crypto/openpgp/packet
+k8s.io/klog
+github.com/hashicorp/hcl/hcl/scanner
+github.com/hashicorp/hcl/json/token
+github.com/spf13/viper/internal/encoding/dotenv
+github.com/go-git/go-git/plumbing/transport/internal/common
+github.com/pelletier/go-toml/v2/internal/danger
+github.com/hashicorp/hcl/json/scanner
+github.com/spf13/viper/internal/encoding/yaml
+github.com/theupdateframework/go-tuf/v0/data
+github.com/spf13/viper/internal/encoding/ini
 github.com/theupdateframework/go-tuf/v0/internal/fsutil
+github.com/go-git/go-git/storage/filesystem
+github.com/pelletier/go-toml/v2/unstable
+github.com/hashicorp/hcl/hcl/parser
+github.com/hashicorp/hcl/json/parser
 github.com/syndtr/goleveldb/leveldb/util
+golang.org/x/crypto/openpgp
+github.com/syndtr/goleveldb/leveldb/storage
+github.com/theupdateframework/go-tuf/v0/util
 github.com/transparency-dev/merkle/compact
 github.com/transparency-dev/merkle/rfc6962
+github.com/go-logr/stdr
+github.com/hashicorp/hcl/hcl/printer
 github.com/google/go-querystring/query
-github.com/syndtr/goleveldb/leveldb/storage
+golang.org/x/crypto/nacl/box
+github.com/transparency-dev/merkle/proof
+github.com/syndtr/goleveldb/leveldb/cache
+github.com/syndtr/goleveldb/leveldb/filter
 golang.org/x/time/rate
+go.uber.org/zap/internal
+github.com/hashicorp/hcl
+gopkg.in/inf.v0
+github.com/gogo/protobuf/proto
+github.com/fxamacker/cbor
 github.com/google/gofuzz
+github.com/syndtr/goleveldb/leveldb/opt
 k8s.io/apimachinery/third_party/forked/golang/reflect
 k8s.io/apimachinery/pkg/fields
-k8s.io/apimachinery/pkg/util/errors
-github.com/hashicorp/hcl/hcl/ast
 go/scanner
-github.com/hashicorp/hcl/hcl/scanner
-github.com/hashicorp/hcl/json/token
+k8s.io/apimachinery/pkg/util/errors
 go/doc/comment
-golang.org/x/text/secure/bidirule
 k8s.io/apimachinery/pkg/conversion/queryparams
-github.com/oklog/ulid
+github.com/pelletier/go-toml/v2/internal/tracker
+sigs.k8s.io/json/internal/golang/encoding/json
 k8s.io/apimachinery/pkg/util/naming
-github.com/go-git/go-git/utils/diff
-github.com/go-git/go-git/plumbing/cache
-vendor/golang.org/x/text/secure/bidirule
-github.com/go-git/go-git/utils/binary
-github.com/go-git/go-git/plumbing/format/diff
-github.com/go-git/go-git/utils/merkletrie/filesystem
-github.com/pelletier/go-toml/v2/unstable
-testing
 github.com/modern-go/concurrent
-github.com/transparency-dev/merkle/proof
+go.mongodb.org/mongo-driver/bson/bsoncodec
 gopkg.in/yaml.v2
-text/template
-golang.org/x/net/idna
-github.com/aws/aws-sdk-go-v2/internal/context
+go/ast
+github.com/pelletier/go-toml/v2
+k8s.io/apimachinery/pkg/conversion
+github.com/spf13/viper/internal/encoding/hcl
+k8s.io/apimachinery/pkg/util/validation/field
 k8s.io/utils/ptr
-vendor/golang.org/x/net/idna
+github.com/syndtr/goleveldb/leveldb/errors
 k8s.io/apimachinery/pkg/util/version
-github.com/hashicorp/hcl/json/scanner
+github.com/google/gnostic-models/jsonschema
+github.com/syndtr/goleveldb/leveldb/iterator
+github.com/syndtr/goleveldb/leveldb/journal
+k8s.io/apimachinery/pkg/util/framer
 sigs.k8s.io/yaml/goyaml.v2
+github.com/json-iterator/go
+k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json
 k8s.io/client-go/pkg/version
-k8s.io/apimachinery/pkg/util/validation/field
 github.com/davecgh/go-spew/spew
-github.com/go-git/go-git/plumbing/format/index
-k8s.io/kube-openapi/pkg/internal/third_party/go-json-experiment/json
-github.com/go-git/go-git/plumbing/format/idxfile
-github.com/aws/aws-sdk-go-v2/internal/middleware
 k8s.io/client-go/tools/metrics
-github.com/aws/aws-sdk-go-v2/aws/protocol/xml
-google.golang.org/protobuf/internal/encoding/messageset
-google.golang.org/grpc/grpclog
-google.golang.org/protobuf/internal/order
-google.golang.org/protobuf/internal/genid
-google.golang.org/protobuf/internal/strs
-google.golang.org/protobuf/runtime/protoiface
-google.golang.org/protobuf/internal/descfmt
-google.golang.org/protobuf/internal/descopts
-github.com/emirpasic/gods/lists/arraylist
-github.com/aws/aws-sdk-go-v2/aws/middleware/private/metrics
-github.com/aws/aws-sdk-go-v2/aws/protocol/restjson
-github.com/cyphar/filepath-securejoin
-github.com/jmespath/go-jmespath
-github.com/sirupsen/logrus
-github.com/docker/docker-credential-helpers/credentials
-github.com/google/go-containerregistry/pkg/v1
-github.com/secure-systems-lab/go-securesystemslib/cjson
-github.com/mailru/easyjson/jlexer
-github.com/blang/semver
-google.golang.org/protobuf/internal/protolazy
-google.golang.org/protobuf/reflect/protoregistry
-go.uber.org/atomic
-golang.org/x/term
-log/slog
-go.opentelemetry.io/otel/attribute
-go.opentelemetry.io/otel/codes
-google.golang.org/protobuf/internal/encoding/text
-google.golang.org/protobuf/internal/encoding/json
-go.opencensus.io/tag
-github.com/docker/docker-credential-helpers/client
-github.com/fsnotify/fsnotify/internal
-github.com/hashicorp/hcl/hcl/parser
-github.com/hashicorp/hcl/json/parser
-github.com/emirpasic/gods/trees/binaryheap
-github.com/go-git/go-git/plumbing/storer
-crypto/rand
-crypto/internal/boring/bbig
-github.com/spf13/viper/internal/encoding/json
-crypto/elliptic
-encoding/asn1
-crypto/dsa
-google.golang.org/grpc/connectivity
-github.com/ProtonMail/go-crypto/openpgp/internal/encoding
-github.com/src-d/gcfg
-github.com/go-git/go-git/utils/merkletrie/index
-github.com/aws/smithy-go/time
-crypto/ed25519
-crypto/internal/hpke
-crypto/rsa
-go.opencensus.io/trace
-github.com/cloudflare/circl/math
-github.com/ProtonMail/go-crypto/openpgp/elgamal
-github.com/aws/aws-sdk-go-v2/internal/rand
-github.com/aws/smithy-go/rand
-github.com/aws/smithy-go/document
-github.com/go-git/go-git/plumbing/format/packfile
-github.com/aws/smithy-go/encoding/json
-github.com/aws/smithy-go/encoding/xml
-github.com/docker/cli/cli/config/credentials
-go.uber.org/multierr
-go.mongodb.org/mongo-driver/bson/primitive
-github.com/klauspost/compress/zstd
-github.com/secure-systems-lab/go-securesystemslib/encrypted
-go.opencensus.io/stats/internal
-golang.org/x/crypto/ed25519
-golang.org/x/crypto/openpgp/elgamal
-github.com/google/certificate-transparency-go/asn1
-github.com/aws/smithy-go/waiter
-github.com/dustin/go-humanize
-go.opencensus.io/stats
-golang.org/x/mod/sumdb/note
-github.com/hashicorp/hcl
-github.com/hashicorp/hcl/hcl/printer
-github.com/jedisct1/go-minisign
-github.com/fsnotify/fsnotify
-google.golang.org/protobuf/proto
-github.com/pelletier/go-toml/v2/internal/tracker
-github.com/aws/aws-sdk-go-v2/service/sso/types
-google.golang.org/protobuf/internal/encoding/defval
-github.com/aws/aws-sdk-go-v2/service/ssooidc/types
-github.com/aws/aws-sdk-go-v2/service/sts/types
-github.com/aws/aws-sdk-go-v2/service/ecr/types
-github.com/aws/aws-sdk-go-v2/service/ecrpublic/types
-go.uber.org/zap/zapcore
-github.com/go-git/go-git/plumbing/format/config
-go.opentelemetry.io/otel/metric
-github.com/ProtonMail/go-crypto/bitcurves
-github.com/ProtonMail/go-crypto/brainpool
-go.opentelemetry.io/otel/trace
-go.opencensus.io/stats/view
-github.com/google/go-containerregistry/internal/verify
-github.com/google/go-containerregistry/pkg/v1/match
-github.com/go-git/go-billy/v5/osfs
-github.com/google/go-containerregistry/pkg/v1/stream
-github.com/google/go-containerregistry/pkg/v1/static
-golang.org/x/oauth2/jws
-github.com/sigstore/sigstore/pkg/signature/options
-go.opentelemetry.io/otel/semconv/v1.17.0
-github.com/theupdateframework/go-tuf/v0/data
-github.com/syndtr/goleveldb/leveldb/cache
-github.com/syndtr/goleveldb/leveldb/errors
-github.com/syndtr/goleveldb/leveldb/filter
-golang.org/x/crypto/nacl/box
-gopkg.in/inf.v0
-github.com/gogo/protobuf/proto
-github.com/fxamacker/cbor
-github.com/awslabs/amazon-ecr-credential-helper/ecr-login/config
-github.com/docker/cli/cli/config/configfile
-github.com/spf13/viper/internal/encoding/hcl
-github.com/syndtr/goleveldb/leveldb/journal
-github.com/syndtr/goleveldb/leveldb/iterator
-k8s.io/apimachinery/pkg/conversion
-github.com/sigstore/cosign/internal/pkg/cosign/payload/size
-go/ast
-sigs.k8s.io/json/internal/golang/encoding/json
-k8s.io/apimachinery/pkg/util/framer
-go.mongodb.org/mongo-driver/x/bsonx/bsoncore
-github.com/json-iterator/go
-vendor/golang.org/x/crypto/cryptobyte
-crypto/x509/pkix
-golang.org/x/crypto/cryptobyte
-github.com/theupdateframework/go-tuf/v0/util
-github.com/pelletier/go-toml/v2
-k8s.io/apimachinery/pkg/util/dump
 k8s.io/client-go/util/flowcontrol
-github.com/go-logr/logr
-k8s.io/klog/internal/sloghandler
 k8s.io/kube-openapi/pkg/cached
-github.com/emicklei/go-restful/log
-github.com/google/go-cmp/cmp/internal/value
-github.com/syndtr/goleveldb/leveldb/opt
-github.com/google/certificate-transparency-go/x509/pkix
-github.com/imdario/mergo
-html/template
 github.com/syndtr/goleveldb/leveldb/memdb
-github.com/spf13/viper/internal/encoding/yaml
-github.com/google/gnostic-models/jsonschema
-gopkg.in/square/go-jose.v2/json
-github.com/go-jose/go-jose/v3/json
-github.com/sigstore/sigstore/pkg/oauth
-github.com/segmentio/ksuid
-go.step.sm/crypto/internal/utils
-github.com/common-nighthawk/go-figure
-go.step.sm/crypto/fingerprint
-go.step.sm/crypto/x25519
-go.step.sm/crypto/internal/bcrypt_pbkdf
 github.com/syndtr/goleveldb/leveldb/table
-go.step.sm/crypto/randutil
-github.com/go-git/go-git/config
-github.com/sigstore/gitsign/internal/config
-github.com/sigstore/gitsign/pkg/version
-github.com/google/trillian/types/internal/tls
-github.com/mattn/go-tty
-github.com/patrickmn/go-cache
-google.golang.org/protobuf/internal/filedesc
-google.golang.org/protobuf/encoding/prototext
-github.com/go-git/go-git/plumbing/format/objfile
-github.com/google/go-cmp/cmp
-github.com/russross/blackfriday/v2
-crypto/ecdsa
-k8s.io/klog/internal/serialize
-github.com/go-logr/logr/funcr
-github.com/cloudflare/circl/internal/conv
-github.com/sigstore/gitsign/internal/cache/api
-github.com/go-git/go-git/internal/path_util
-github.com/kevinburke/ssh_config
-github.com/aws/aws-sdk-go-v2/internal/shareddefaults
-github.com/docker/docker/pkg/homedir
-github.com/cloudflare/circl/math/fp25519
-github.com/cloudflare/circl/math/fp448
-github.com/cloudflare/circl/math/mlsbset
-archive/tar
-github.com/vbatts/tar-split/archive/tar
-github.com/go-git/go-git/plumbing/format/gitignore
-k8s.io/klog
-github.com/docker/cli/cli/config
-github.com/sigstore/gitsign/internal/io
-github.com/go-git/go-git/storage
-github.com/syndtr/goleveldb/leveldb
-github.com/go-git/go-git/storage/memory
-github.com/go-git/go-git/storage/filesystem/dotgit
-github.com/go-logr/stdr
-github.com/cloudflare/circl/ecc/goldilocks
-github.com/cloudflare/circl/dh/x448
-go.uber.org/zap/internal
-sigs.k8s.io/yaml
-github.com/cloudflare/circl/dh/x25519
-github.com/cloudflare/circl/sign/ed25519
-github.com/spf13/viper/internal/encoding/toml
-github.com/go-git/go-git/plumbing/protocol/packp
-go/doc
-go/parser
-go.mongodb.org/mongo-driver/bson/bsonrw
-github.com/spf13/cast
-github.com/ProtonMail/go-crypto/openpgp/x25519
-github.com/ProtonMail/go-crypto/openpgp/ed25519
-github.com/spiffe/go-spiffe/v2/internal/cryptoutil
-golang.org/x/crypto/openpgp/packet
-github.com/google/certificate-transparency-go/tls
-gopkg.in/square/go-jose.v2/cipher
-github.com/go-jose/go-jose/v3/cipher
-github.com/go-jose/go-jose/cipher
-github.com/go-git/go-git/storage/filesystem
-github.com/spiffe/go-spiffe/v2/internal/jwtutil
-github.com/cpuguy83/go-md2man/v2/md2man
-github.com/ProtonMail/go-crypto/openpgp/x448
-github.com/cloudflare/circl/sign/ed448
-google.golang.org/protobuf/internal/encoding/tag
-google.golang.org/protobuf/encoding/protojson
-sigs.k8s.io/json
-k8s.io/apimachinery/pkg/util/json
-github.com/go-git/go-git/plumbing/transport
-github.com/spf13/viper/internal/encoding/dotenv
-github.com/spf13/viper/internal/encoding/ini
-github.com/ProtonMail/go-crypto/openpgp/ed448
-github.com/ProtonMail/go-crypto/openpgp/internal/ecc
-google.golang.org/protobuf/internal/impl
-k8s.io/apimachinery/pkg/util/yaml
-github.com/go-git/go-git/plumbing/transport/internal/common
-k8s.io/apimachinery/pkg/runtime/serializer/cbor/internal/modes
-github.com/ProtonMail/go-crypto/openpgp/ecdh
-github.com/ProtonMail/go-crypto/openpgp/ecdsa
-github.com/ProtonMail/go-crypto/openpgp/eddsa
-github.com/google/go-containerregistry/internal/zstd
-github.com/containerd/stargz-snapshotter/estargz
-github.com/ProtonMail/go-crypto/openpgp/packet
-golang.org/x/crypto/openpgp
-go.mongodb.org/mongo-driver/bson/bsoncodec
-github.com/google/go-containerregistry/internal/compression
-github.com/google/go-containerregistry/pkg/v1/partial
-sigs.k8s.io/structured-merge-diff/value
-k8s.io/apimachinery/pkg/runtime/serializer/cbor/direct
-github.com/google/go-containerregistry/pkg/v1/empty
-github.com/ProtonMail/go-crypto/openpgp
-net/textproto
 crypto/x509
+net/textproto
 vendor/golang.org/x/net/http/httpproxy
 google.golang.org/grpc/internal
-google.golang.org/grpc/internal/resolver/dns/internal
-golang.org/x/net/internal/socks
-github.com/mitchellh/mapstructure
-github.com/mailru/easyjson/buffer
-github.com/google/uuid
 google.golang.org/grpc/internal/syscall
+google.golang.org/grpc/internal/resolver/dns/internal
+github.com/ProtonMail/go-crypto/openpgp
 github.com/go-git/go-git/plumbing/transport/git
-k8s.io/client-go/util/connrotation
-k8s.io/utils/internal/third_party/forked/golang/net
-github.com/google/go-containerregistry/pkg/name
-github.com/google/certificate-transparency-go/x509
-github.com/spf13/pflag
-sigs.k8s.io/structured-merge-diff/fieldpath
-k8s.io/utils/net
-github.com/mailru/easyjson/jwriter
 google.golang.org/grpc/metadata
 google.golang.org/grpc/codes
-golang.org/x/net/proxy
+golang.org/x/net/internal/socks
+github.com/google/go-containerregistry/pkg/name
+github.com/google/uuid
 vendor/golang.org/x/net/http/httpguts
-golang.org/x/net/http/httpguts
 mime/multipart
-net/mail
-google.golang.org/grpc/internal/balancerload
 google.golang.org/grpc/internal/grpcutil
+google.golang.org/grpc/internal/balancerload
+golang.org/x/net/http/httpguts
 google.golang.org/grpc/stats
 google.golang.org/grpc/tap
-github.com/sigstore/sigstore/pkg/signature/payload
-github.com/google/go-containerregistry/pkg/authn
 google.golang.org/grpc/encoding
-k8s.io/apimachinery/pkg/util/validation
+github.com/google/go-containerregistry/internal/zstd
+github.com/containerd/stargz-snapshotter/estargz
+github.com/mitchellh/mapstructure
+github.com/google/go-containerregistry/internal/compression
+net/mail
+golang.org/x/net/proxy
+github.com/google/go-containerregistry/pkg/v1/partial
+github.com/google/go-containerregistry/pkg/authn
+github.com/mailru/easyjson/buffer
+github.com/sigstore/sigstore/pkg/signature/payload
+github.com/mailru/easyjson/jwriter
+github.com/spf13/pflag
+github.com/google/certificate-transparency-go/x509
+github.com/spf13/viper/internal/encoding/toml
+github.com/syndtr/goleveldb/leveldb
+k8s.io/utils/internal/third_party/forked/golang/net
+github.com/google/go-containerregistry/pkg/v1/empty
+k8s.io/utils/net
 github.com/google/go-containerregistry/pkg/authn/github
-k8s.io/apimachinery/pkg/runtime/schema
-k8s.io/apimachinery/pkg/util/intstr
-k8s.io/apimachinery/pkg/api/resource
-go.mongodb.org/mongo-driver/bson
+go/parser
+go/doc
+k8s.io/apimachinery/pkg/util/dump
+k8s.io/client-go/util/connrotation
+github.com/emicklei/go-restful/log
+github.com/google/go-cmp/cmp/internal/value
+k8s.io/apimachinery/pkg/util/validation
+github.com/google/go-cmp/cmp
 github.com/go-git/go-git/plumbing/object
 k8s.io/apimachinery/pkg/labels
-github.com/google/go-containerregistry/internal/estargz
-github.com/google/go-containerregistry/pkg/v1/tarball
-sigs.k8s.io/structured-merge-diff/typed
-github.com/google/go-containerregistry/pkg/v1/mutate
-github.com/google/go-containerregistry/pkg/v1/layout
-github.com/spiffe/go-spiffe/v2/internal/x509util
-github.com/spiffe/go-spiffe/v2/internal/pemutil
-github.com/sigstore/gitsign/internal
-github.com/digitorus/pkcs7
-github.com/secure-systems-lab/go-securesystemslib/signerverifier
-gopkg.in/square/go-jose.v2
-github.com/go-jose/go-jose/v3
-k8s.io/client-go/util/keyutil
+sigs.k8s.io/yaml
+sigs.k8s.io/json
+github.com/imdario/mergo
+k8s.io/apimachinery/pkg/util/json
+github.com/common-nighthawk/go-figure
+k8s.io/apimachinery/pkg/util/yaml
+gopkg.in/square/go-jose.v2/cipher
+gopkg.in/square/go-jose.v2/json
+github.com/go-jose/go-jose/v3/cipher
+github.com/go-jose/go-jose/v3/json
+github.com/segmentio/ksuid
+github.com/sigstore/sigstore/pkg/oauth
+k8s.io/apimachinery/pkg/runtime/serializer/cbor/internal/modes
+go.step.sm/crypto/internal/utils
+github.com/skratchdot/open-golang/open
+go.step.sm/crypto/fingerprint
+crypto/tls
 github.com/go-jose/go-jose
-github.com/github/smimesign/ietf-cms/oid
-github.com/theupdateframework/go-tuf/v0/pkg/keys
-github.com/sigstore/sigstore/pkg/cryptoutils
+github.com/spiffe/go-spiffe/v2/internal/pemutil
+github.com/spiffe/go-spiffe/v2/internal/x509util
 golang.org/x/crypto/ssh
-github.com/asaskevich/govalidator
-crypto/tls
-github.com/google/certificate-transparency-go
-github.com/sigstore/gitsign/internal/gpg
 github.com/spiffe/go-spiffe/v2/bundle/x509bundle
-github.com/github/smimesign/ietf-cms/protocol
-github.com/spf13/cobra
-github.com/go-git/go-git/plumbing/revlist
-github.com/sigstore/gitsign/internal/git/gittest
-github.com/sigstore/sigstore/pkg/signature
+github.com/secure-systems-lab/go-securesystemslib/signerverifier
 github.com/spiffe/go-spiffe/v2/svid/x509svid
-github.com/google/certificate-transparency-go/gossip/minimal/x509ext
-github.com/sigstore/cosign/pkg/cosign/fulcioverifier/ctutil
-github.com/digitorus/timestamp
+github.com/asaskevich/govalidator
+go.mongodb.org/mongo-driver/bson
+github.com/sigstore/sigstore/pkg/cryptoutils
+github.com/go-git/go-git/plumbing/revlist
+github.com/spf13/cobra
+github.com/digitorus/pkcs7
+github.com/theupdateframework/go-tuf/v0/pkg/keys
+k8s.io/apimachinery/pkg/runtime/serializer/cbor/direct
+k8s.io/client-go/util/keyutil
 github.com/go-git/go-git/plumbing/transport/server
-github.com/theupdateframework/go-tuf/v0/internal/signer
-github.com/theupdateframework/go-tuf/v0/verify
-github.com/theupdateframework/go-tuf/v0/sign
-sigs.k8s.io/structured-merge-diff/merge
-k8s.io/client-go/applyconfigurations/internal
-github.com/sigstore/timestamp-authority/pkg/verification
+sigs.k8s.io/structured-merge-diff/value
+github.com/go-jose/go-jose/v3
+go.step.sm/crypto/x25519
+github.com/google/go-containerregistry/internal/estargz
+gopkg.in/square/go-jose.v2
+github.com/google/go-containerregistry/pkg/v1/tarball
+github.com/sigstore/sigstore/pkg/signature
 github.com/go-git/go-git/plumbing/transport/file
-github.com/theupdateframework/go-tuf/v0/pkg/targets
-github.com/spiffe/go-spiffe/v2/bundle/jwtbundle
-github.com/go-jose/go-jose/jwt
-github.com/go-jose/go-jose/v3/cryptosigner
-github.com/go-jose/go-jose/v3/jwt
-github.com/theupdateframework/go-tuf/v0
-github.com/sigstore/rekor/pkg/pki/minisign
-github.com/sigstore/rekor/pkg/pki/x509
-github.com/sigstore/cosign/pkg/cosign/pkcs11key
-github.com/sigstore/cosign/pkg/cosign/pivkey
-github.com/sigstore/gitsign/internal/signerverifier
-github.com/sigstore/sigstore/pkg/signature/kms
-github.com/spiffe/go-spiffe/v2/bundle/spiffebundle
-github.com/spiffe/go-spiffe/v2/svid/jwtsvid
-github.com/sigstore/gitsign/internal/commands/version
+go.step.sm/crypto/internal/bcrypt_pbkdf
 google.golang.org/protobuf/internal/filetype
-sigs.k8s.io/release-utils/version
-github.com/spf13/cobra/doc
+go.step.sm/crypto/randutil
+github.com/google/certificate-transparency-go
+github.com/sigstore/gitsign/internal
+github.com/sigstore/gitsign/internal/config
+github.com/github/smimesign/ietf-cms/oid
+github.com/go-jose/go-jose/jwt
+github.com/spiffe/go-spiffe/v2/bundle/jwtbundle
 google.golang.org/protobuf/runtime/protoimpl
+github.com/digitorus/timestamp
+github.com/github/smimesign/ietf-cms/protocol
+github.com/google/trillian/types/internal/tls
+github.com/sigstore/gitsign/pkg/version
+github.com/sigstore/gitsign/internal/cache/api
+github.com/google/go-containerregistry/pkg/v1/mutate
+github.com/theupdateframework/go-tuf/v0/internal/signer
+github.com/google/certificate-transparency-go/gossip/minimal/x509ext
+github.com/sigstore/cosign/pkg/cosign/fulcioverifier/ctutil
+google.golang.org/protobuf/protoadapt
 google.golang.org/protobuf/types/known/durationpb
-google.golang.org/protobuf/types/known/timestamppb
 google.golang.org/protobuf/types/known/anypb
-google.golang.org/protobuf/types/known/structpb
-google.golang.org/protobuf/types/known/fieldmaskpb
-google.golang.org/protobuf/protoadapt
-github.com/sigstore/protobuf-specs/gen/pb-go/dsse
+google.golang.org/protobuf/types/known/timestamppb
+github.com/spiffe/go-spiffe/v2/bundle/spiffebundle
 google.golang.org/protobuf/types/descriptorpb
 google.golang.org/grpc/encoding/proto
 google.golang.org/grpc/internal/pretty
 github.com/golang/protobuf/ptypes/duration
+github.com/golang/protobuf/ptypes/timestamp
+github.com/spiffe/go-spiffe/v2/svid/jwtsvid
+google.golang.org/protobuf/types/known/structpb
+github.com/sigstore/protobuf-specs/gen/pb-go/dsse
+github.com/sigstore/rekor/pkg/pki/minisign
 google.golang.org/genproto/googleapis/rpc/status
+github.com/theupdateframework/go-tuf/v0/verify
+github.com/theupdateframework/go-tuf/v0/sign
+github.com/sigstore/timestamp-authority/pkg/verification
 github.com/google/gnostic-models/extensions
-github.com/golang/protobuf/ptypes/timestamp
+github.com/sigstore/cosign/pkg/cosign/pkcs11key
 google.golang.org/grpc/binarylog/grpc_binarylog_v1
+github.com/sigstore/sigstore/pkg/signature/kms
+github.com/sigstore/cosign/pkg/cosign/pivkey
+github.com/google/go-containerregistry/pkg/v1/layout
+github.com/theupdateframework/go-tuf/v0/pkg/targets
+google.golang.org/protobuf/types/known/fieldmaskpb
+github.com/sigstore/gitsign/internal/signerverifier
+github.com/sigstore/gitsign/internal/gpg
+github.com/mattn/go-tty
+sigs.k8s.io/structured-merge-diff/fieldpath
+github.com/theupdateframework/go-tuf/v0
+github.com/patrickmn/go-cache
+github.com/sigstore/rekor/pkg/pki/x509
 google.golang.org/grpc/internal/status
+github.com/russross/blackfriday/v2
+github.com/go-jose/go-jose/v3/cryptosigner
+github.com/go-jose/go-jose/v3/jwt
+github.com/sigstore/gitsign/internal/git/gittest
 google.golang.org/grpc/status
-golang.org/x/crypto/ssh/knownhosts
-github.com/secure-systems-lab/go-securesystemslib/dsse
-go.step.sm/crypto/keyutil
-golang.org/x/crypto/ssh/agent
-github.com/sigstore/sigstore/pkg/signature/dsse
-github.com/in-toto/in-toto-golang/in_toto
+sigs.k8s.io/release-utils/version
+github.com/sigstore/gitsign/internal/commands/version
 google.golang.org/grpc/internal/binarylog
-github.com/skeema/knownhosts
-go.step.sm/crypto/pemutil
-github.com/xanzy/ssh-agent
+github.com/sigstore/gitsign/internal/io
+k8s.io/apimachinery/pkg/runtime/schema
+k8s.io/apimachinery/pkg/api/resource
+k8s.io/apimachinery/pkg/util/intstr
 google.golang.org/protobuf/internal/editionssupport
 google.golang.org/protobuf/types/gofeaturespb
 google.golang.org/genproto/googleapis/api/annotations
-github.com/go-git/go-git/plumbing/transport/ssh
+github.com/sigstore/protobuf-specs/gen/pb-go/common/v1
 google.golang.org/protobuf/reflect/protodesc
+github.com/cpuguy83/go-md2man/v2/md2man
+sigs.k8s.io/structured-merge-diff/typed
+github.com/spf13/cobra/doc
+github.com/sigstore/protobuf-specs/gen/pb-go/rekor/v1
+github.com/sigstore/protobuf-specs/gen/pb-go/bundle/v1
+github.com/golang/protobuf/proto
+sigs.k8s.io/structured-merge-diff/merge
+k8s.io/client-go/applyconfigurations/internal
+golang.org/x/crypto/ssh/knownhosts
+golang.org/x/crypto/ssh/agent
+github.com/secure-systems-lab/go-securesystemslib/dsse
+go.step.sm/crypto/keyutil
 net/http/httptrace
 google.golang.org/api/transport/cert
-github.com/coreos/go-systemd/activation
-k8s.io/client-go/util/cert
 google.golang.org/grpc/internal/credentials
 github.com/sassoftware/relic/lib/x509tools
-github.com/sigstore/protobuf-specs/gen/pb-go/common/v1
-google.golang.org/grpc/credentials
+k8s.io/client-go/util/cert
+github.com/coreos/go-systemd/activation
+github.com/in-toto/in-toto-golang/in_toto
+github.com/sigstore/sigstore/pkg/signature/dsse
+go.step.sm/crypto/pemutil
+github.com/skeema/knownhosts
 net/http
-github.com/sigstore/cosign/pkg/cosign/attestation
-github.com/sigstore/protobuf-specs/gen/pb-go/rekor/v1
-google.golang.org/grpc/peer
-google.golang.org/grpc/internal/channelz
+google.golang.org/grpc/credentials
 google.golang.org/grpc/resolver
 google.golang.org/grpc/credentials/insecure
-github.com/sigstore/protobuf-specs/gen/pb-go/bundle/v1
+google.golang.org/grpc/peer
+google.golang.org/grpc/internal/channelz
+github.com/xanzy/ssh-agent
+github.com/go-git/go-git/plumbing/transport/ssh
+github.com/sassoftware/relic/lib/pkcs7
+google.golang.org/grpc/internal/metadata
 google.golang.org/grpc/internal/resolver/passthrough
-google.golang.org/grpc/balancer/grpclb/state
 google.golang.org/grpc/internal/transport/networktype
-google.golang.org/grpc/internal/metadata
+google.golang.org/grpc/balancer/grpclb/state
 google.golang.org/grpc/internal/resolver/unix
 google.golang.org/grpc/internal/resolver/dns
-github.com/sassoftware/relic/lib/pkcs7
-github.com/golang/protobuf/proto
-google.golang.org/grpc/resolver/dns
 google.golang.org/grpc/channelz
-github.com/sigstore/rekor/pkg/pki/pkcs7
 google.golang.org/grpc/balancer
 google.golang.org/grpc/balancer/base
 google.golang.org/grpc/internal/serviceconfig
+google.golang.org/grpc/resolver/dns
+github.com/sigstore/rekor/pkg/pki/pkcs7
 google.golang.org/grpc/internal/resolver
 google.golang.org/grpc/balancer/roundrobin
 google.golang.org/grpc/internal/balancer/gracefulswitch
+github.com/sigstore/cosign/pkg/cosign/attestation
 github.com/sigstore/cosign/pkg/providers/github
 cloud.google.com/go/compute/metadata
-golang.org/x/oauth2/internal
+github.com/go-openapi/errors
+expvar
+github.com/go-openapi/swag
+github.com/go-chi/chi
+golang.org/x/net/trace
 go.opencensus.io/trace/propagation
 google.golang.org/api/googleapi/transport
-github.com/aws/smithy-go/endpoints
-golang.org/x/net/trace
 github.com/go-git/go-git/plumbing/transport/http
 github.com/aws/smithy-go/encoding/httpbinding
+net/http/httputil
+github.com/aws/smithy-go/endpoints
 github.com/docker/distribution/registry/client/auth/challenge
-expvar
-github.com/go-openapi/errors
+golang.org/x/net/http2
+net/http/pprof
+go.uber.org/zap
 github.com/sigstore/rekor/pkg/pki/pgp
-github.com/go-chi/chi
 github.com/sigstore/rekor/pkg/pki/ssh
+golang.org/x/oauth2/internal
+github.com/google/certificate-transparency-go/x509util
 github.com/sigstore/cosign/pkg/blob
+go.opencensus.io/plugin/ochttp/propagation/b3
+google.golang.org/api/transport/http/internal/propagation
+go.opencensus.io/plugin/ochttp
 github.com/go-openapi/runtime/middleware/denco
-github.com/go-openapi/swag
-golang.org/x/net/http2
 github.com/go-openapi/runtime/middleware/header
-github.com/sigstore/rekor/pkg/util
-go.uber.org/zap
-github.com/google/certificate-transparency-go/x509util
-github.com/opentracing/opentracing-go
-github.com/magiconair/properties
-net/http/httptest
 go.opentelemetry.io/otel/propagation
+github.com/opentracing/opentracing-go
+golang.org/x/oauth2
 go.opentelemetry.io/otel/semconv/internal/v2
-github.com/hashicorp/go-cleanhttp
-k8s.io/apimachinery/pkg/util/runtime
-net/http/pprof
-github.com/sigstore/cosign/internal/pkg/cosign/tsa/client
-github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp
-github.com/spf13/afero
-github.com/sigstore/fulcio/pkg/api
-net/http/httputil
-go.step.sm/crypto/jose
-net/rpc
-github.com/google/gnostic-models/compiler
-github.com/theupdateframework/go-tuf/v0/client
-github.com/emicklei/go-restful
-github.com/google/go-github/github
-k8s.io/apimachinery/pkg/runtime
-k8s.io/client-go/features
-go.opencensus.io/plugin/ochttp/propagation/b3
-google.golang.org/api/transport/http/internal/propagation
-k8s.io/apimachinery/pkg/util/wait
-k8s.io/client-go/util/workqueue
-github.com/hashicorp/go-retryablehttp
 github.com/sigstore/rekor/pkg/pki
-golang.org/x/oauth2
-github.com/sigstore/gitsign/internal/fork/ietf-cms
+github.com/sigstore/rekor/pkg/util
+github.com/go-openapi/strfmt
 go.opentelemetry.io/otel/internal/global
-github.com/opentracing/opentracing-go/ext
-go.opencensus.io/plugin/ochttp
+github.com/spf13/afero
+github.com/magiconair/properties
+github.com/theupdateframework/go-tuf/v0/client
 github.com/go-git/go-git/plumbing/transport/client
-github.com/go-openapi/strfmt
-go.opentelemetry.io/otel/semconv/v1.17.0/httpconv
+net/http/httptest
+github.com/opentracing/opentracing-go/ext
+github.com/hashicorp/go-cleanhttp
 github.com/go-git/go-git
-github.com/google/gnostic-models/openapiv3
-github.com/google/gnostic-models/openapiv2
-github.com/theupdateframework/go-tuf/v0/client/leveldbstore
+go.opentelemetry.io/otel/semconv/v1.17.0/httpconv
+github.com/google/go-github/github
+k8s.io/apimachinery/pkg/util/runtime
+github.com/google/gnostic-models/compiler
 golang.org/x/oauth2/authhandler
 golang.org/x/oauth2/google/internal/impersonate
 golang.org/x/oauth2/google/internal/stsexchange
 golang.org/x/oauth2/jwt
 google.golang.org/api/internal/impersonate
-github.com/coreos/go-oidc/v3/oidc
-github.com/go-chi/chi/middleware
 github.com/aws/smithy-go/transport/http
 github.com/google/go-containerregistry/pkg/v1/remote/transport
+github.com/go-chi/chi/middleware
+github.com/hashicorp/go-retryablehttp
+k8s.io/apimachinery/pkg/runtime
+k8s.io/client-go/features
+github.com/theupdateframework/go-tuf/v0/client/leveldbstore
+golang.org/x/oauth2/google/externalaccount
+golang.org/x/oauth2/google/internal/externalaccountauthorizeduser
+github.com/google/gnostic-models/openapiv2
 github.com/spf13/viper/internal/encoding/javaproperties
 github.com/sigstore/sigstore/pkg/tuf
-github.com/xanzy/go-gitlab
-golang.org/x/oauth2/google/internal/externalaccountauthorizeduser
-golang.org/x/oauth2/google/externalaccount
-github.com/sigstore/gitsign/internal/cache
+github.com/google/gnostic-models/openapiv3
+k8s.io/apimachinery/pkg/util/wait
+k8s.io/client-go/util/workqueue
 go.opentelemetry.io/otel
-github.com/sigstore/sigstore/pkg/oauthflow
-github.com/sigstore/cosign/cmd/cosign/cli/initialize
-github.com/sigstore/gitsign/internal/fulcio/fulcioroots
-github.com/sigstore/sigstore/pkg/fulcioroots
+github.com/emicklei/go-restful
 github.com/google/go-containerregistry/pkg/v1/remote
+github.com/sigstore/fulcio/pkg/api
 github.com/go-openapi/jsonpointer
-github.com/sigstore/gitsign/internal/commands/initialize
-github.com/aws/aws-sdk-go-v2/internal/auth
-github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding
+github.com/coreos/go-oidc/v3/oidc
+golang.org/x/oauth2/google
+go.step.sm/crypto/jose
 github.com/aws/smithy-go/auth/bearer
+github.com/aws/aws-sdk-go-v2/internal/auth
+github.com/xanzy/go-gitlab
+github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn
+github.com/aws/aws-sdk-go-v2/aws
 github.com/aws/aws-sdk-go-v2/aws/protocol/query
+github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding
 github.com/aws/smithy-go/private/requestcompression
-github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn
-github.com/sigstore/cosign/internal/pkg/cosign/fulcio/fulcioroots
-github.com/spf13/viper
-golang.org/x/oauth2/google
-github.com/sigstore/gitsign/pkg/fulcio
 github.com/go-openapi/jsonreference
-github.com/aws/aws-sdk-go-v2/aws
-github.com/sigstore/rekor/pkg/log
 github.com/go-openapi/runtime
-k8s.io/kube-openapi/pkg/internal
+github.com/sigstore/rekor/pkg/log
+github.com/sigstore/sigstore/pkg/fulcioroots
 github.com/go-openapi/spec
-github.com/sigstore/gitsign/internal/fulcio
+k8s.io/kube-openapi/pkg/internal
 github.com/google/go-containerregistry/pkg/v1/google
-github.com/sigstore/gitsign/internal/cache/service
-k8s.io/apimachinery/pkg/runtime/serializer/streaming
-k8s.io/apimachinery/pkg/runtime/serializer/recognizer
-k8s.io/client-go/tools/clientcmd/api
-k8s.io/apimachinery/pkg/runtime/serializer/json
-github.com/sigstore/gitsign/cmd/gitsign-credential-cache
+github.com/sigstore/cosign/internal/pkg/cosign/tsa/client
+github.com/spf13/viper
+github.com/sigstore/cosign/cmd/cosign/cli/initialize
+github.com/sigstore/sigstore/pkg/oauthflow
+github.com/sigstore/cosign/internal/pkg/cosign/fulcio/fulcioroots
+github.com/sigstore/gitsign/internal/fulcio/fulcioroots
+github.com/sigstore/gitsign/internal/commands/initialize
+github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp
+net/rpc
+github.com/sigstore/gitsign/internal/commands/show
+github.com/sigstore/gitsign/internal/fork/ietf-cms
+github.com/go-openapi/runtime/yamlpc
+github.com/go-openapi/runtime/security
 github.com/aws/aws-sdk-go-v2/credentials
+github.com/aws/aws-sdk-go-v2/credentials/processcreds
+github.com/aws/aws-sdk-go-v2/aws/defaults
+github.com/aws/aws-sdk-go-v2/aws/signer/internal/v4
 github.com/aws/aws-sdk-go-v2/internal/configsources
+github.com/aws/aws-sdk-go-v2/aws/middleware
 github.com/aws/aws-sdk-go-v2/internal/endpoints
 github.com/aws/aws-sdk-go-v2/internal/endpoints/v2
-github.com/aws/aws-sdk-go-v2/credentials/processcreds
-github.com/aws/aws-sdk-go-v2/aws/middleware
 github.com/awslabs/amazon-ecr-credential-helper/ecr-login/cache
-github.com/aws/aws-sdk-go-v2/aws/defaults
-github.com/aws/aws-sdk-go-v2/aws/signer/internal/v4
-k8s.io/client-go/tools/clientcmd/api/v1
-github.com/go-openapi/runtime/yamlpc
-github.com/go-openapi/runtime/security
+github.com/sigstore/gitsign/pkg/fulcio
+github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints
 github.com/aws/aws-sdk-go-v2/service/ssooidc/internal/endpoints
-github.com/aws/aws-sdk-go-v2/service/ecrpublic/internal/endpoints
 github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints
 github.com/aws/aws-sdk-go-v2/service/ecr/internal/endpoints
-github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints
+github.com/aws/aws-sdk-go-v2/service/ecrpublic/internal/endpoints
 github.com/aws/aws-sdk-go-v2/aws/transport/http
 github.com/aws/aws-sdk-go-v2/aws/retry
 github.com/aws/aws-sdk-go-v2/aws/signer/v4
-github.com/sigstore/gitsign/internal/commands/show
+k8s.io/apimachinery/pkg/runtime/serializer/recognizer
+k8s.io/apimachinery/pkg/runtime/serializer/streaming
+k8s.io/client-go/tools/clientcmd/api
+k8s.io/apimachinery/pkg/runtime/serializer/json
+github.com/sigstore/gitsign/internal/cache
+github.com/go-openapi/analysis/internal/flatten/operations
+github.com/go-openapi/analysis/internal/flatten/schutils
+github.com/go-openapi/analysis/internal/flatten/replace
+github.com/go-openapi/analysis/internal/flatten/normalize
+k8s.io/client-go/tools/clientcmd/api/v1
+github.com/go-openapi/analysis/internal/flatten/sortref
 github.com/aws/aws-sdk-go-v2/service/internal/presigned-url
+github.com/sigstore/gitsign/internal/fulcio
 github.com/aws/aws-sdk-go-v2/internal/auth/smithy
-github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client
+github.com/go-openapi/analysis
 github.com/aws/aws-sdk-go-v2/feature/ec2/imds
+github.com/sigstore/gitsign/internal/cache/service
+github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client
 github.com/aws/aws-sdk-go-v2/service/sso
-github.com/aws/aws-sdk-go-v2/service/sts
 github.com/aws/aws-sdk-go-v2/service/ssooidc
+github.com/aws/aws-sdk-go-v2/service/sts
 github.com/aws/aws-sdk-go-v2/service/ecrpublic
 github.com/aws/aws-sdk-go-v2/service/ecr
 k8s.io/apimachinery/pkg/util/net
 google.golang.org/grpc/internal/transport
-github.com/go-openapi/analysis/internal/flatten/normalize
-github.com/go-openapi/analysis/internal/flatten/replace
-github.com/go-openapi/analysis/internal/flatten/operations
-github.com/go-openapi/analysis/internal/flatten/schutils
+github.com/sigstore/gitsign/cmd/gitsign-credential-cache
 github.com/aws/aws-sdk-go-v2/credentials/endpointcreds
-github.com/go-openapi/analysis/internal/flatten/sortref
 github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds
-github.com/go-openapi/analysis
+github.com/go-openapi/loads
 k8s.io/apimachinery/pkg/watch
 k8s.io/client-go/transport
-k8s.io/apimachinery/pkg/apis/meta/v1
-github.com/go-openapi/loads
 github.com/go-openapi/runtime/middleware/untyped
 github.com/go-openapi/validate
+k8s.io/apimachinery/pkg/apis/meta/v1
 github.com/aws/aws-sdk-go-v2/credentials/ssocreds
 google.golang.org/grpc
 github.com/aws/aws-sdk-go-v2/credentials/stscreds
@@ -4087,272 +4123,272 @@
 github.com/aws/aws-sdk-go-v2/config
 github.com/go-openapi/runtime/middleware
 github.com/sigstore/rekor/pkg/generated/models
-google.golang.org/api/internal
-github.com/spiffe/go-spiffe/v2/proto/spiffe/workload
-github.com/google/trillian
+github.com/go-openapi/runtime/client
 k8s.io/kube-openapi/pkg/schemaconv
 k8s.io/kube-openapi/pkg/spec3
-google.golang.org/api/option
-google.golang.org/api/transport/internal/dca
+k8s.io/apimachinery/pkg/api/errors
+k8s.io/api/apidiscovery/v2
 k8s.io/apimachinery/pkg/runtime/serializer/protobuf
-k8s.io/api/certificates/v1alpha1
 k8s.io/apimachinery/pkg/apis/meta/v1/unstructured
+k8s.io/api/apiserverinternal/v1alpha1
+k8s.io/api/authentication/v1
 k8s.io/api/authorization/v1
+k8s.io/api/certificates/v1alpha1
 k8s.io/api/apidiscovery/v2beta1
-k8s.io/api/apiserverinternal/v1alpha1
-k8s.io/api/networking/v1alpha1
-k8s.io/apimachinery/pkg/api/meta
-k8s.io/apimachinery/pkg/api/equality
-k8s.io/client-go/rest/watch
-k8s.io/apimachinery/pkg/apis/meta/v1/validation
-k8s.io/api/flowcontrol/v1
 k8s.io/api/admissionregistration/v1
-k8s.io/apimachinery/pkg/api/errors
-k8s.io/client-go/pkg/apis/clientauthentication
-k8s.io/api/flowcontrol/v1beta3
-k8s.io/api/policy/v1beta1
-k8s.io/api/policy/v1
-k8s.io/api/authentication/v1
-k8s.io/apimachinery/pkg/apis/meta/v1beta1
-k8s.io/api/apidiscovery/v2
 k8s.io/api/coordination/v1
-k8s.io/api/rbac/v1
-k8s.io/api/flowcontrol/v1beta2
-k8s.io/api/flowcontrol/v1beta1
-k8s.io/api/rbac/v1alpha1
-k8s.io/api/rbac/v1beta1
+k8s.io/api/flowcontrol/v1
 k8s.io/api/core/v1
-github.com/go-openapi/runtime/client
-github.com/spiffe/go-spiffe/v2/workloadapi
-k8s.io/client-go/pkg/apis/clientauthentication/v1
-k8s.io/client-go/pkg/apis/clientauthentication/v1beta1
-google.golang.org/api/option/internaloption
-google.golang.org/api/transport/http
-k8s.io/apimachinery/pkg/apis/meta/internalversion
-github.com/google/trillian/types
-k8s.io/client-go/pkg/apis/clientauthentication/install
 github.com/sigstore/rekor/pkg/types
-k8s.io/apimachinery/pkg/runtime/serializer/versioning
-github.com/sigstore/rekor/pkg/sharding
-google.golang.org/api/impersonate
-google.golang.org/api/idtoken
-k8s.io/api/coordination/v1alpha1
-k8s.io/api/coordination/v1beta1
-k8s.io/apimachinery/pkg/apis/meta/internalversion/validation
-github.com/sigstore/cosign/pkg/providers/spiffe
+google.golang.org/api/internal
+github.com/spiffe/go-spiffe/v2/proto/spiffe/workload
 github.com/sigstore/rekor/pkg/generated/client/entries
 github.com/sigstore/rekor/pkg/generated/client/index
 github.com/sigstore/rekor/pkg/generated/client/pubkey
-k8s.io/client-go/util/watchlist
+google.golang.org/api/option
+google.golang.org/api/transport/internal/dca
 github.com/sigstore/rekor/pkg/generated/client/tlog
-k8s.io/api/authentication/v1beta1
-k8s.io/api/authentication/v1alpha1
-github.com/sigstore/cosign/pkg/providers/google
-k8s.io/kube-openapi/pkg/common
-k8s.io/apimachinery/pkg/api/validation
-k8s.io/client-go/util/consistencydetector
+k8s.io/api/coordination/v1alpha1
+k8s.io/apimachinery/pkg/runtime/serializer/versioning
+k8s.io/api/coordination/v1beta1
+k8s.io/api/flowcontrol/v1beta1
+k8s.io/api/flowcontrol/v1beta2
+k8s.io/api/flowcontrol/v1beta3
+github.com/sigstore/rekor/pkg/tle
+github.com/spiffe/go-spiffe/v2/workloadapi
 github.com/sigstore/rekor/pkg/types/dsse
 github.com/sigstore/rekor/pkg/types/hashedrekord
+google.golang.org/api/option/internaloption
+google.golang.org/api/transport/http
+github.com/sigstore/cosign/pkg/cosign/bundle
+github.com/sigstore/rekor/pkg/generated/client
 github.com/sigstore/rekor/pkg/types/intoto
 github.com/sigstore/rekor/pkg/types/rekord
-github.com/sigstore/rekor/pkg/tle
 k8s.io/apimachinery/pkg/runtime/serializer
-k8s.io/client-go/tools/clientcmd/api/latest
-github.com/sigstore/cosign/pkg/providers/all
-github.com/sigstore/rekor/pkg/generated/client
-k8s.io/client-go/plugin/pkg/client/auth/exec
-github.com/sigstore/rekor/pkg/client
-github.com/sigstore/cosign/pkg/cosign/bundle
-k8s.io/apimachinery/pkg/util/managedfields/internal
-k8s.io/api/authorization/v1beta1
+github.com/sigstore/cosign/pkg/oci
+k8s.io/api/authentication/v1alpha1
 github.com/sigstore/rekor/pkg/types/hashedrekord/v0.0.1
-github.com/sigstore/rekor/pkg/types/rekord/v0.0.1
 github.com/sigstore/rekor/pkg/types/dsse/v0.0.1
-github.com/sigstore/rekor/pkg/types/intoto/v0.0.1
-github.com/sigstore/rekor/pkg/types/intoto/v0.0.2
-github.com/sigstore/cosign/pkg/oci
-k8s.io/kube-openapi/pkg/handler3
-github.com/sigstore/gitsign/internal/rekor/oid
+k8s.io/api/authentication/v1beta1
+k8s.io/api/networking/v1alpha1
+k8s.io/api/policy/v1
+google.golang.org/api/idtoken
+google.golang.org/api/impersonate
 github.com/sigstore/cosign/internal/pkg/cosign
-github.com/sigstore/cosign/pkg/oci/empty
 github.com/sigstore/cosign/pkg/oci/internal/signature
-k8s.io/client-go/rest
-k8s.io/api/admissionregistration/v1alpha1
-k8s.io/api/admissionregistration/v1beta1
+github.com/sigstore/rekor/pkg/types/rekord/v0.0.1
+github.com/sigstore/cosign/pkg/oci/empty
+k8s.io/api/authorization/v1beta1
+github.com/sigstore/cosign/pkg/providers/spiffe
+k8s.io/api/policy/v1beta1
+github.com/sigstore/rekor/pkg/types/intoto/v0.0.1
+github.com/sigstore/rekor/pkg/types/intoto/v0.0.2
+k8s.io/api/rbac/v1
 github.com/sigstore/cosign/pkg/oci/signed
 github.com/sigstore/cosign/pkg/oci/remote
+k8s.io/api/rbac/v1beta1
+k8s.io/api/rbac/v1alpha1
 github.com/sigstore/cosign/pkg/oci/layout
+k8s.io/apimachinery/pkg/api/meta
+github.com/sigstore/cosign/pkg/providers/google
 github.com/sigstore/cosign/pkg/oci/static
-github.com/sigstore/cosign/internal/pkg/cosign/payload
+k8s.io/apimachinery/pkg/api/equality
+k8s.io/apimachinery/pkg/apis/meta/v1/validation
+k8s.io/client-go/pkg/apis/clientauthentication
+k8s.io/api/admissionregistration/v1alpha1
+github.com/sigstore/cosign/pkg/providers/all
+k8s.io/api/admissionregistration/v1beta1
+k8s.io/client-go/rest/watch
+k8s.io/kube-openapi/pkg/common
+k8s.io/apimachinery/pkg/apis/meta/v1beta1
+k8s.io/client-go/pkg/apis/clientauthentication/v1
 github.com/sigstore/cosign/pkg/oci/mutate
-github.com/awslabs/amazon-ecr-credential-helper/ecr-login/api
+k8s.io/client-go/pkg/apis/clientauthentication/v1beta1
+k8s.io/client-go/tools/clientcmd/api/latest
+github.com/sigstore/rekor/pkg/client
+github.com/sigstore/cosign/internal/pkg/cosign/payload
+github.com/sigstore/gitsign/internal/rekor/oid
+github.com/google/trillian
+k8s.io/apimachinery/pkg/apis/meta/internalversion
+k8s.io/client-go/pkg/apis/clientauthentication/install
 github.com/sigstore/cosign/pkg/cosign
-k8s.io/apimachinery/pkg/util/managedfields
-github.com/sigstore/cosign/internal/pkg/cosign/fulcio
 github.com/sigstore/cosign/pkg/cosign/remote
-github.com/sigstore/cosign/pkg/oci/walk
+k8s.io/client-go/plugin/pkg/client/auth/exec
+github.com/sigstore/cosign/internal/pkg/cosign/fulcio
 github.com/sigstore/cosign/internal/pkg/cosign/tsa
+github.com/sigstore/cosign/pkg/oci/walk
+k8s.io/apimachinery/pkg/api/validation
+k8s.io/client-go/util/consistencydetector
+k8s.io/apimachinery/pkg/apis/meta/internalversion/validation
+k8s.io/kube-openapi/pkg/handler3
+k8s.io/client-go/util/watchlist
+k8s.io/client-go/rest
+k8s.io/apimachinery/pkg/util/managedfields/internal
+github.com/awslabs/amazon-ecr-credential-helper/ecr-login/api
+github.com/google/trillian/types
 github.com/awslabs/amazon-ecr-credential-helper/ecr-login
-k8s.io/client-go/plugin/pkg/client/auth/gcp
-k8s.io/client-go/plugin/pkg/client/auth/oidc
-k8s.io/client-go/tools/auth
-k8s.io/client-go/gentype
-k8s.io/client-go/plugin/pkg/client/auth/azure
-k8s.io/client-go/tools/clientcmd
-k8s.io/client-go/plugin/pkg/client/auth
-k8s.io/client-go/openapi
+github.com/sigstore/rekor/pkg/sharding
 github.com/sigstore/cosign/pkg/cosign/git/github
 github.com/sigstore/cosign/pkg/cosign/git/gitlab
-github.com/sigstore/cosign/internal/pkg/cosign/rekor
 github.com/sigstore/gitsign/internal/cert
+github.com/sigstore/cosign/internal/pkg/cosign/rekor
 github.com/sigstore/gitsign/pkg/rekor
+k8s.io/client-go/gentype
+k8s.io/client-go/plugin/pkg/client/auth/azure
+k8s.io/client-go/plugin/pkg/client/auth/gcp
+k8s.io/client-go/tools/auth
+k8s.io/client-go/plugin/pkg/client/auth/oidc
+k8s.io/apimachinery/pkg/util/managedfields
+k8s.io/client-go/tools/clientcmd
+github.com/sigstore/cosign/pkg/cosign/git
 github.com/sigstore/gitsign/internal/rekor
 github.com/sigstore/gitsign/pkg/git
 github.com/sigstore/gitsign/internal/signature
-github.com/sigstore/cosign/pkg/cosign/git
+k8s.io/client-go/plugin/pkg/client/auth
 github.com/sigstore/gitsign/pkg/gitsign
 github.com/sigstore/gitsign/internal/git
+k8s.io/client-go/openapi
 k8s.io/api/apps/v1beta1
-k8s.io/api/autoscaling/v2beta2
-k8s.io/api/autoscaling/v1
+k8s.io/api/apps/v1
+k8s.io/api/apps/v1beta2
 k8s.io/api/certificates/v1beta1
-k8s.io/api/certificates/v1
-k8s.io/api/autoscaling/v2beta1
+k8s.io/api/networking/v1
 k8s.io/api/discovery/v1
-k8s.io/api/scheduling/v1beta1
-k8s.io/api/autoscaling/v2
-k8s.io/api/node/v1beta1
-k8s.io/api/events/v1
-k8s.io/api/apps/v1
+k8s.io/api/certificates/v1
 k8s.io/api/networking/v1beta1
+k8s.io/api/autoscaling/v2
 k8s.io/api/batch/v1
-k8s.io/client-go/tools/reference
 k8s.io/api/discovery/v1beta1
+k8s.io/api/events/v1
 k8s.io/api/events/v1beta1
 k8s.io/api/node/v1
-k8s.io/api/networking/v1
-k8s.io/api/storagemigration/v1alpha1
-k8s.io/api/apps/v1beta2
-k8s.io/api/scheduling/v1
 k8s.io/api/node/v1alpha1
+k8s.io/api/node/v1beta1
+k8s.io/api/autoscaling/v2beta1
+k8s.io/api/resource/v1alpha3
+k8s.io/api/autoscaling/v2beta2
+k8s.io/api/autoscaling/v1
+k8s.io/api/scheduling/v1
+k8s.io/api/scheduling/v1alpha1
 k8s.io/api/storage/v1
+k8s.io/api/scheduling/v1beta1
 k8s.io/api/storage/v1alpha1
-k8s.io/api/scheduling/v1alpha1
 k8s.io/api/storage/v1beta1
-k8s.io/api/resource/v1alpha3
+k8s.io/api/storagemigration/v1alpha1
+k8s.io/client-go/tools/reference
 k8s.io/api/batch/v1beta1
 k8s.io/api/extensions/v1beta1
 k8s.io/client-go/kubernetes/scheme
 k8s.io/client-go/discovery
-k8s.io/client-go/kubernetes/typed/authentication/v1beta1
 k8s.io/client-go/kubernetes/typed/authentication/v1
+k8s.io/client-go/kubernetes/typed/authentication/v1alpha1
+k8s.io/client-go/kubernetes/typed/authentication/v1beta1
 k8s.io/client-go/kubernetes/typed/authorization/v1
 k8s.io/client-go/kubernetes/typed/authorization/v1beta1
-k8s.io/client-go/kubernetes/typed/authentication/v1alpha1
 k8s.io/client-go/applyconfigurations/meta/v1
 k8s.io/client-go/applyconfigurations/apiserverinternal/v1alpha1
+k8s.io/client-go/applyconfigurations/autoscaling/v1
+k8s.io/client-go/applyconfigurations/autoscaling/v2
+k8s.io/client-go/applyconfigurations/autoscaling/v2beta1
+k8s.io/client-go/applyconfigurations/flowcontrol/v1
+k8s.io/client-go/applyconfigurations/autoscaling/v2beta2
+k8s.io/client-go/applyconfigurations/certificates/v1alpha1
 k8s.io/client-go/applyconfigurations/certificates/v1
-k8s.io/client-go/applyconfigurations/scheduling/v1beta1
-k8s.io/client-go/applyconfigurations/coordination/v1alpha1
-k8s.io/client-go/applyconfigurations/scheduling/v1
-k8s.io/client-go/applyconfigurations/coordination/v1beta1
 k8s.io/client-go/applyconfigurations/certificates/v1beta1
-k8s.io/client-go/applyconfigurations/storagemigration/v1alpha1
-k8s.io/client-go/applyconfigurations/scheduling/v1alpha1
-k8s.io/client-go/applyconfigurations/rbac/v1beta1
-k8s.io/client-go/applyconfigurations/autoscaling/v2beta1
-k8s.io/client-go/applyconfigurations/rbac/v1alpha1
 k8s.io/client-go/applyconfigurations/coordination/v1
-k8s.io/client-go/applyconfigurations/networking/v1alpha1
-k8s.io/client-go/applyconfigurations/autoscaling/v2
-k8s.io/client-go/applyconfigurations/autoscaling/v1
+k8s.io/client-go/applyconfigurations/coordination/v1alpha1
+k8s.io/client-go/applyconfigurations/admissionregistration/v1
+k8s.io/client-go/applyconfigurations/coordination/v1beta1
+k8s.io/client-go/applyconfigurations/flowcontrol/v1beta1
 k8s.io/client-go/applyconfigurations/policy/v1beta1
-k8s.io/client-go/applyconfigurations/flowcontrol/v1beta3
-k8s.io/client-go/applyconfigurations/certificates/v1alpha1
+k8s.io/client-go/applyconfigurations/networking/v1alpha1
 k8s.io/client-go/applyconfigurations/policy/v1
-k8s.io/client-go/applyconfigurations/flowcontrol/v1
+k8s.io/client-go/applyconfigurations/flowcontrol/v1beta3
 k8s.io/client-go/applyconfigurations/flowcontrol/v1beta2
-k8s.io/client-go/applyconfigurations/flowcontrol/v1beta1
-k8s.io/client-go/applyconfigurations/admissionregistration/v1
-k8s.io/client-go/applyconfigurations/rbac/v1
-k8s.io/client-go/applyconfigurations/autoscaling/v2beta2
 k8s.io/client-go/applyconfigurations/core/v1
-k8s.io/client-go/kubernetes/typed/storagemigration/v1alpha1
-k8s.io/client-go/kubernetes/typed/networking/v1alpha1
-k8s.io/client-go/kubernetes/typed/scheduling/v1
 k8s.io/client-go/kubernetes/typed/coordination/v1beta1
-k8s.io/client-go/kubernetes/typed/scheduling/v1alpha1
-k8s.io/client-go/kubernetes/typed/certificates/v1alpha1
-k8s.io/client-go/kubernetes/typed/scheduling/v1beta1
-k8s.io/client-go/kubernetes/typed/certificates/v1beta1
-k8s.io/client-go/kubernetes/typed/policy/v1
-k8s.io/client-go/kubernetes/typed/policy/v1beta1
-k8s.io/client-go/kubernetes/typed/certificates/v1
 k8s.io/client-go/kubernetes/typed/apiserverinternal/v1alpha1
-k8s.io/client-go/kubernetes/typed/coordination/v1
-k8s.io/client-go/kubernetes/typed/coordination/v1alpha1
-k8s.io/client-go/kubernetes/typed/flowcontrol/v1
+k8s.io/client-go/kubernetes/typed/certificates/v1
 k8s.io/client-go/kubernetes/typed/autoscaling/v1
-k8s.io/client-go/kubernetes/typed/autoscaling/v2
-k8s.io/client-go/kubernetes/typed/rbac/v1alpha1
-k8s.io/client-go/kubernetes/typed/rbac/v1beta1
-k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta3
-k8s.io/client-go/kubernetes/typed/rbac/v1
+k8s.io/client-go/kubernetes/typed/networking/v1alpha1
+k8s.io/client-go/kubernetes/typed/certificates/v1beta1
+k8s.io/client-go/kubernetes/typed/coordination/v1alpha1
+k8s.io/client-go/kubernetes/typed/certificates/v1alpha1
+k8s.io/client-go/kubernetes/typed/coordination/v1
 k8s.io/client-go/kubernetes/typed/autoscaling/v2beta1
 k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta1
+k8s.io/client-go/kubernetes/typed/policy/v1
+k8s.io/client-go/kubernetes/typed/autoscaling/v2
 k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta2
+k8s.io/client-go/kubernetes/typed/policy/v1beta1
+k8s.io/client-go/kubernetes/typed/flowcontrol/v1
+k8s.io/client-go/kubernetes/typed/autoscaling/v2beta2
+k8s.io/client-go/kubernetes/typed/flowcontrol/v1beta3
 k8s.io/client-go/kubernetes/typed/admissionregistration/v1
 k8s.io/client-go/applyconfigurations/admissionregistration/v1alpha1
 k8s.io/client-go/applyconfigurations/admissionregistration/v1beta1
-k8s.io/client-go/kubernetes/typed/autoscaling/v2beta2
+k8s.io/client-go/applyconfigurations/rbac/v1
+k8s.io/client-go/applyconfigurations/rbac/v1alpha1
+k8s.io/client-go/applyconfigurations/rbac/v1beta1
+k8s.io/client-go/applyconfigurations/scheduling/v1
+k8s.io/client-go/applyconfigurations/scheduling/v1alpha1
+k8s.io/client-go/applyconfigurations/scheduling/v1beta1
+k8s.io/client-go/applyconfigurations/storagemigration/v1alpha1
+k8s.io/client-go/kubernetes/typed/scheduling/v1beta1
+k8s.io/client-go/kubernetes/typed/scheduling/v1
 k8s.io/client-go/kubernetes/typed/admissionregistration/v1alpha1
+k8s.io/client-go/kubernetes/typed/scheduling/v1alpha1
+k8s.io/client-go/kubernetes/typed/rbac/v1beta1
+k8s.io/client-go/kubernetes/typed/rbac/v1
+k8s.io/client-go/kubernetes/typed/storagemigration/v1alpha1
 k8s.io/client-go/kubernetes/typed/admissionregistration/v1beta1
+k8s.io/client-go/kubernetes/typed/rbac/v1alpha1
 k8s.io/client-go/applyconfigurations/apps/v1beta1
-k8s.io/client-go/applyconfigurations/events/v1beta1
-k8s.io/client-go/applyconfigurations/events/v1
-k8s.io/client-go/applyconfigurations/discovery/v1
-k8s.io/client-go/applyconfigurations/discovery/v1beta1
-k8s.io/client-go/applyconfigurations/apps/v1
 k8s.io/client-go/applyconfigurations/batch/v1
-k8s.io/client-go/kubernetes/typed/core/v1
-k8s.io/client-go/applyconfigurations/node/v1
-k8s.io/client-go/applyconfigurations/node/v1beta1
-k8s.io/client-go/applyconfigurations/node/v1alpha1
-k8s.io/client-go/applyconfigurations/networking/v1beta1
-k8s.io/client-go/applyconfigurations/networking/v1
 k8s.io/client-go/applyconfigurations/apps/v1beta2
 k8s.io/client-go/applyconfigurations/storage/v1alpha1
 k8s.io/client-go/applyconfigurations/storage/v1
+k8s.io/client-go/applyconfigurations/networking/v1
+k8s.io/client-go/applyconfigurations/networking/v1beta1
+k8s.io/client-go/applyconfigurations/node/v1beta1
 k8s.io/client-go/applyconfigurations/extensions/v1beta1
-k8s.io/client-go/applyconfigurations/storage/v1beta1
+k8s.io/client-go/applyconfigurations/discovery/v1
+k8s.io/client-go/applyconfigurations/discovery/v1beta1
+k8s.io/client-go/applyconfigurations/events/v1
+k8s.io/client-go/kubernetes/typed/core/v1
+k8s.io/client-go/applyconfigurations/events/v1beta1
+k8s.io/client-go/applyconfigurations/node/v1
+k8s.io/client-go/applyconfigurations/node/v1alpha1
 k8s.io/client-go/applyconfigurations/resource/v1alpha3
-k8s.io/client-go/kubernetes/typed/events/v1beta1
+k8s.io/client-go/applyconfigurations/apps/v1
+k8s.io/client-go/applyconfigurations/storage/v1beta1
+k8s.io/client-go/kubernetes/typed/discovery/v1beta1
 k8s.io/client-go/kubernetes/typed/node/v1alpha1
-k8s.io/client-go/kubernetes/typed/events/v1
 k8s.io/client-go/kubernetes/typed/discovery/v1
-k8s.io/client-go/kubernetes/typed/node/v1beta1
 k8s.io/client-go/kubernetes/typed/node/v1
-k8s.io/client-go/kubernetes/typed/discovery/v1beta1
-k8s.io/client-go/kubernetes/typed/networking/v1
+k8s.io/client-go/kubernetes/typed/events/v1beta1
+k8s.io/client-go/kubernetes/typed/events/v1
 k8s.io/client-go/kubernetes/typed/storage/v1alpha1
+k8s.io/client-go/kubernetes/typed/node/v1beta1
 k8s.io/client-go/kubernetes/typed/networking/v1beta1
-k8s.io/client-go/kubernetes/typed/batch/v1
-k8s.io/client-go/applyconfigurations/batch/v1beta1
-k8s.io/client-go/kubernetes/typed/apps/v1beta1
-k8s.io/client-go/kubernetes/typed/storage/v1
-k8s.io/client-go/kubernetes/typed/apps/v1
 k8s.io/client-go/kubernetes/typed/storage/v1beta1
+k8s.io/client-go/kubernetes/typed/networking/v1
+k8s.io/client-go/kubernetes/typed/storage/v1
+k8s.io/client-go/kubernetes/typed/apps/v1beta1
 k8s.io/client-go/kubernetes/typed/resource/v1alpha3
-k8s.io/client-go/kubernetes/typed/extensions/v1beta1
+k8s.io/client-go/kubernetes/typed/apps/v1
+k8s.io/client-go/kubernetes/typed/batch/v1
+k8s.io/client-go/applyconfigurations/batch/v1beta1
 k8s.io/client-go/kubernetes/typed/apps/v1beta2
+k8s.io/client-go/kubernetes/typed/extensions/v1beta1
 k8s.io/client-go/kubernetes/typed/batch/v1beta1
 k8s.io/client-go/kubernetes
 github.com/sigstore/cosign/pkg/cosign/kubernetes
 github.com/sigstore/cosign/pkg/signature
 github.com/sigstore/cosign/cmd/cosign/cli/options
 github.com/sigstore/cosign/cmd/cosign/cli/fulcio
-github.com/sigstore/gitsign/internal/gitsign
 github.com/sigstore/cosign/cmd/cosign/cli/rekor
+github.com/sigstore/gitsign/internal/gitsign
 github.com/sigstore/cosign/cmd/cosign/cli/fulcio/fulcioverifier
 github.com/sigstore/cosign/cmd/cosign/cli/sign
 github.com/sigstore/gitsign/internal/commands/verify
@@ -4362,14 +4398,14 @@
 github.com/sigstore/gitsign
 github.com/sigstore/gitsign/docs/cli
    dh_auto_test -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go test -vet=off -v -p 42 github.com/sigstore/gitsign github.com/sigstore/gitsign/cmd/gitsign-credential-cache github.com/sigstore/gitsign/docs/cli github.com/sigstore/gitsign/internal github.com/sigstore/gitsign/internal/attest github.com/sigstore/gitsign/internal/cache github.com/sigstore/gitsign/internal/cache/api github.com/sigstore/gitsign/internal/cache/service github.com/sigstore/gitsign/internal/cert github.com/sigstore/gitsign/internal/commands/attest github.com/sigstore/gitsign/internal/commands/initialize github.com/sigstore/gitsign/internal/commands/root github.com/sigstore/gitsign/internal/commands/show github.com/sigstore/gitsign/internal/commands/verify github.com/sigstore/gitsign/internal/commands/version github.com/sigstore/gitsign/internal/config github.com/sigstore/gitsign/internal/fork/ietf-cms github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp github.com/sigstore/gitsign/internal/fulcio github.com/sigstore/gitsign/internal/fulcio/fulcioroots github.com/sigstore/gitsign/internal/git github.com/sigstore/gitsign/internal/git/gittest github.com/sigstore/gitsign/internal/gitsign github.com/sigstore/gitsign/internal/gpg github.com/sigstore/gitsign/internal/io github.com/sigstore/gitsign/internal/rekor github.com/sigstore/gitsign/internal/rekor/oid github.com/sigstore/gitsign/internal/signature github.com/sigstore/gitsign/internal/signerverifier github.com/sigstore/gitsign/pkg/fulcio github.com/sigstore/gitsign/pkg/git github.com/sigstore/gitsign/pkg/gitsign github.com/sigstore/gitsign/pkg/predicate github.com/sigstore/gitsign/pkg/rekor github.com/sigstore/gitsign/pkg/version
+	cd _build && go test -vet=off -v -p 20 github.com/sigstore/gitsign github.com/sigstore/gitsign/cmd/gitsign-credential-cache github.com/sigstore/gitsign/docs/cli github.com/sigstore/gitsign/internal github.com/sigstore/gitsign/internal/attest github.com/sigstore/gitsign/internal/cache github.com/sigstore/gitsign/internal/cache/api github.com/sigstore/gitsign/internal/cache/service github.com/sigstore/gitsign/internal/cert github.com/sigstore/gitsign/internal/commands/attest github.com/sigstore/gitsign/internal/commands/initialize github.com/sigstore/gitsign/internal/commands/root github.com/sigstore/gitsign/internal/commands/show github.com/sigstore/gitsign/internal/commands/verify github.com/sigstore/gitsign/internal/commands/version github.com/sigstore/gitsign/internal/config github.com/sigstore/gitsign/internal/fork/ietf-cms github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp github.com/sigstore/gitsign/internal/fulcio github.com/sigstore/gitsign/internal/fulcio/fulcioroots github.com/sigstore/gitsign/internal/git github.com/sigstore/gitsign/internal/git/gittest github.com/sigstore/gitsign/internal/gitsign github.com/sigstore/gitsign/internal/gpg github.com/sigstore/gitsign/internal/io github.com/sigstore/gitsign/internal/rekor github.com/sigstore/gitsign/internal/rekor/oid github.com/sigstore/gitsign/internal/signature github.com/sigstore/gitsign/internal/signerverifier github.com/sigstore/gitsign/pkg/fulcio github.com/sigstore/gitsign/pkg/git github.com/sigstore/gitsign/pkg/gitsign github.com/sigstore/gitsign/pkg/predicate github.com/sigstore/gitsign/pkg/rekor github.com/sigstore/gitsign/pkg/version
 ?   	github.com/sigstore/gitsign	[no test files]
 ?   	github.com/sigstore/gitsign/cmd/gitsign-credential-cache	[no test files]
 ?   	github.com/sigstore/gitsign/docs/cli	[no test files]
 === RUN   TestStripUrl
 --- PASS: TestStripUrl (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal	0.004s
+ok  	github.com/sigstore/gitsign/internal	0.052s
 === RUN   TestAttestCommitRef
 === RUN   TestAttestCommitRef/base
 LogEntry ID foo 1
@@ -4377,8 +4413,8 @@
 LogEntry ID foo 1
 === RUN   TestAttestCommitRef/new_commit
 LogEntry ID foo 1
---- PASS: TestAttestCommitRef (0.00s)
-    --- PASS: TestAttestCommitRef/base (0.00s)
+--- PASS: TestAttestCommitRef (0.04s)
+    --- PASS: TestAttestCommitRef/base (0.01s)
     --- PASS: TestAttestCommitRef/noop (0.00s)
     --- PASS: TestAttestCommitRef/new_commit (0.00s)
 === RUN   TestAttestTreeRef
@@ -4390,23 +4426,23 @@
 LogEntry ID foo 1
 === RUN   TestAttestTreeRef/new_commit_new_tree
 LogEntry ID foo 1
---- PASS: TestAttestTreeRef (0.01s)
+--- PASS: TestAttestTreeRef (0.02s)
     --- PASS: TestAttestTreeRef/base (0.00s)
     --- PASS: TestAttestTreeRef/noop (0.00s)
     --- PASS: TestAttestTreeRef/new_commit_same_tree (0.00s)
     --- PASS: TestAttestTreeRef/new_commit_new_tree (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/attest	0.042s
+ok  	github.com/sigstore/gitsign/internal/attest	0.353s
 === RUN   TestCache
-Get ionos5-amd64@/build/reproducible-path/gitsign-0.12.0/_build/src/github.com/sigstore/gitsign/internal/cache
-Store ionos5-amd64@/build/reproducible-path/gitsign-0.12.0/_build/src/github.com/sigstore/gitsign/internal/cache
-Get ionos5-amd64@/build/reproducible-path/gitsign-0.12.0/_build/src/github.com/sigstore/gitsign/internal/cache
+Get i-capture-the-hostname@/build/reproducible-path/gitsign-0.12.0/_build/src/github.com/sigstore/gitsign/internal/cache
+Store i-capture-the-hostname@/build/reproducible-path/gitsign-0.12.0/_build/src/github.com/sigstore/gitsign/internal/cache
+Get i-capture-the-hostname@/build/reproducible-path/gitsign-0.12.0/_build/src/github.com/sigstore/gitsign/internal/cache
 gitsign-credential-cache: found credential!
-Get ionos5-amd64@/build/reproducible-path/gitsign-0.12.0/_build/src/github.com/sigstore/gitsign/internal/cache
+Get i-capture-the-hostname@/build/reproducible-path/gitsign-0.12.0/_build/src/github.com/sigstore/gitsign/internal/cache
 gitsign-credential-cache: found credential!
---- PASS: TestCache (0.57s)
+--- PASS: TestCache (2.59s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/cache	0.574s
+ok  	github.com/sigstore/gitsign/internal/cache	2.648s
 ?   	github.com/sigstore/gitsign/internal/cache/api	[no test files]
 ?   	github.com/sigstore/gitsign/internal/cache/service	[no test files]
 ?   	github.com/sigstore/gitsign/internal/cert	[no test files]
@@ -4420,25 +4456,25 @@
     --- PASS: TestShow/fulcio-cert (0.00s)
     --- PASS: TestShow/gpg (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/commands/show	0.013s
+ok  	github.com/sigstore/gitsign/internal/commands/show	0.070s
 ?   	github.com/sigstore/gitsign/internal/commands/verify	[no test files]
 ?   	github.com/sigstore/gitsign/internal/commands/version	[no test files]
 === RUN   TestGet
 --- PASS: TestGet (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/config	0.009s
+ok  	github.com/sigstore/gitsign/internal/config	0.076s
 === RUN   TestSign
---- PASS: TestSign (0.00s)
+--- PASS: TestSign (0.01s)
 === RUN   TestSignDetached
---- PASS: TestSignDetached (0.00s)
+--- PASS: TestSignDetached (0.01s)
 === RUN   TestSignDetachedWithOpenSSL
---- PASS: TestSignDetachedWithOpenSSL (0.01s)
+--- PASS: TestSignDetachedWithOpenSSL (0.22s)
 === RUN   TestSignRemoveHeaders
---- PASS: TestSignRemoveHeaders (0.00s)
+--- PASS: TestSignRemoveHeaders (0.01s)
 === RUN   TestAddTimestamps
---- PASS: TestAddTimestamps (0.02s)
+--- PASS: TestAddTimestamps (0.13s)
 === RUN   TestTimestampsVerifications
---- PASS: TestTimestampsVerifications (0.14s)
+--- PASS: TestTimestampsVerifications (3.95s)
 === RUN   TestVerify
 --- PASS: TestVerify (0.00s)
 === RUN   TestVerifyGPGSMAttached
@@ -4452,11 +4488,11 @@
 === RUN   TestVerifyOpenSSLDetached
 --- PASS: TestVerifyOpenSSLDetached (0.00s)
 === RUN   TestVerifyChain
---- PASS: TestVerifyChain (0.02s)
+--- PASS: TestVerifyChain (0.17s)
 === RUN   TestVerifyDSAWithSHA1
 --- PASS: TestVerifyDSAWithSHA1 (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/fork/ietf-cms	1.520s
+ok  	github.com/sigstore/gitsign/internal/fork/ietf-cms	19.097s
 === RUN   TestRequestDo
 --- PASS: TestRequestDo (0.00s)
 === RUN   TestRequestMatches
@@ -4474,7 +4510,7 @@
 === RUN   TestParseTimestampSymantec
 --- PASS: TestParseTimestampSymantec (0.00s)
 === RUN   TestParseTimestampSymantecWithCerts
---- PASS: TestParseTimestampSymantecWithCerts (0.00s)
+--- PASS: TestParseTimestampSymantecWithCerts (0.01s)
 === RUN   TestParseTimestampDigicert
 --- PASS: TestParseTimestampDigicert (0.00s)
 === RUN   TestParseTimestampComodo
@@ -4482,33 +4518,33 @@
 === RUN   TestParseTimestampGlobalSign
 --- PASS: TestParseTimestampGlobalSign (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp	0.010s
+ok  	github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp	0.100s
 ?   	github.com/sigstore/gitsign/internal/fulcio	[no test files]
 === RUN   TestNew
 === RUN   TestNew/FromFile
 === RUN   TestNew/Static
 === RUN   TestNew/None
---- PASS: TestNew (0.29s)
+--- PASS: TestNew (0.44s)
     --- PASS: TestNew/FromFile (0.00s)
     --- PASS: TestNew/Static (0.00s)
     --- PASS: TestNew/None (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/fulcio/fulcioroots	0.299s
+ok  	github.com/sigstore/gitsign/internal/fulcio/fulcioroots	0.504s
 ?   	github.com/sigstore/gitsign/internal/git	[no test files]
 ?   	github.com/sigstore/gitsign/internal/git/gittest	[no test files]
 === RUN   TestVerify
---- PASS: TestVerify (0.01s)
+--- PASS: TestVerify (0.06s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/gitsign	0.036s
+ok  	github.com/sigstore/gitsign/internal/gitsign	0.233s
 ?   	github.com/sigstore/gitsign/internal/gpg	[no test files]
 ?   	github.com/sigstore/gitsign/internal/io	[no test files]
 ?   	github.com/sigstore/gitsign/internal/rekor	[no test files]
 === RUN   TestOID
---- PASS: TestOID (0.00s)
+--- PASS: TestOID (0.01s)
 === RUN   TestConvert
 --- PASS: TestConvert (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/rekor/oid	0.014s
+ok  	github.com/sigstore/gitsign/internal/rekor/oid	0.068s
 === RUN   TestMatchSAN
 === RUN   TestMatchSAN/email_match
 === RUN   TestMatchSAN/uri_match
@@ -4518,7 +4554,7 @@
     --- PASS: TestMatchSAN/uri_match (0.00s)
     --- PASS: TestMatchSAN/no_match (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/internal/signature	0.015s
+ok  	github.com/sigstore/gitsign/internal/signature	0.092s
 ?   	github.com/sigstore/gitsign/internal/signerverifier	[no test files]
 === RUN   TestKeyAlgorithm
 === RUN   TestKeyAlgorithm/ecdsa
@@ -4529,9 +4565,9 @@
     --- PASS: TestKeyAlgorithm/fulcio (0.00s)
     --- PASS: TestKeyAlgorithm/#00 (0.00s)
 === RUN   TestGetCert
---- PASS: TestGetCert (0.00s)
+--- PASS: TestGetCert (0.01s)
 PASS
-ok  	github.com/sigstore/gitsign/pkg/fulcio	0.010s
+ok  	github.com/sigstore/gitsign/pkg/fulcio	0.084s
 === RUN   TestObjectHash
 === RUN   TestObjectHash/tag
 === RUN   TestObjectHash/commit
@@ -4545,15 +4581,15 @@
 === RUN   TestSignVerify/detached(false)
 === RUN   TestSignVerify/detached(false)/VerifySignature
 === RUN   TestSignVerify/detached(false)/CertVerifier.Verify
---- PASS: TestSignVerify (0.52s)
-    --- PASS: TestSignVerify/detached(true) (0.00s)
+--- PASS: TestSignVerify (1.71s)
+    --- PASS: TestSignVerify/detached(true) (0.01s)
         --- PASS: TestSignVerify/detached(true)/VerifySignature (0.00s)
         --- PASS: TestSignVerify/detached(true)/CertVerifier.Verify (0.00s)
-    --- PASS: TestSignVerify/detached(false) (0.00s)
+    --- PASS: TestSignVerify/detached(false) (0.01s)
         --- PASS: TestSignVerify/detached(false)/VerifySignature (0.00s)
         --- PASS: TestSignVerify/detached(false)/CertVerifier.Verify (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/pkg/git	0.541s
+ok  	github.com/sigstore/gitsign/pkg/git	1.768s
 ?   	github.com/sigstore/gitsign/pkg/gitsign	[no test files]
 ?   	github.com/sigstore/gitsign/pkg/predicate	[no test files]
 ?   	github.com/sigstore/gitsign/pkg/rekor	[no test files]
@@ -4562,7 +4598,7 @@
 === RUN   TestEnv
 --- PASS: TestEnv (0.00s)
 PASS
-ok  	github.com/sigstore/gitsign/pkg/version	0.005s
+ok  	github.com/sigstore/gitsign/pkg/version	0.060s
    create-stamp debian/debhelper-build-stamp
    dh_testroot -O--builddirectory=_build -O--buildsystem=golang
    dh_prep -O--builddirectory=_build -O--buildsystem=golang
@@ -4612,9 +4648,9 @@
 dpkg-gencontrol: warning: package gitsign: substitution variable ${misc:Static-Built-Using} unused, but is defined
    dh_md5sums -O--builddirectory=_build -O--buildsystem=golang
    dh_builddeb -O--builddirectory=_build -O--buildsystem=golang
-dpkg-deb: building package 'gitsign-dbgsym' in '../gitsign-dbgsym_0.12.0-4_amd64.deb'.
 dpkg-deb: building package 'gitsign' in '../gitsign_0.12.0-4_amd64.deb'.
 dpkg-deb: building package 'golang-github-sigstore-gitsign-dev' in '../golang-github-sigstore-gitsign-dev_0.12.0-4_all.deb'.
+dpkg-deb: building package 'gitsign-dbgsym' in '../gitsign-dbgsym_0.12.0-4_amd64.deb'.
  dpkg-genbuildinfo --build=binary -O../gitsign_0.12.0-4_amd64.buildinfo
  dpkg-genchanges --build=binary -O../gitsign_0.12.0-4_amd64.changes
 dpkg-genchanges: info: binary-only upload (no source code included)
@@ -4622,12 +4658,14 @@
 dpkg-buildpackage: info: binary-only upload (no source included)
 dpkg-genchanges: info: not including original source code in upload
 I: copying local configuration
+I: user script /srv/workspace/pbuilder/2934915/tmp/hooks/B01_cleanup starting
+I: user script /srv/workspace/pbuilder/2934915/tmp/hooks/B01_cleanup finished
 I: unmounting dev/ptmx filesystem
 I: unmounting dev/pts filesystem
 I: unmounting dev/shm filesystem
 I: unmounting proc filesystem
 I: unmounting sys filesystem
 I: cleaning the build env 
-I: removing directory /srv/workspace/pbuilder/2648201 and its subdirectories
-I: Current time: Tue Apr 14 21:28:18 -12 2026
-I: pbuilder-time-stamp: 1776245298
+I: removing directory /srv/workspace/pbuilder/2934915 and its subdirectories
+I: Current time: Thu Mar 13 17:34:26 +14 2025
+I: pbuilder-time-stamp: 1741836866