Diff of the two buildlogs:

--
--- b1/build.log	2025-03-17 05:54:08.230132267 +0000
+++ b2/build.log	2025-03-17 06:09:49.655450227 +0000
@@ -1,6 +1,6 @@
 I: pbuilder: network access will be disabled during build
-I: Current time: Sun Apr 19 00:14:05 -12 2026
-I: pbuilder-time-stamp: 1776600845
+I: Current time: Mon Mar 17 19:54:11 +14 2025
+I: pbuilder-time-stamp: 1742190851
 I: Building the build Environment
 I: extracting base tarball [/var/cache/pbuilder/unstable-reproducible-base.tgz]
 I: copying local configuration
@@ -22,52 +22,84 @@
 dpkg-source: info: unpacking sigstore-go_0.7.0-2.debian.tar.xz
 I: Not using root during the build.
 I: Installing the build-deps
-I: user script /srv/workspace/pbuilder/2710469/tmp/hooks/D02_print_environment starting
+I: user script /srv/workspace/pbuilder/2312480/tmp/hooks/D01_modify_environment starting
+debug: Running on ionos1-amd64.
+I: Changing host+domainname to test build reproducibility
+I: Adding a custom variable just for the fun of it...
+I: Changing /bin/sh to bash
+'/bin/sh' -> '/bin/bash'
+lrwxrwxrwx 1 root root 9 Mar 17 05:54 /bin/sh -> /bin/bash
+I: Setting pbuilder2's login shell to /bin/bash
+I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other
+I: user script /srv/workspace/pbuilder/2312480/tmp/hooks/D01_modify_environment finished
+I: user script /srv/workspace/pbuilder/2312480/tmp/hooks/D02_print_environment starting
 I: set
-  BUILDDIR='/build/reproducible-path'
-  BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other'
-  BUILDUSERNAME='pbuilder1'
-  BUILD_ARCH='amd64'
-  DEBIAN_FRONTEND='noninteractive'
-  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=42 '
-  DISTRIBUTION='unstable'
-  HOME='/root'
-  HOST_ARCH='amd64'
+  BASH=/bin/sh
+  BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath
+  BASH_ALIASES=()
+  BASH_ARGC=()
+  BASH_ARGV=()
+  BASH_CMDS=()
+  BASH_LINENO=([0]="12" [1]="0")
+  BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:.
+  BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment")
+  BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="x86_64-pc-linux-gnu")
+  BASH_VERSION='5.2.37(1)-release'
+  BUILDDIR=/build/reproducible-path
+  BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other'
+  BUILDUSERNAME=pbuilder2
+  BUILD_ARCH=amd64
+  DEBIAN_FRONTEND=noninteractive
+  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=20 '
+  DIRSTACK=()
+  DISTRIBUTION=unstable
+  EUID=0
+  FUNCNAME=([0]="Echo" [1]="main")
+  GROUPS=()
+  HOME=/root
+  HOSTNAME=i-capture-the-hostname
+  HOSTTYPE=x86_64
+  HOST_ARCH=amd64
   IFS=' 	
   '
-  INVOCATION_ID='9b2bcb28b5de46f7a14d0a7dd2aa240f'
-  LANG='C'
-  LANGUAGE='en_US:en'
-  LC_ALL='C'
-  MAIL='/var/mail/root'
-  OPTIND='1'
-  PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games'
-  PBCURRENTCOMMANDLINEOPERATION='build'
-  PBUILDER_OPERATION='build'
-  PBUILDER_PKGDATADIR='/usr/share/pbuilder'
-  PBUILDER_PKGLIBDIR='/usr/lib/pbuilder'
-  PBUILDER_SYSCONFDIR='/etc'
-  PPID='2710469'
-  PS1='# '
-  PS2='> '
+  INVOCATION_ID=f3c3988f91aa4ad195977e3fd3edcb28
+  LANG=C
+  LANGUAGE=et_EE:et
+  LC_ALL=C
+  MACHTYPE=x86_64-pc-linux-gnu
+  MAIL=/var/mail/root
+  OPTERR=1
+  OPTIND=1
+  OSTYPE=linux-gnu
+  PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path
+  PBCURRENTCOMMANDLINEOPERATION=build
+  PBUILDER_OPERATION=build
+  PBUILDER_PKGDATADIR=/usr/share/pbuilder
+  PBUILDER_PKGLIBDIR=/usr/lib/pbuilder
+  PBUILDER_SYSCONFDIR=/etc
+  PIPESTATUS=([0]="0")
+  POSIXLY_CORRECT=y
+  PPID=2312480
   PS4='+ '
-  PWD='/'
-  SHELL='/bin/bash'
-  SHLVL='2'
-  SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.7EkHNfnq/pbuilderrc_R7Wq --distribution unstable --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.7EkHNfnq/b1 --logfile b1/build.log sigstore-go_0.7.0-2.dsc'
-  SUDO_GID='110'
-  SUDO_UID='105'
-  SUDO_USER='jenkins'
-  TERM='unknown'
-  TZ='/usr/share/zoneinfo/Etc/GMT+12'
-  USER='root'
-  _='/usr/bin/systemd-run'
-  http_proxy='http://213.165.73.152:3128'
+  PWD=/
+  SHELL=/bin/bash
+  SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix
+  SHLVL=3
+  SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.7EkHNfnq/pbuilderrc_Vg6x --distribution unstable --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.7EkHNfnq/b2 --logfile b2/build.log sigstore-go_0.7.0-2.dsc'
+  SUDO_GID=110
+  SUDO_UID=105
+  SUDO_USER=jenkins
+  TERM=unknown
+  TZ=/usr/share/zoneinfo/Etc/GMT-14
+  UID=0
+  USER=root
+  _='I: set'
+  http_proxy=http://46.16.76.132:3128
 I: uname -a
-  Linux ionos5-amd64 6.12.12+bpo-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.12-1~bpo12+1 (2025-02-23) x86_64 GNU/Linux
+  Linux i-capture-the-hostname 6.1.0-32-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.129-1 (2025-03-06) x86_64 GNU/Linux
 I: ls -l /bin
-  lrwxrwxrwx 1 root root 7 Mar  4  2025 /bin -> usr/bin
-I: user script /srv/workspace/pbuilder/2710469/tmp/hooks/D02_print_environment finished
+  lrwxrwxrwx 1 root root 7 Mar  4 11:20 /bin -> usr/bin
+I: user script /srv/workspace/pbuilder/2312480/tmp/hooks/D02_print_environment finished
  -> Attempting to satisfy build-dependencies
  -> Creating pbuilder-satisfydepends-dummy package
 Package: pbuilder-satisfydepends-dummy
@@ -653,7 +685,7 @@
 Get: 508 http://deb.debian.org/debian unstable/main amd64 golang-github-urfave-negroni-dev all 0.2.0-3 [8752 B]
 Get: 509 http://deb.debian.org/debian unstable/main amd64 golang-github-sigstore-timestamp-authority-dev all 1.2.3-2 [75.8 kB]
 Get: 510 http://deb.debian.org/debian unstable/main amd64 help2man amd64 1.49.3 [198 kB]
-Fetched 239 MB in 3s (84.8 MB/s)
+Fetched 239 MB in 13s (18.9 MB/s)
 Preconfiguring packages ...
 Selecting previously unselected package golang-golang-x-sys-dev.
 (Reading database ... 
(Reading database ... 5%
(Reading database ... 10%
(Reading database ... 15%
(Reading database ... 20%
(Reading database ... 25%
(Reading database ... 30%
(Reading database ... 35%
(Reading database ... 40%
(Reading database ... 45%
(Reading database ... 50%
(Reading database ... 55%
(Reading database ... 60%
(Reading database ... 65%
(Reading database ... 70%
(Reading database ... 75%
(Reading database ... 80%
(Reading database ... 85%
(Reading database ... 90%
(Reading database ... 95%
(Reading database ... 100%
(Reading database ... 19784 files and directories currently installed.)
@@ -2286,8 +2318,8 @@
 Setting up tzdata (2025a-2) ...
 
 Current default time zone: 'Etc/UTC'
-Local time is now:      Sun Apr 19 12:15:53 UTC 2026.
-Universal Time is now:  Sun Apr 19 12:15:53 UTC 2026.
+Local time is now:      Mon Mar 17 06:04:21 UTC 2025.
+Universal Time is now:  Mon Mar 17 06:04:21 UTC 2025.
 Run 'dpkg-reconfigure tzdata' if you wish to change it.
 
 Setting up golang-github-coreos-go-semver-dev (0.3.0-1) ...
@@ -2714,7 +2746,11 @@
 Building tag database...
  -> Finished parsing the build-deps
 I: Building the package
-I: Running cd /build/reproducible-path/sigstore-go-0.7.0/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S  > ../sigstore-go_0.7.0-2_source.changes
+I: user script /srv/workspace/pbuilder/2312480/tmp/hooks/A99_set_merged_usr starting
+Not re-configuring usrmerge for unstable
+I: user script /srv/workspace/pbuilder/2312480/tmp/hooks/A99_set_merged_usr finished
+hostname: Name or service not known
+I: Running cd /build/reproducible-path/sigstore-go-0.7.0/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S  > ../sigstore-go_0.7.0-2_source.changes
 dpkg-buildpackage: info: source package sigstore-go
 dpkg-buildpackage: info: source version 0.7.0-2
 dpkg-buildpackage: info: source distribution unstable
@@ -2732,67 +2768,67 @@
    dh_autoreconf -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_configure -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_build -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go install -trimpath -v -p 42 github.com/sigstore/sigstore-go/cmd/conformance github.com/sigstore/sigstore-go/cmd/sigstore-go github.com/sigstore/sigstore-go/examples/oci-image-verification github.com/sigstore/sigstore-go/examples/sigstore-go-signing github.com/sigstore/sigstore-go/pkg/bundle github.com/sigstore/sigstore-go/pkg/fulcio/certificate github.com/sigstore/sigstore-go/pkg/root github.com/sigstore/sigstore-go/pkg/sign github.com/sigstore/sigstore-go/pkg/testing/ca github.com/sigstore/sigstore-go/pkg/testing/data github.com/sigstore/sigstore-go/pkg/tlog github.com/sigstore/sigstore-go/pkg/tuf github.com/sigstore/sigstore-go/pkg/util github.com/sigstore/sigstore-go/pkg/verify
-internal/byteorder
+	cd _build && go install -trimpath -v -p 20 github.com/sigstore/sigstore-go/cmd/conformance github.com/sigstore/sigstore-go/cmd/sigstore-go github.com/sigstore/sigstore-go/examples/oci-image-verification github.com/sigstore/sigstore-go/examples/sigstore-go-signing github.com/sigstore/sigstore-go/pkg/bundle github.com/sigstore/sigstore-go/pkg/fulcio/certificate github.com/sigstore/sigstore-go/pkg/root github.com/sigstore/sigstore-go/pkg/sign github.com/sigstore/sigstore-go/pkg/testing/ca github.com/sigstore/sigstore-go/pkg/testing/data github.com/sigstore/sigstore-go/pkg/tlog github.com/sigstore/sigstore-go/pkg/tuf github.com/sigstore/sigstore-go/pkg/util github.com/sigstore/sigstore-go/pkg/verify
+internal/goos
+internal/msan
 internal/unsafeheader
-cmp
 internal/goarch
+internal/asan
+internal/coverage/rtcov
+internal/byteorder
 internal/itoa
-github.com/klauspost/compress/internal/cpuinfo
-log/slog/internal
-container/list
-math/bits
-golang.org/x/exp/constraints
-github.com/sigstore/rekor/pkg/pki/identity
+internal/godebugs
+google.golang.org/protobuf/internal/flags
+cmp
 internal/cpu
-golang.org/x/crypto/cryptobyte/asn1
-crypto/internal/boring/sig
-internal/msan
-github.com/google/go-containerregistry/pkg/v1/types
-golang.org/x/crypto/internal/alias
-log/internal
-internal/nettrace
-go.mongodb.org/mongo-driver/bson/bsonoptions
-github.com/transparency-dev/merkle
-github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/common
+math/bits
 internal/runtime/syscall
-internal/coverage/rtcov
-internal/godebugs
-vendor/golang.org/x/crypto/cryptobyte/asn1
-internal/asan
-encoding
-internal/chacha8rand
-go.opentelemetry.io/otel/trace/embedded
-internal/profilerecord
 unicode/utf16
-crypto/internal/fips140/alias
-internal/runtime/math
-image/color
 unicode/utf8
-go.opentelemetry.io/otel/metric/embedded
+internal/goexperiment
 unicode
+internal/profilerecord
+encoding
 internal/runtime/atomic
+crypto/internal/fips140/alias
+sync/atomic
+crypto/internal/boring/sig
+vendor/golang.org/x/crypto/cryptobyte/asn1
+internal/runtime/math
 internal/abi
-internal/goexperiment
-go.mongodb.org/mongo-driver/bson/bsontype
-vendor/golang.org/x/crypto/internal/alias
+internal/chacha8rand
+internal/runtime/sys
 crypto/internal/fips140deps/byteorder
-google.golang.org/protobuf/internal/flags
-github.com/klauspost/compress/internal/le
-sync/atomic
-internal/goos
-github.com/google/go-containerregistry/pkg/compression
-github.com/docker/cli/cli/config/types
+internal/nettrace
+golang.org/x/crypto/internal/alias
+log/internal
 crypto/internal/fips140/subtle
-internal/runtime/sys
+container/list
+vendor/golang.org/x/crypto/internal/alias
+go.mongodb.org/mongo-driver/bson/bsontype
+go.mongodb.org/mongo-driver/bson/bsonoptions
+github.com/sigstore/rekor/pkg/pki/identity
+image/color
+golang.org/x/exp/constraints
+github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/common
+github.com/pelletier/go-toml/v2/internal/characters
 google.golang.org/protobuf/internal/set
 golang.org/x/crypto/salsa20/salsa
+log/slog/internal
+go.opentelemetry.io/otel/metric/embedded
+github.com/transparency-dev/merkle
+go.opentelemetry.io/otel/trace/embedded
+golang.org/x/crypto/cryptobyte/asn1
+github.com/google/go-containerregistry/pkg/v1/types
 golang.org/x/exp/slices
-github.com/pelletier/go-toml/v2/internal/characters
+github.com/klauspost/compress/internal/cpuinfo
+github.com/klauspost/compress/internal/le
+github.com/google/go-containerregistry/pkg/compression
+github.com/docker/cli/cli/config/types
+internal/runtime/exithook
 crypto/internal/fips140deps/cpu
-internal/bytealg
 math
-internal/runtime/exithook
+internal/bytealg
 internal/stringslite
 internal/race
 internal/sync
@@ -2800,470 +2836,470 @@
 go.opentelemetry.io/otel/internal
 github.com/klauspost/compress
 runtime
+internal/reflectlite
 iter
+sync
 crypto/subtle
-k8s.io/klog/internal/dbg
-internal/reflectlite
 weak
-sync
-maps
+k8s.io/klog/internal/dbg
 slices
-errors
-sort
+maps
 internal/bisect
 google.golang.org/protobuf/internal/pragma
+internal/testlog
 internal/singleflight
-github.com/josharian/intern
 unique
+github.com/josharian/intern
 go.uber.org/zap/internal/pool
-log/slog/internal/buffer
-internal/testlog
 github.com/spf13/viper/internal/encoding
+log/slog/internal/buffer
+errors
+sort
 runtime/cgo
-internal/oserror
-path
+golang.org/x/mod/semver
+internal/godebug
 io
 math/rand/v2
-github.com/sassoftware/relic/signers/sigerrors
+golang.org/x/crypto/cast5
 strconv
+github.com/sassoftware/relic/signers/sigerrors
+path
 github.com/hashicorp/hcl/hcl/strconv
-golang.org/x/crypto/cast5
 vendor/golang.org/x/net/dns/dnsmessage
+internal/oserror
 syscall
-internal/godebug
+bytes
+github.com/google/go-containerregistry/internal/and
 strings
-crypto/internal/randutil
 hash
-bytes
-golang.org/x/mod/semver
+crypto/internal/randutil
 internal/saferio
-github.com/google/go-containerregistry/internal/and
-hash/adler32
 hash/fnv
 hash/crc32
+hash/adler32
 crypto/internal/fips140deps/godebug
 math/rand
+reflect
 crypto
-golang.org/x/crypto/openpgp/errors
 net/netip
+golang.org/x/crypto/openpgp/errors
 golang.org/x/crypto/blowfish
-reflect
 golang.org/x/crypto/openpgp/s2k
-crypto/internal/impl
 crypto/internal/fips140
-k8s.io/klog/internal/severity
+crypto/internal/impl
 regexp/syntax
+net/http/internal/ascii
 html
+k8s.io/klog/internal/severity
 net/http/internal/testcert
-net/http/internal/ascii
+bufio
 vendor/golang.org/x/text/transform
 golang.org/x/text/transform
-bufio
-crypto/tls/internal/fips140tls
 crypto/internal/fips140/sha256
-crypto/internal/fips140/sha512
 crypto/internal/fips140/sha3
+crypto/internal/fips140/sha512
+crypto/tls/internal/fips140tls
 golang.org/x/text/runes
 compress/bzip2
 image
-crypto/sha3
 crypto/internal/fips140/hmac
-internal/syscall/execenv
-internal/syscall/unix
-time
-crypto/internal/fips140/check
+crypto/sha3
 crypto/internal/fips140hash
+crypto/internal/fips140/check
 crypto/internal/fips140/edwards25519/field
-crypto/internal/fips140/aes
 crypto/internal/fips140/hkdf
+crypto/internal/fips140/aes
 crypto/internal/fips140/bigmod
 crypto/internal/fips140/tls12
 crypto/internal/fips140/nistec/fiat
+internal/syscall/execenv
+internal/syscall/unix
+time
 crypto/internal/fips140/tls13
+regexp
 crypto/internal/fips140/edwards25519
 image/internal/imageutil
-regexp
 image/jpeg
+io/fs
+context
+go.uber.org/zap/buffer
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.1
+github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.2
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v1
-github.com/google/go-containerregistry/internal/retry/wait
 k8s.io/klog/internal/clock
-io/fs
-github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.2
-go.uber.org/zap/buffer
-context
+github.com/google/go-containerregistry/internal/retry/wait
 internal/poll
+crypto/internal/fips140/nistec
 go.uber.org/zap/internal/bufferpool
 go.uber.org/zap/internal/stacktrace
 go.opentelemetry.io/otel/internal/baggage
-crypto/internal/fips140/nistec
-github.com/spf13/afero/internal/common
 internal/filepathlite
 embed
+github.com/spf13/afero/internal/common
 google.golang.org/protobuf/internal/editiondefaults
 os
 internal/fmtsort
-go.opentelemetry.io/otel/internal/attribute
 encoding/binary
+go.opentelemetry.io/otel/internal/attribute
 encoding/base64
 golang.org/x/crypto/internal/poly1305
+github.com/klauspost/compress/internal/snapref
 vendor/golang.org/x/crypto/internal/poly1305
 github.com/cespare/xxhash
-github.com/klauspost/compress/internal/snapref
 golang.org/x/sys/unix
-golang.org/x/crypto/nacl/secretbox
 encoding/pem
 golang.org/x/crypto/openpgp/armor
+golang.org/x/crypto/nacl/secretbox
+fmt
 google.golang.org/protobuf/internal/detrand
 crypto/internal/sysrand
+path/filepath
+golang.org/x/sys/cpu
+vendor/golang.org/x/sys/cpu
 io/ioutil
-go.uber.org/zap/internal/exit
 internal/sysinfo
+go.uber.org/zap/internal/exit
 k8s.io/klog/internal/buffer
-vendor/golang.org/x/sys/cpu
-fmt
-golang.org/x/sys/cpu
-path/filepath
 net
 crypto/internal/entropy
 crypto/internal/fips140/drbg
+os/exec
+github.com/shibumi/go-pathspec
+github.com/spf13/afero/mem
 golang.org/x/crypto/blake2b
 golang.org/x/crypto/sha3
+crypto/internal/fips140/aes/gcm
 crypto/internal/fips140only
-crypto/internal/fips140/ed25519
 crypto/internal/fips140/ecdsa
 crypto/internal/fips140/ecdh
-crypto/internal/fips140/aes/gcm
-crypto/internal/fips140/mlkem
+crypto/internal/fips140/ed25519
 crypto/internal/fips140/rsa
-github.com/shibumi/go-pathspec
-os/exec
-github.com/spf13/afero/mem
-crypto/rc4
+crypto/internal/fips140/mlkem
 crypto/md5
+crypto/rc4
 crypto/cipher
 github.com/skratchdot/open-golang/open
 github.com/mitchellh/go-homedir
+encoding/hex
+google.golang.org/protobuf/internal/errors
 go/token
+compress/flate
+math/big
+vendor/golang.org/x/net/http2/hpack
+encoding/json
 google.golang.org/protobuf/internal/version
+net/url
 log
 runtime/debug
-net/url
 github.com/opencontainers/go-digest
-encoding/hex
-google.golang.org/protobuf/internal/errors
-go.uber.org/zap/internal/color
-golang.org/x/sync/errgroup
-text/tabwriter
-github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer
-math/big
-text/template/parse
-github.com/subosito/gotenv
-encoding/json
-encoding/csv
-compress/flate
-database/sql/driver
-github.com/hashicorp/hcl/hcl/token
-github.com/pelletier/go-toml/v2/internal/danger
 vendor/golang.org/x/text/unicode/norm
-github.com/go-openapi/runtime/logger
-encoding/xml
+mime
+google.golang.org/protobuf/encoding/protowire
 mime/quotedprintable
-encoding/gob
-golang.org/x/text/unicode/norm
-github.com/opentracing/opentracing-go/log
-gopkg.in/yaml.v3
-github.com/transparency-dev/merkle/compact
 net/http/internal
-os/user
-gopkg.in/square/go-jose.v2/json
-mime
-crypto/internal/boring
 runtime/trace
-gopkg.in/ini.v1
-github.com/pkg/errors
-vendor/golang.org/x/net/http2/hpack
 flag
+google.golang.org/protobuf/reflect/protoreflect
+github.com/pkg/errors
+github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer
+encoding/csv
+crypto/internal/boring
 crypto/des
 golang.org/x/crypto/chacha20
 vendor/golang.org/x/crypto/chacha20
-google.golang.org/protobuf/encoding/protowire
-github.com/go-jose/go-jose/v3/json
-github.com/pelletier/go-toml/v2/unstable
-github.com/containerd/stargz-snapshotter/estargz/errorutil
-github.com/transparency-dev/merkle/proof
-github.com/hashicorp/hcl/hcl/ast
-github.com/hashicorp/hcl/hcl/scanner
+github.com/sigstore/sigstore-go/pkg/util
+vendor/golang.org/x/text/unicode/bidi
+encoding/xml
+database/sql/driver
+testing
+gopkg.in/yaml.v3
+golang.org/x/sync/errgroup
+github.com/go-openapi/analysis/internal/debug
+encoding/gob
 crypto/aes
 crypto/ecdh
 crypto/sha512
+crypto/sha1
 crypto/sha256
 crypto/hmac
-crypto/sha1
-github.com/hashicorp/hcl/json/token
-github.com/klauspost/compress/fse
-github.com/opencontainers/image-spec/specs-go
-golang.org/x/sys/execabs
-github.com/google/go-containerregistry/internal/retry
-github.com/davecgh/go-spew/spew
-vendor/golang.org/x/crypto/chacha20poly1305
-github.com/opencontainers/image-spec/specs-go/v1
-github.com/pmezard/go-difflib/difflib
-github.com/transparency-dev/merkle/rfc6962
 golang.org/x/crypto/ssh/internal/bcrypt_pbkdf
+vendor/golang.org/x/crypto/chacha20poly1305
+compress/gzip
 golang.org/x/crypto/pbkdf2
-google.golang.org/protobuf/reflect/protoreflect
-github.com/hashicorp/hcl/json/scanner
+text/tabwriter
 github.com/oklog/ulid
-golang.org/x/crypto/scrypt
-github.com/sigstore/sigstore-go/pkg/util
-github.com/go-openapi/analysis/internal/debug
-github.com/spf13/jwalterweatherman
-vendor/golang.org/x/text/unicode/bidi
-github.com/google/go-containerregistry/pkg/logs
-github.com/hashicorp/hcl/hcl/parser
-github.com/hashicorp/hcl/json/parser
-github.com/google/go-containerregistry/internal/redact
-go.opentelemetry.io/otel/baggage
 github.com/go-openapi/jsonreference/internal
 golang.org/x/crypto/curve25519
-compress/gzip
+golang.org/x/crypto/scrypt
+go.uber.org/zap/internal/color
 compress/zlib
-testing
-github.com/hashicorp/hcl/hcl/printer
-github.com/pelletier/go-toml/v2/internal/tracker
-github.com/klauspost/compress/huff0
-github.com/hashicorp/hcl
+text/template/parse
+golang.org/x/text/unicode/norm
+github.com/spf13/jwalterweatherman
+github.com/subosito/gotenv
 internal/profile
 runtime/pprof
-github.com/google/go-containerregistry/internal/gzip
 vendor/golang.org/x/text/secure/bidirule
-text/template
-vendor/golang.org/x/net/idna
+github.com/hashicorp/hcl/hcl/token
+gopkg.in/ini.v1
+github.com/pelletier/go-toml/v2/internal/danger
 google.golang.org/protobuf/internal/descfmt
 google.golang.org/protobuf/internal/descopts
-google.golang.org/protobuf/internal/encoding/messageset
 google.golang.org/protobuf/internal/strs
-google.golang.org/protobuf/internal/genid
+google.golang.org/protobuf/internal/encoding/messageset
 google.golang.org/protobuf/internal/order
+google.golang.org/protobuf/internal/genid
 google.golang.org/protobuf/runtime/protoiface
+vendor/golang.org/x/net/idna
 google.golang.org/protobuf/internal/protolazy
 google.golang.org/protobuf/reflect/protoregistry
-google.golang.org/protobuf/internal/encoding/json
 google.golang.org/protobuf/internal/encoding/text
+google.golang.org/protobuf/internal/encoding/json
+golang.org/x/term
+github.com/fsnotify/fsnotify/internal
+github.com/hashicorp/hcl/hcl/ast
+github.com/hashicorp/hcl/hcl/scanner
+github.com/hashicorp/hcl/json/token
+github.com/fsnotify/fsnotify
+google.golang.org/protobuf/proto
+github.com/hashicorp/hcl/hcl/parser
+github.com/hashicorp/hcl/json/scanner
+github.com/pelletier/go-toml/v2/unstable
+github.com/go-openapi/runtime/logger
+github.com/opentracing/opentracing-go/log
+github.com/hashicorp/hcl/hcl/printer
+go.opentelemetry.io/otel/baggage
+github.com/transparency-dev/merkle/compact
+github.com/hashicorp/hcl/json/parser
+google.golang.org/protobuf/internal/encoding/defval
+text/template
+github.com/transparency-dev/merkle/rfc6962
+github.com/transparency-dev/merkle/proof
+os/user
+gopkg.in/square/go-jose.v2/json
+github.com/go-jose/go-jose/v3/json
+github.com/google/go-containerregistry/internal/gzip
+github.com/pelletier/go-toml/v2/internal/tracker
+github.com/containerd/stargz-snapshotter/estargz/errorutil
+github.com/klauspost/compress/fse
+github.com/secure-systems-lab/go-securesystemslib/cjson
+github.com/mailru/easyjson/jlexer
 crypto/dsa
-crypto/internal/boring/bbig
 crypto/elliptic
+crypto/internal/boring/bbig
 encoding/asn1
 crypto/rand
-github.com/google/certificate-transparency-go/asn1
-golang.org/x/term
-github.com/fsnotify/fsnotify/internal
+github.com/blang/semver
+google.golang.org/protobuf/internal/filedesc
+google.golang.org/protobuf/encoding/prototext
 crypto/ed25519
-crypto/internal/hpke
-golang.org/x/crypto/openpgp/elgamal
-github.com/segmentio/ksuid
+github.com/hashicorp/hcl
+go.uber.org/atomic
 crypto/rsa
-github.com/klauspost/compress/zstd
+github.com/secure-systems-lab/go-securesystemslib/encrypted
+crypto/internal/hpke
+go.mongodb.org/mongo-driver/bson/primitive
 golang.org/x/crypto/ed25519
+golang.org/x/crypto/openpgp/elgamal
+go.uber.org/multierr
+github.com/jedisct1/go-minisign
 golang.org/x/mod/sumdb/note
-google.golang.org/protobuf/proto
-github.com/secure-systems-lab/go-securesystemslib/encrypted
 github.com/spf13/viper/internal/encoding/hcl
-github.com/blang/semver
-github.com/mailru/easyjson/jlexer
-go.uber.org/atomic
-go.mongodb.org/mongo-driver/bson/primitive
+github.com/spf13/viper/internal/encoding/json
+github.com/pelletier/go-toml/v2
 log/slog
-go.opentelemetry.io/otel/codes
-github.com/secure-systems-lab/go-securesystemslib/cjson
+go.uber.org/zap/zapcore
 go.opentelemetry.io/otel/attribute
-github.com/pelletier/go-toml/v2
-github.com/docker/docker-credential-helpers/credentials
+go.opentelemetry.io/otel/codes
+github.com/google/certificate-transparency-go/asn1
+github.com/segmentio/ksuid
 github.com/google/go-containerregistry/pkg/v1
-github.com/spf13/viper/internal/encoding/json
-github.com/sirupsen/logrus
-github.com/fsnotify/fsnotify
-github.com/jedisct1/go-minisign
-google.golang.org/protobuf/internal/encoding/defval
-github.com/docker/docker-credential-helpers/client
-github.com/spf13/viper/internal/encoding/yaml
-github.com/stretchr/testify/assert/yaml
+github.com/klauspost/compress/huff0
+github.com/google/go-containerregistry/pkg/logs
 github.com/sigstore/sigstore/pkg/signature/options
-go.uber.org/multierr
-github.com/sigstore/sigstore/pkg/oauth
-github.com/docker/cli/cli/config/credentials
-html/template
-github.com/google/certificate-transparency-go/x509/pkix
-crypto/x509/pkix
+github.com/opencontainers/image-spec/specs-go
+go.mongodb.org/mongo-driver/x/bsonx/bsoncore
 vendor/golang.org/x/crypto/cryptobyte
+crypto/x509/pkix
 golang.org/x/crypto/cryptobyte
-go.mongodb.org/mongo-driver/x/bsonx/bsoncore
-github.com/docker/docker/pkg/homedir
-archive/tar
-github.com/vbatts/tar-split/archive/tar
-go.uber.org/zap/zapcore
-go.opentelemetry.io/otel/trace
+github.com/opencontainers/image-spec/specs-go/v1
+github.com/docker/docker-credential-helpers/credentials
+github.com/spf13/viper/internal/encoding/yaml
+golang.org/x/sys/execabs
+github.com/sirupsen/logrus
 go.opentelemetry.io/otel/metric
+go.opentelemetry.io/otel/trace
 go.opentelemetry.io/otel/semconv/v1.17.0
 github.com/google/go-containerregistry/pkg/v1/match
-github.com/google/go-containerregistry/pkg/v1/stream
+github.com/docker/docker-credential-helpers/client
 github.com/google/go-containerregistry/pkg/legacy
-github.com/google/go-containerregistry/internal/verify
-google.golang.org/protobuf/encoding/prototext
-google.golang.org/protobuf/internal/filedesc
-github.com/docker/cli/cli/config/configfile
+github.com/klauspost/compress/zstd
+github.com/google/go-containerregistry/pkg/v1/stream
+github.com/google/go-containerregistry/internal/redact
 crypto/ecdsa
 github.com/spf13/viper/internal/encoding/toml
-github.com/docker/cli/cli/config
+github.com/docker/cli/cli/config/credentials
+github.com/google/go-containerregistry/internal/retry
+github.com/google/go-containerregistry/internal/verify
+github.com/davecgh/go-spew/spew
+github.com/pmezard/go-difflib/difflib
+github.com/google/certificate-transparency-go/x509/pkix
+github.com/stretchr/testify/assert/yaml
 k8s.io/klog/internal/sloghandler
 github.com/go-logr/logr
-github.com/spf13/cast
+github.com/sigstore/sigstore/pkg/oauth
+html/template
+go.mongodb.org/mongo-driver/bson/bsonrw
 github.com/go-logr/logr/funcr
 k8s.io/klog/internal/serialize
-k8s.io/klog
-go.mongodb.org/mongo-driver/bson/bsonrw
+google.golang.org/protobuf/encoding/protojson
+google.golang.org/protobuf/internal/encoding/tag
 go.uber.org/zap/internal
-github.com/spf13/viper/internal/encoding/dotenv
-github.com/spf13/viper/internal/encoding/ini
+google.golang.org/protobuf/internal/impl
+github.com/docker/cli/cli/config/configfile
+golang.org/x/crypto/openpgp/packet
 github.com/google/certificate-transparency-go/tls
 gopkg.in/square/go-jose.v2/cipher
-golang.org/x/crypto/openpgp/packet
 github.com/go-jose/go-jose/v3/cipher
 github.com/go-logr/stdr
-google.golang.org/protobuf/internal/encoding/tag
-google.golang.org/protobuf/encoding/protojson
-google.golang.org/protobuf/internal/impl
+k8s.io/klog
+archive/tar
+github.com/docker/docker/pkg/homedir
+github.com/vbatts/tar-split/archive/tar
+github.com/docker/cli/cli/config
+github.com/spf13/cast
+go.mongodb.org/mongo-driver/bson/bsoncodec
+golang.org/x/crypto/openpgp
+github.com/spf13/viper/internal/encoding/dotenv
+github.com/spf13/viper/internal/encoding/ini
 github.com/google/go-containerregistry/internal/zstd
 github.com/containerd/stargz-snapshotter/estargz
 github.com/google/go-containerregistry/internal/compression
 github.com/google/go-containerregistry/pkg/v1/partial
-golang.org/x/crypto/openpgp
 github.com/google/go-containerregistry/pkg/v1/empty
-go.mongodb.org/mongo-driver/bson/bsoncodec
+github.com/google/go-containerregistry/pkg/name
+crypto/x509
 vendor/golang.org/x/net/http/httpproxy
-github.com/mailru/easyjson/buffer
+github.com/google/uuid
 github.com/mitchellh/mapstructure
 net/textproto
-github.com/google/go-containerregistry/pkg/name
-github.com/google/uuid
-crypto/x509
-github.com/google/certificate-transparency-go/x509
 github.com/spf13/pflag
+github.com/google/certificate-transparency-go/x509
+github.com/mailru/easyjson/buffer
+github.com/google/go-containerregistry/pkg/authn
+github.com/sigstore/sigstore/pkg/signature/payload
 github.com/mailru/easyjson/jwriter
 vendor/golang.org/x/net/http/httpguts
-net/mail
 mime/multipart
-github.com/google/go-containerregistry/pkg/authn
-github.com/sigstore/sigstore/pkg/signature/payload
+net/mail
+go.mongodb.org/mongo-driver/bson
+github.com/google/certificate-transparency-go
 github.com/google/go-containerregistry/internal/estargz
+github.com/spf13/cobra
+github.com/google/certificate-transparency-go/gossip/minimal/x509ext
 github.com/google/go-containerregistry/pkg/v1/tarball
-github.com/secure-systems-lab/go-securesystemslib/signerverifier
 github.com/sigstore/sigstore/pkg/cryptoutils
-github.com/asaskevich/govalidator
 github.com/digitorus/pkcs7
+github.com/asaskevich/govalidator
+github.com/secure-systems-lab/go-securesystemslib/signerverifier
 gopkg.in/square/go-jose.v2
 github.com/go-jose/go-jose/v3
 crypto/tls
 golang.org/x/crypto/ssh
-github.com/google/certificate-transparency-go
-go.mongodb.org/mongo-driver/bson
-github.com/sigstore/timestamp-authority/pkg/x509
-github.com/sigstore/sigstore-go/pkg/fulcio/certificate
-github.com/sigstore/sigstore/pkg/signature
+github.com/google/go-containerregistry/internal/windows
 github.com/google/go-containerregistry/pkg/legacy/tarball
 github.com/google/go-containerregistry/pkg/v1/mutate
-github.com/google/go-containerregistry/internal/windows
-github.com/google/certificate-transparency-go/gossip/minimal/x509ext
-github.com/spf13/cobra
+github.com/sigstore/sigstore-go/pkg/fulcio/certificate
+github.com/sigstore/timestamp-authority/pkg/x509
+github.com/sigstore/sigstore/pkg/signature
 github.com/digitorus/timestamp
 github.com/google/go-containerregistry/pkg/v1/layout
 github.com/sigstore/timestamp-authority/pkg/verification
 github.com/sigstore/rekor/pkg/pki/minisign
 github.com/theupdateframework/go-tuf/metadata
-github.com/sigstore/rekor/pkg/pki/x509
-github.com/theupdateframework/go-tuf/metadata/trustedmetadata
 google.golang.org/protobuf/internal/filetype
+github.com/sigstore/rekor/pkg/pki/x509
 google.golang.org/protobuf/runtime/protoimpl
-github.com/sigstore/protobuf-specs/gen/pb-go/dsse
 google.golang.org/protobuf/types/known/timestamppb
+github.com/sigstore/protobuf-specs/gen/pb-go/dsse
 google.golang.org/protobuf/types/known/structpb
 google.golang.org/protobuf/types/descriptorpb
 github.com/google/certificate-transparency-go/client/configpb
-github.com/secure-systems-lab/go-securesystemslib/dsse
+github.com/theupdateframework/go-tuf/metadata/trustedmetadata
 github.com/in-toto/attestation/go/v1
-github.com/sigstore/sigstore/pkg/signature/dsse
-github.com/in-toto/in-toto-golang/in_toto
 google.golang.org/genproto/googleapis/api/annotations
 github.com/sigstore/protobuf-specs/gen/pb-go/common/v1
-net/http/httptrace
-github.com/sassoftware/relic/lib/x509tools
-net/http
+github.com/secure-systems-lab/go-securesystemslib/dsse
 github.com/sigstore/protobuf-specs/gen/pb-go/rekor/v1
 github.com/sigstore/protobuf-specs/gen/pb-go/trustroot/v1
+github.com/in-toto/in-toto-golang/in_toto
+github.com/sigstore/sigstore/pkg/signature/dsse
 github.com/sigstore/protobuf-specs/gen/pb-go/bundle/v1
+net/http/httptrace
+github.com/sassoftware/relic/lib/x509tools
+net/http
 github.com/sassoftware/relic/lib/pkcs7
 github.com/sigstore/rekor/pkg/pki/pkcs7
 github.com/theupdateframework/go-tuf/metadata/fetcher
-expvar
-github.com/sigstore/rekor/pkg/pki/pgp
-github.com/go-openapi/runtime/middleware/header
-github.com/go-chi/chi
-github.com/go-openapi/runtime/middleware/denco
-github.com/opentracing/opentracing-go
+github.com/go-openapi/errors
 github.com/magiconair/properties
+github.com/opentracing/opentracing-go
+net/http/httputil
 go.opentelemetry.io/otel/propagation
 github.com/spf13/afero
-net/http/pprof
-go.opentelemetry.io/otel/semconv/internal/v2
-go.uber.org/zap
 golang.org/x/net/context/ctxhttp
-github.com/docker/distribution/registry/client/auth/challenge
-net/http/httputil
+expvar
+github.com/go-chi/chi
+github.com/go-openapi/swag
+net/http/pprof
+github.com/sigstore/rekor/pkg/pki/pgp
 github.com/sigstore/rekor/pkg/pki/ssh
 github.com/sigstore/rekor/pkg/util
-golang.org/x/oauth2/internal
+github.com/go-openapi/runtime/middleware/denco
+github.com/go-openapi/runtime/middleware/header
 github.com/google/certificate-transparency-go/x509util
-github.com/hashicorp/go-cleanhttp
-net/http/httptest
-github.com/go-openapi/errors
-github.com/go-openapi/swag
-github.com/google/certificate-transparency-go/jsonclient
+go.opentelemetry.io/otel/semconv/internal/v2
+go.uber.org/zap
 github.com/theupdateframework/go-tuf/metadata/config
-github.com/theupdateframework/go-tuf/metadata/updater
-golang.org/x/oauth2
-github.com/opentracing/opentracing-go/ext
+github.com/google/certificate-transparency-go/jsonclient
 go.opentelemetry.io/otel/internal/global
-github.com/hashicorp/go-retryablehttp
-github.com/sigstore/rekor/pkg/pki
+github.com/theupdateframework/go-tuf/metadata/updater
+github.com/hashicorp/go-cleanhttp
+golang.org/x/oauth2/internal
 github.com/go-openapi/strfmt
+github.com/docker/distribution/registry/client/auth/challenge
+net/http/httptest
+github.com/opentracing/opentracing-go/ext
 go.opentelemetry.io/otel/semconv/v1.17.0/httpconv
+github.com/sigstore/rekor/pkg/pki
+github.com/hashicorp/go-retryablehttp
 github.com/google/certificate-transparency-go/client
-github.com/stretchr/testify/assert
+golang.org/x/oauth2
 github.com/spf13/viper/internal/encoding/javaproperties
-github.com/coreos/go-oidc/v3/oidc
 github.com/google/go-containerregistry/pkg/v1/remote/transport
-github.com/google/certificate-transparency-go/loglist3
+go.opentelemetry.io/otel
+github.com/coreos/go-oidc/v3/oidc
+github.com/stretchr/testify/assert
 github.com/go-chi/chi/middleware
+github.com/google/certificate-transparency-go/loglist3
 github.com/sigstore/sigstore-go/pkg/tuf
 github.com/google/certificate-transparency-go/ctutil
-go.opentelemetry.io/otel
 github.com/sigstore/sigstore/pkg/oauthflow
 github.com/google/go-containerregistry/pkg/v1/remote
+github.com/spf13/viper
 github.com/go-openapi/jsonpointer
 github.com/sigstore/sigstore-go/pkg/root
-github.com/spf13/viper
 github.com/go-openapi/jsonreference
-github.com/sigstore/rekor/pkg/log
-github.com/go-openapi/spec
 github.com/go-openapi/runtime
+github.com/go-openapi/spec
+github.com/sigstore/rekor/pkg/log
 github.com/go-openapi/runtime/yamlpc
 github.com/go-openapi/runtime/security
 github.com/google/go-containerregistry/pkg/crane
-github.com/go-openapi/analysis/internal/flatten/operations
 github.com/go-openapi/analysis/internal/flatten/normalize
 github.com/go-openapi/analysis/internal/flatten/replace
 github.com/go-openapi/analysis/internal/flatten/schutils
+github.com/go-openapi/analysis/internal/flatten/operations
 github.com/go-openapi/analysis/internal/flatten/sortref
 github.com/go-openapi/analysis
 github.com/go-openapi/loads
@@ -3274,37 +3310,37 @@
 github.com/go-openapi/runtime/client
 github.com/sigstore/rekor/pkg/types
 github.com/sigstore/rekor/pkg/generated/client/index
-github.com/sigstore/rekor/pkg/generated/client/pubkey
 github.com/sigstore/rekor/pkg/generated/client/tlog
 github.com/sigstore/rekor/pkg/generated/client/entries
+github.com/sigstore/rekor/pkg/generated/client/pubkey
 github.com/sigstore/rekor/pkg/types/dsse
-github.com/sigstore/rekor/pkg/types/intoto
 github.com/sigstore/rekor/pkg/types/hashedrekord
-github.com/sigstore/rekor/pkg/types/rekord
+github.com/sigstore/rekor/pkg/types/intoto
 github.com/sigstore/rekor/pkg/tle
+github.com/sigstore/rekor/pkg/types/rekord
 github.com/sigstore/rekor/pkg/generated/client
 github.com/sigstore/rekor/pkg/verify
 github.com/sigstore/rekor/pkg/client
-github.com/sigstore/rekor/pkg/types/intoto/v0.0.2
 github.com/sigstore/rekor/pkg/types/dsse/v0.0.1
 github.com/sigstore/rekor/pkg/types/hashedrekord/v0.0.1
+github.com/sigstore/rekor/pkg/types/intoto/v0.0.2
 github.com/sigstore/sigstore-go/pkg/tlog
 github.com/sigstore/sigstore-go/pkg/verify
 github.com/sigstore/sigstore-go/pkg/bundle
+github.com/sigstore/sigstore-go/pkg/sign
 github.com/sigstore/sigstore-go/cmd/sigstore-go
 github.com/sigstore/sigstore-go/examples/oci-image-verification
-github.com/sigstore/sigstore-go/pkg/sign
 github.com/sigstore/sigstore-go/pkg/testing/ca
 github.com/sigstore/sigstore-go/pkg/testing/data
-github.com/sigstore/sigstore-go/examples/sigstore-go-signing
 github.com/sigstore/sigstore-go/cmd/conformance
+github.com/sigstore/sigstore-go/examples/sigstore-go-signing
    debian/rules execute_before_dh_auto_test
 make[1]: Entering directory '/build/reproducible-path/sigstore-go-0.7.0'
 rm -fv _build/src/github.com/sigstore/sigstore-go/pkg/verify/sct_test.go
 removed '_build/src/github.com/sigstore/sigstore-go/pkg/verify/sct_test.go'
 make[1]: Leaving directory '/build/reproducible-path/sigstore-go-0.7.0'
    dh_auto_test -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go test -vet=off -v -p 42 github.com/sigstore/sigstore-go/cmd/conformance github.com/sigstore/sigstore-go/cmd/sigstore-go github.com/sigstore/sigstore-go/examples/oci-image-verification github.com/sigstore/sigstore-go/examples/sigstore-go-signing github.com/sigstore/sigstore-go/pkg/bundle github.com/sigstore/sigstore-go/pkg/fulcio/certificate github.com/sigstore/sigstore-go/pkg/root github.com/sigstore/sigstore-go/pkg/sign github.com/sigstore/sigstore-go/pkg/testing/ca github.com/sigstore/sigstore-go/pkg/testing/data github.com/sigstore/sigstore-go/pkg/tlog github.com/sigstore/sigstore-go/pkg/tuf github.com/sigstore/sigstore-go/pkg/util github.com/sigstore/sigstore-go/pkg/verify
+	cd _build && go test -vet=off -v -p 20 github.com/sigstore/sigstore-go/cmd/conformance github.com/sigstore/sigstore-go/cmd/sigstore-go github.com/sigstore/sigstore-go/examples/oci-image-verification github.com/sigstore/sigstore-go/examples/sigstore-go-signing github.com/sigstore/sigstore-go/pkg/bundle github.com/sigstore/sigstore-go/pkg/fulcio/certificate github.com/sigstore/sigstore-go/pkg/root github.com/sigstore/sigstore-go/pkg/sign github.com/sigstore/sigstore-go/pkg/testing/ca github.com/sigstore/sigstore-go/pkg/testing/data github.com/sigstore/sigstore-go/pkg/tlog github.com/sigstore/sigstore-go/pkg/tuf github.com/sigstore/sigstore-go/pkg/util github.com/sigstore/sigstore-go/pkg/verify
 ?   	github.com/sigstore/sigstore-go/cmd/conformance	[no test files]
 ?   	github.com/sigstore/sigstore-go/cmd/sigstore-go	[no test files]
 ?   	github.com/sigstore/sigstore-go/examples/oci-image-verification	[no test files]
@@ -3360,110 +3396,110 @@
 === CONT  TestMinVersion
 === RUN   TestMinVersion/old-format
 === PAUSE TestMinVersion/old-format
-=== CONT  TestSignatureContent
-=== CONT  Test_validate
-=== CONT  TestVerificationContent
-=== CONT  TestMediaTypeString
-=== CONT  TestTimestamps
 === RUN   TestMinVersion/old-format-unexpected
-=== CONT  TestEnvelope
-=== RUN   TestEnvelope/dsse_envelope
-=== RUN   TestTimestamps/missing_verification_material
 === PAUSE TestMinVersion/old-format-unexpected
-=== RUN   Test_validate/invalid_media_type
-=== RUN   TestMediaTypeString/normal-semver
-=== RUN   TestSignatureContent/dsse_envelope
-=== RUN   TestTimestamps/empty_timestamp_data
-=== RUN   TestEnvelope/message_signature
---- PASS: TestEnvelope (0.00s)
-    --- PASS: TestEnvelope/dsse_envelope (0.00s)
-    --- PASS: TestEnvelope/message_signature (0.00s)
-=== PAUSE TestMediaTypeString/normal-semver
-=== RUN   TestTimestamps/one_timestamp
 === RUN   TestMinVersion/old-format-without-v
 === PAUSE TestMinVersion/old-format-without-v
-=== RUN   TestTimestamps/multiple_timestamps
 === RUN   TestMinVersion/new-format
 === PAUSE TestMinVersion/new-format
---- PASS: TestTimestamps (0.00s)
-    --- PASS: TestTimestamps/missing_verification_material (0.00s)
-    --- PASS: TestTimestamps/empty_timestamp_data (0.00s)
-    --- PASS: TestTimestamps/one_timestamp (0.00s)
-    --- PASS: TestTimestamps/multiple_timestamps (0.00s)
-=== RUN   TestSignatureContent/dsse_envelope_with_nil_signature
-=== RUN   TestSignatureContent/dsse_envelope_with_nil_payload
-=== RUN   TestSignatureContent/message_signature
-=== RUN   TestMediaTypeString/old-semver1
-=== RUN   Test_validate/version_too_low
-=== RUN   Test_validate/version_too_high
-=== PAUSE TestMediaTypeString/old-semver1
 === RUN   TestMinVersion/new-format-exact
 === PAUSE TestMinVersion/new-format-exact
 === RUN   TestMinVersion/new-format-unexpected
 === PAUSE TestMinVersion/new-format-unexpected
-=== RUN   TestMediaTypeString/old-semver2
-=== PAUSE TestMediaTypeString/old-semver2
-=== RUN   TestMediaTypeString/blank
-=== PAUSE TestMediaTypeString/blank
-=== RUN   TestMediaTypeString/invalid
-=== PAUSE TestMediaTypeString/invalid
---- PASS: TestSignatureContent (0.00s)
-    --- PASS: TestSignatureContent/dsse_envelope (0.00s)
-    --- PASS: TestSignatureContent/dsse_envelope_with_nil_signature (0.00s)
-    --- PASS: TestSignatureContent/dsse_envelope_with_nil_payload (0.00s)
-    --- PASS: TestSignatureContent/message_signature (0.00s)
-=== RUN   Test_validate/no_verification_material
 === RUN   TestMinVersion/new-format-without-v
 === PAUSE TestMinVersion/new-format-without-v
 === RUN   TestMinVersion/new-format-without-v-unexpected
 === PAUSE TestMinVersion/new-format-without-v-unexpected
 === RUN   TestMinVersion/blank
 === PAUSE TestMinVersion/blank
-=== CONT  TestMediaTypeString/normal-semver
 === RUN   TestMinVersion/invalid
 === PAUSE TestMinVersion/invalid
 === CONT  TestMinVersion/old-format
+=== CONT  TestTimestamps
+=== RUN   TestTimestamps/missing_verification_material
+=== CONT  TestMinVersion/blank
+=== CONT  TestEnvelope
+=== RUN   TestEnvelope/dsse_envelope
+=== RUN   TestEnvelope/message_signature
+--- PASS: TestEnvelope (0.00s)
+    --- PASS: TestEnvelope/dsse_envelope (0.00s)
+    --- PASS: TestEnvelope/message_signature (0.00s)
+=== CONT  TestSignatureContent
+=== RUN   TestSignatureContent/dsse_envelope
+=== RUN   TestSignatureContent/dsse_envelope_with_nil_signature
+=== RUN   TestSignatureContent/dsse_envelope_with_nil_payload
+=== RUN   TestSignatureContent/message_signature
+--- PASS: TestSignatureContent (0.00s)
+    --- PASS: TestSignatureContent/dsse_envelope (0.00s)
+    --- PASS: TestSignatureContent/dsse_envelope_with_nil_signature (0.00s)
+    --- PASS: TestSignatureContent/dsse_envelope_with_nil_payload (0.00s)
+    --- PASS: TestSignatureContent/message_signature (0.00s)
+=== CONT  TestVerificationContent
+=== CONT  TestMediaTypeString
+=== RUN   TestMediaTypeString/normal-semver
+=== PAUSE TestMediaTypeString/normal-semver
+=== RUN   TestMediaTypeString/old-semver1
+=== PAUSE TestMediaTypeString/old-semver1
+=== RUN   TestMediaTypeString/old-semver2
+=== PAUSE TestMediaTypeString/old-semver2
+=== RUN   TestMediaTypeString/blank
+=== PAUSE TestMediaTypeString/blank
+=== RUN   TestMediaTypeString/invalid
+=== PAUSE TestMediaTypeString/invalid
+=== CONT  TestMediaTypeString/normal-semver
+=== CONT  Test_validate
+=== RUN   Test_validate/invalid_media_type
+=== RUN   Test_validate/version_too_low
+=== RUN   Test_validate/version_too_high
+=== RUN   Test_validate/no_verification_material
+=== RUN   Test_validate/v0.1_with_no_inclusion_promise
+=== RUN   Test_validate/v0.1_with_inclusion_promise
+=== RUN   Test_validate/v0.1_with_inclusion_promise_&_proof_without_checkpoint
+=== RUN   Test_validate/v0.1_with_inclusion_proof_&_promise
+=== RUN   TestTimestamps/empty_timestamp_data
+=== RUN   Test_validate/v0.2_with_no_inclusion_proof
+=== RUN   TestTimestamps/one_timestamp
+=== RUN   TestTimestamps/multiple_timestamps
+--- PASS: TestTimestamps (0.01s)
+    --- PASS: TestTimestamps/missing_verification_material (0.00s)
+    --- PASS: TestTimestamps/empty_timestamp_data (0.00s)
+    --- PASS: TestTimestamps/one_timestamp (0.00s)
+    --- PASS: TestTimestamps/multiple_timestamps (0.00s)
+=== CONT  TestMinVersion/new-format-without-v-unexpected
+=== CONT  TestMinVersion/new-format-without-v
 === CONT  TestMinVersion/new-format-unexpected
 === CONT  TestMinVersion/new-format-exact
 === CONT  TestMinVersion/new-format
 === CONT  TestMinVersion/old-format-without-v
 === CONT  TestMinVersion/old-format-unexpected
-=== CONT  TestMediaTypeString/invalid
-=== CONT  TestMinVersion/invalid
-=== CONT  TestMinVersion/blank
 === CONT  TestMediaTypeString/blank
-=== CONT  TestMinVersion/new-format-without-v-unexpected
-=== CONT  TestMinVersion/new-format-without-v
+=== CONT  TestMediaTypeString/invalid
 === CONT  TestMediaTypeString/old-semver2
+=== CONT  TestMinVersion/invalid
 --- PASS: TestMinVersion (0.00s)
     --- PASS: TestMinVersion/old-format (0.00s)
+    --- PASS: TestMinVersion/blank (0.00s)
+    --- PASS: TestMinVersion/new-format-without-v-unexpected (0.00s)
+    --- PASS: TestMinVersion/new-format-without-v (0.00s)
     --- PASS: TestMinVersion/new-format-unexpected (0.00s)
     --- PASS: TestMinVersion/new-format-exact (0.00s)
     --- PASS: TestMinVersion/new-format (0.00s)
     --- PASS: TestMinVersion/old-format-without-v (0.00s)
     --- PASS: TestMinVersion/old-format-unexpected (0.00s)
     --- PASS: TestMinVersion/invalid (0.00s)
-    --- PASS: TestMinVersion/blank (0.00s)
-    --- PASS: TestMinVersion/new-format-without-v-unexpected (0.00s)
-    --- PASS: TestMinVersion/new-format-without-v (0.00s)
 === CONT  TestMediaTypeString/old-semver1
 --- PASS: TestMediaTypeString (0.00s)
     --- PASS: TestMediaTypeString/normal-semver (0.00s)
-    --- PASS: TestMediaTypeString/invalid (0.00s)
     --- PASS: TestMediaTypeString/blank (0.00s)
+    --- PASS: TestMediaTypeString/invalid (0.00s)
     --- PASS: TestMediaTypeString/old-semver2 (0.00s)
     --- PASS: TestMediaTypeString/old-semver1 (0.00s)
-=== RUN   Test_validate/v0.1_with_no_inclusion_promise
-=== RUN   Test_validate/v0.1_with_inclusion_promise
-=== RUN   Test_validate/v0.1_with_inclusion_promise_&_proof_without_checkpoint
-=== RUN   Test_validate/v0.1_with_inclusion_proof_&_promise
-=== RUN   Test_validate/v0.2_with_no_inclusion_proof
 === RUN   Test_validate/v0.2_with_inclusion_proof_without_checkpoint
 === RUN   Test_validate/v0.2_with_inclusion_proof_with_empty_checkpoint
 === RUN   Test_validate/v0.2_with_inclusion_proof
 === RUN   Test_validate/v0.3_with_x.509_certificate_chain
 === RUN   Test_validate/v0.3_without_x.509_certificate_chain
---- PASS: Test_validate (0.01s)
+--- PASS: Test_validate (0.05s)
     --- PASS: Test_validate/invalid_media_type (0.00s)
     --- PASS: Test_validate/version_too_low (0.00s)
     --- PASS: Test_validate/version_too_high (0.00s)
@@ -3476,7 +3512,7 @@
     --- PASS: Test_validate/v0.2_with_inclusion_proof_without_checkpoint (0.00s)
     --- PASS: Test_validate/v0.2_with_inclusion_proof_with_empty_checkpoint (0.00s)
     --- PASS: Test_validate/v0.2_with_inclusion_proof (0.00s)
-    --- PASS: Test_validate/v0.3_with_x.509_certificate_chain (0.00s)
+    --- PASS: Test_validate/v0.3_with_x.509_certificate_chain (0.03s)
     --- PASS: Test_validate/v0.3_without_x.509_certificate_chain (0.00s)
 === RUN   TestVerificationContent/no_verification_material
 === RUN   TestVerificationContent/certificate_chain_with_zero_certs
@@ -3492,7 +3528,7 @@
 === RUN   TestVerificationContent/empty_certificate
 === RUN   TestVerificationContent/public_key
 === RUN   TestVerificationContent/nil_public_key
---- PASS: TestVerificationContent (0.01s)
+--- PASS: TestVerificationContent (0.47s)
     --- PASS: TestVerificationContent/no_verification_material (0.00s)
     --- PASS: TestVerificationContent/certificate_chain_with_zero_certs (0.00s)
     --- PASS: TestVerificationContent/certificate_chain_with_self-signed_cert (0.00s)
@@ -3510,17 +3546,17 @@
 === RUN   FuzzBundle
 --- PASS: FuzzBundle (0.00s)
 PASS
-ok  	github.com/sigstore/sigstore-go/pkg/bundle	0.025s
+ok  	github.com/sigstore/sigstore-go/pkg/bundle	0.548s
 === RUN   TestSummarizeCertificateWithActionsBundle
---- PASS: TestSummarizeCertificateWithActionsBundle (0.00s)
+--- PASS: TestSummarizeCertificateWithActionsBundle (0.02s)
 === RUN   TestSummarizeCertificateWithOauthBundle
 --- PASS: TestSummarizeCertificateWithOauthBundle (0.00s)
 === RUN   TestSummarizeCertificateWithOtherNameSAN
---- PASS: TestSummarizeCertificateWithOtherNameSAN (0.00s)
+--- PASS: TestSummarizeCertificateWithOtherNameSAN (0.01s)
 === RUN   TestCompareExtensions
 --- PASS: TestCompareExtensions (0.00s)
 PASS
-ok  	github.com/sigstore/sigstore-go/pkg/fulcio/certificate	0.018s
+ok  	github.com/sigstore/sigstore-go/pkg/fulcio/certificate	0.100s
 === RUN   TestSigningConfig_FulcioCertificateAuthorityURL
 === RUN   TestSigningConfig_FulcioCertificateAuthorityURL/valid
 === RUN   TestSigningConfig_FulcioCertificateAuthorityURL/empty
@@ -3554,15 +3590,15 @@
 === RUN   TestNewSigningConfigWithOptions
 --- PASS: TestNewSigningConfigWithOptions (0.00s)
 === RUN   TestGetSigstoreTrustedRoot
---- PASS: TestGetSigstoreTrustedRoot (0.00s)
+--- PASS: TestGetSigstoreTrustedRoot (0.01s)
 === RUN   TestTrustedMaterialCollectionECDSA
 --- PASS: TestTrustedMaterialCollectionECDSA (0.00s)
 === RUN   TestTrustedMaterialCollectionED25519
---- PASS: TestTrustedMaterialCollectionED25519 (0.00s)
+--- PASS: TestTrustedMaterialCollectionED25519 (0.01s)
 === RUN   TestTrustedMaterialCollectionRSA
---- PASS: TestTrustedMaterialCollectionRSA (0.21s)
+--- PASS: TestTrustedMaterialCollectionRSA (1.37s)
 === RUN   TestFromJSONToJSON
---- PASS: TestFromJSONToJSON (0.00s)
+--- PASS: TestFromJSONToJSON (0.03s)
 === RUN   TestCertificateAuthority
 === RUN   TestCertificateAuthority/normal
 === RUN   TestCertificateAuthority/no_validity_period_defined
@@ -3572,7 +3608,7 @@
 === RUN   TestCertificateAuthority/bad_leaf
 === RUN   TestCertificateAuthority/bad_intermediate
 === RUN   TestCertificateAuthority/bad_root
---- PASS: TestCertificateAuthority (0.00s)
+--- PASS: TestCertificateAuthority (0.06s)
     --- PASS: TestCertificateAuthority/normal (0.00s)
     --- PASS: TestCertificateAuthority/no_validity_period_defined (0.00s)
     --- PASS: TestCertificateAuthority/before_validity_period (0.00s)
@@ -3580,7 +3616,7 @@
     --- PASS: TestCertificateAuthority/missing_intermediate (0.00s)
     --- PASS: TestCertificateAuthority/bad_leaf (0.00s)
     --- PASS: TestCertificateAuthority/bad_intermediate (0.00s)
-    --- PASS: TestCertificateAuthority/bad_root (0.00s)
+    --- PASS: TestCertificateAuthority/bad_root (0.03s)
 === RUN   TestTimestampingAuthority
 === RUN   TestTimestampingAuthority/normal
 === RUN   TestTimestampingAuthority/no_validity_period_defined
@@ -3591,20 +3627,20 @@
 === RUN   TestTimestampingAuthority/bad_intermediate
 === RUN   TestTimestampingAuthority/bad_root
 === RUN   TestTimestampingAuthority/signature_over_wrong_artifact
---- PASS: TestTimestampingAuthority (0.01s)
-    --- PASS: TestTimestampingAuthority/normal (0.00s)
+--- PASS: TestTimestampingAuthority (0.09s)
+    --- PASS: TestTimestampingAuthority/normal (0.03s)
     --- PASS: TestTimestampingAuthority/no_validity_period_defined (0.00s)
     --- PASS: TestTimestampingAuthority/before_validity_period (0.00s)
-    --- PASS: TestTimestampingAuthority/after_validity_period (0.00s)
+    --- PASS: TestTimestampingAuthority/after_validity_period (0.03s)
     --- PASS: TestTimestampingAuthority/missing_intermediate (0.00s)
     --- PASS: TestTimestampingAuthority/bad_leaf (0.00s)
     --- PASS: TestTimestampingAuthority/bad_intermediate (0.00s)
     --- PASS: TestTimestampingAuthority/bad_root (0.00s)
     --- PASS: TestTimestampingAuthority/signature_over_wrong_artifact (0.00s)
 PASS
-ok  	github.com/sigstore/sigstore-go/pkg/root	0.229s
+ok  	github.com/sigstore/sigstore-go/pkg/root	1.624s
 === RUN   Test_GetCertificate
---- PASS: Test_GetCertificate (4.02s)
+--- PASS: Test_GetCertificate (4.03s)
 === RUN   Test_PlainData
 --- PASS: Test_PlainData (0.00s)
 === RUN   Test_DSSEData
@@ -3614,33 +3650,33 @@
 === RUN   Test_Bundle
 --- PASS: Test_Bundle (0.00s)
 === RUN   Test_GetTimestamp
---- PASS: Test_GetTimestamp (4.02s)
+--- PASS: Test_GetTimestamp (4.01s)
 === RUN   Test_GetTransparencyLogEntry
---- PASS: Test_GetTransparencyLogEntry (0.00s)
+--- PASS: Test_GetTransparencyLogEntry (0.02s)
 PASS
-ok  	github.com/sigstore/sigstore-go/pkg/sign	8.054s
+ok  	github.com/sigstore/sigstore-go/pkg/sign	8.160s
 ?   	github.com/sigstore/sigstore-go/pkg/testing/ca	[no test files]
 ?   	github.com/sigstore/sigstore-go/pkg/testing/data	[no test files]
 === RUN   FuzzParseEntry
 --- PASS: FuzzParseEntry (0.00s)
 PASS
-ok  	github.com/sigstore/sigstore-go/pkg/tlog	0.011s
+ok  	github.com/sigstore/sigstore-go/pkg/tlog	0.068s
 === RUN   TestNewOfflineClientFail
---- PASS: TestNewOfflineClientFail (0.27s)
+--- PASS: TestNewOfflineClientFail (0.05s)
 === RUN   TestRefresh
---- PASS: TestRefresh (0.15s)
+--- PASS: TestRefresh (0.03s)
 === RUN   TestInvalidRoot
---- PASS: TestInvalidRoot (0.00s)
+--- PASS: TestInvalidRoot (0.02s)
 === RUN   TestInvalidRepositoryURL
 --- PASS: TestInvalidRepositoryURL (0.00s)
 === RUN   TestCache
---- PASS: TestCache (0.42s)
+--- PASS: TestCache (0.08s)
 === RUN   TestExpiredTimestamp
---- PASS: TestExpiredTimestamp (0.53s)
+--- PASS: TestExpiredTimestamp (0.05s)
 === RUN   TestConfig
 --- PASS: TestConfig (0.00s)
 PASS
-ok  	github.com/sigstore/sigstore-go/pkg/tuf	1.380s
+ok  	github.com/sigstore/sigstore-go/pkg/tuf	0.284s
 ?   	github.com/sigstore/sigstore-go/pkg/util	[no test files]
 === RUN   TestCertificateIdentityVerify
 --- PASS: TestCertificateIdentityVerify (0.00s)
@@ -3658,84 +3694,84 @@
 === RUN   TestVerifyValidityPeriod/before_validity_period
 === RUN   TestVerifyValidityPeriod/inside_validity_period
 === RUN   TestVerifyValidityPeriod/after_validity_period
---- PASS: TestVerifyValidityPeriod (0.00s)
+--- PASS: TestVerifyValidityPeriod (0.02s)
     --- PASS: TestVerifyValidityPeriod/before_validity_period (0.00s)
     --- PASS: TestVerifyValidityPeriod/inside_validity_period (0.00s)
     --- PASS: TestVerifyValidityPeriod/after_validity_period (0.00s)
 === RUN   TestSignatureVerifier
---- PASS: TestSignatureVerifier (0.01s)
+--- PASS: TestSignatureVerifier (0.04s)
 === RUN   TestEnvelopeSubject
---- PASS: TestEnvelopeSubject (0.01s)
+--- PASS: TestEnvelopeSubject (0.12s)
 === RUN   TestSignatureVerifierMessageSignature
---- PASS: TestSignatureVerifierMessageSignature (0.01s)
+--- PASS: TestSignatureVerifierMessageSignature (0.14s)
 === RUN   TestTooManySubjects
---- PASS: TestTooManySubjects (0.01s)
+--- PASS: TestTooManySubjects (0.17s)
 === RUN   TestTooManyDigests
---- PASS: TestTooManyDigests (0.01s)
+--- PASS: TestTooManyDigests (0.04s)
 === RUN   TestSignedEntityVerifierInitialization
---- PASS: TestSignedEntityVerifierInitialization (0.00s)
+--- PASS: TestSignedEntityVerifierInitialization (0.02s)
 === RUN   TestSignedEntityVerifierInitRequiresTimestamp
---- PASS: TestSignedEntityVerifierInitRequiresTimestamp (0.00s)
+--- PASS: TestSignedEntityVerifierInitRequiresTimestamp (0.01s)
 === RUN   TestEntitySignedByPublicGoodWithTlogVerifiesSuccessfully
---- PASS: TestEntitySignedByPublicGoodWithTlogVerifiesSuccessfully (0.02s)
+--- PASS: TestEntitySignedByPublicGoodWithTlogVerifiesSuccessfully (0.07s)
 === RUN   TestEntitySignedByPublicGoodWithoutTimestampsVerifiesSuccessfully
---- PASS: TestEntitySignedByPublicGoodWithoutTimestampsVerifiesSuccessfully (0.01s)
+--- PASS: TestEntitySignedByPublicGoodWithoutTimestampsVerifiesSuccessfully (0.05s)
 === RUN   TestEntitySignedByPublicGoodWithHighTlogThresholdFails
---- PASS: TestEntitySignedByPublicGoodWithHighTlogThresholdFails (0.01s)
+--- PASS: TestEntitySignedByPublicGoodWithHighTlogThresholdFails (0.03s)
 === RUN   TestEntitySignedByPublicGoodWithoutVerifyingLogEntryFails
 --- PASS: TestEntitySignedByPublicGoodWithoutVerifyingLogEntryFails (0.00s)
 === RUN   TestEntitySignedByPublicGoodWithHighLogTimestampThresholdFails
---- PASS: TestEntitySignedByPublicGoodWithHighLogTimestampThresholdFails (0.01s)
+--- PASS: TestEntitySignedByPublicGoodWithHighLogTimestampThresholdFails (0.08s)
 === RUN   TestEntitySignedByPublicGoodExpectingTSAFails
---- PASS: TestEntitySignedByPublicGoodExpectingTSAFails (0.01s)
+--- PASS: TestEntitySignedByPublicGoodExpectingTSAFails (0.07s)
 === RUN   TestEntitySignedByPublicGoodWithHighObserverTimestampThresholdFails
---- PASS: TestEntitySignedByPublicGoodWithHighObserverTimestampThresholdFails (0.01s)
+--- PASS: TestEntitySignedByPublicGoodWithHighObserverTimestampThresholdFails (0.09s)
 === RUN   TestEntityWithOthernameSan
---- PASS: TestEntityWithOthernameSan (0.01s)
+--- PASS: TestEntityWithOthernameSan (0.04s)
 === RUN   TestVerifyPolicyOptionErors
---- PASS: TestVerifyPolicyOptionErors (0.00s)
+--- PASS: TestVerifyPolicyOptionErors (0.01s)
 === RUN   TestEntitySignedByPublicGoodWithCertificateIdentityVerifiesSuccessfully
---- PASS: TestEntitySignedByPublicGoodWithCertificateIdentityVerifiesSuccessfully (0.02s)
+--- PASS: TestEntitySignedByPublicGoodWithCertificateIdentityVerifiesSuccessfully (0.13s)
 === RUN   TestThatAllTheJSONKeysStartWithALowerCase
---- PASS: TestThatAllTheJSONKeysStartWithALowerCase (0.01s)
+--- PASS: TestThatAllTheJSONKeysStartWithALowerCase (0.06s)
 === RUN   TestSigstoreBundle2Sig
---- PASS: TestSigstoreBundle2Sig (0.00s)
+--- PASS: TestSigstoreBundle2Sig (0.08s)
 === RUN   TestStatementSerializesToValidInTotoStatement
---- PASS: TestStatementSerializesToValidInTotoStatement (0.00s)
+--- PASS: TestStatementSerializesToValidInTotoStatement (0.03s)
 === RUN   TestTlogVerifier
---- PASS: TestTlogVerifier (0.01s)
+--- PASS: TestTlogVerifier (0.11s)
 === RUN   TestIgnoredTLogEntries
---- PASS: TestIgnoredTLogEntries (0.01s)
+--- PASS: TestIgnoredTLogEntries (0.16s)
 === RUN   TestInvalidTLogEntries
---- PASS: TestInvalidTLogEntries (0.00s)
+--- PASS: TestInvalidTLogEntries (0.02s)
 === RUN   TestNoTLogEntries
---- PASS: TestNoTLogEntries (0.00s)
+--- PASS: TestNoTLogEntries (0.02s)
 === RUN   TestDuplicateTlogEntries
---- PASS: TestDuplicateTlogEntries (0.00s)
+--- PASS: TestDuplicateTlogEntries (0.02s)
 === RUN   TestMaxAllowedTlogEntries
---- PASS: TestMaxAllowedTlogEntries (0.00s)
+--- PASS: TestMaxAllowedTlogEntries (0.08s)
 === RUN   TestOfflineInclusionProofVerification
---- PASS: TestOfflineInclusionProofVerification (0.00s)
+--- PASS: TestOfflineInclusionProofVerification (0.08s)
 === RUN   TestTimestampAuthorityVerifier
---- PASS: TestTimestampAuthorityVerifier (0.01s)
+--- PASS: TestTimestampAuthorityVerifier (0.15s)
 === RUN   TestTimestampAuthorityVerifierWithoutThreshold
---- PASS: TestTimestampAuthorityVerifierWithoutThreshold (0.01s)
+--- PASS: TestTimestampAuthorityVerifierWithoutThreshold (0.10s)
 === RUN   TestDuplicateTimestamps
---- PASS: TestDuplicateTimestamps (0.00s)
+--- PASS: TestDuplicateTimestamps (0.05s)
 === RUN   TestBadTSASignature
---- PASS: TestBadTSASignature (0.00s)
+--- PASS: TestBadTSASignature (0.05s)
 === RUN   TestBadTSACertificateChain
---- PASS: TestBadTSACertificateChain (0.00s)
+--- PASS: TestBadTSACertificateChain (0.05s)
 === RUN   TestBadTSACertificateChainOutsideValidityPeriod
 === RUN   TestBadTSACertificateChainOutsideValidityPeriod/valid
 === RUN   TestBadTSACertificateChainOutsideValidityPeriod/invalid:_start_time_in_the_future
 === RUN   TestBadTSACertificateChainOutsideValidityPeriod/invalid:_end_time_in_the_past
---- PASS: TestBadTSACertificateChainOutsideValidityPeriod (0.01s)
-    --- PASS: TestBadTSACertificateChainOutsideValidityPeriod/valid (0.00s)
-    --- PASS: TestBadTSACertificateChainOutsideValidityPeriod/invalid:_start_time_in_the_future (0.00s)
-    --- PASS: TestBadTSACertificateChainOutsideValidityPeriod/invalid:_end_time_in_the_past (0.00s)
+--- PASS: TestBadTSACertificateChainOutsideValidityPeriod (0.12s)
+    --- PASS: TestBadTSACertificateChainOutsideValidityPeriod/valid (0.02s)
+    --- PASS: TestBadTSACertificateChainOutsideValidityPeriod/invalid:_start_time_in_the_future (0.04s)
+    --- PASS: TestBadTSACertificateChainOutsideValidityPeriod/invalid:_end_time_in_the_past (0.03s)
 === RUN   TestTooManyTimestamps
---- PASS: TestTooManyTimestamps (0.00s)
+--- PASS: TestTooManyTimestamps (0.04s)
 === RUN   FuzzVerifyTimestampAuthorityWithoutThreshold
 --- PASS: FuzzVerifyTimestampAuthorityWithoutThreshold (0.00s)
 === RUN   FuzzVerifyTimestampAuthorityWithThreshold
@@ -3751,7 +3787,7 @@
 === RUN   FuzzVerifySignatureWithArtifactDigest
 --- PASS: FuzzVerifySignatureWithArtifactDigest (0.00s)
 PASS
-ok  	github.com/sigstore/sigstore-go/pkg/verify	0.262s
+ok  	github.com/sigstore/sigstore-go/pkg/verify	2.448s
    create-stamp debian/debhelper-build-stamp
    dh_testroot -O--builddirectory=_build -O--buildsystem=golang
    dh_prep -O--builddirectory=_build -O--buildsystem=golang
@@ -3805,8 +3841,8 @@
 dpkg-gencontrol: warning: package sigstore-go: substitution variable ${misc:Static-Built-Using} unused, but is defined
    dh_md5sums -O--builddirectory=_build -O--buildsystem=golang
    dh_builddeb -O--builddirectory=_build -O--buildsystem=golang
-dpkg-deb: building package 'sigstore-go' in '../sigstore-go_0.7.0-2_amd64.deb'.
 dpkg-deb: building package 'sigstore-go-dbgsym' in '../sigstore-go-dbgsym_0.7.0-2_amd64.deb'.
+dpkg-deb: building package 'sigstore-go' in '../sigstore-go_0.7.0-2_amd64.deb'.
 dpkg-deb: building package 'golang-github-sigstore-sigstore-go-dev' in '../golang-github-sigstore-sigstore-go-dev_0.7.0-2_all.deb'.
  dpkg-genbuildinfo --build=binary -O../sigstore-go_0.7.0-2_amd64.buildinfo
  dpkg-genchanges --build=binary -O../sigstore-go_0.7.0-2_amd64.changes
@@ -3815,12 +3851,14 @@
 dpkg-buildpackage: info: binary-only upload (no source included)
 dpkg-genchanges: info: not including original source code in upload
 I: copying local configuration
+I: user script /srv/workspace/pbuilder/2312480/tmp/hooks/B01_cleanup starting
+I: user script /srv/workspace/pbuilder/2312480/tmp/hooks/B01_cleanup finished
 I: unmounting dev/ptmx filesystem
 I: unmounting dev/pts filesystem
 I: unmounting dev/shm filesystem
 I: unmounting proc filesystem
 I: unmounting sys filesystem
 I: cleaning the build env 
-I: removing directory /srv/workspace/pbuilder/2710469 and its subdirectories
-I: Current time: Sun Apr 19 00:17:06 -12 2026
-I: pbuilder-time-stamp: 1776601026
+I: removing directory /srv/workspace/pbuilder/2312480 and its subdirectories
+I: Current time: Mon Mar 17 20:09:48 +14 2025
+I: pbuilder-time-stamp: 1742191788