Diff of the two buildlogs:

--
--- b1/build.log	2025-01-17 19:39:38.939815889 +0000
+++ b2/build.log	2025-01-17 19:41:34.502552294 +0000
@@ -1,6 +1,6 @@
 I: pbuilder: network access will be disabled during build
-I: Current time: Fri Jan 17 07:29:42 -12 2025
-I: pbuilder-time-stamp: 1737142182
+I: Current time: Fri Feb 20 16:02:40 +14 2026
+I: pbuilder-time-stamp: 1771552960
 I: Building the build Environment
 I: extracting base tarball [/var/cache/pbuilder/unstable-reproducible-base.tgz]
 I: copying local configuration
@@ -25,54 +25,86 @@
 dpkg-source: info: applying disable-rpmtuf.patch
 I: Not using root during the build.
 I: Installing the build-deps
-I: user script /srv/workspace/pbuilder/31500/tmp/hooks/D02_print_environment starting
+I: user script /srv/workspace/pbuilder/5639/tmp/hooks/D01_modify_environment starting
+debug: Running on ionos16-i386.
+I: Changing host+domainname to test build reproducibility
+I: Adding a custom variable just for the fun of it...
+I: Changing /bin/sh to bash
+'/bin/sh' -> '/bin/bash'
+lrwxrwxrwx 1 root root 9 Feb 20 02:02 /bin/sh -> /bin/bash
+I: Setting pbuilder2's login shell to /bin/bash
+I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other
+I: user script /srv/workspace/pbuilder/5639/tmp/hooks/D01_modify_environment finished
+I: user script /srv/workspace/pbuilder/5639/tmp/hooks/D02_print_environment starting
 I: set
-  BUILDDIR='/build/reproducible-path'
-  BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other'
-  BUILDUSERNAME='pbuilder1'
-  BUILD_ARCH='i386'
-  DEBIAN_FRONTEND='noninteractive'
-  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=11 '
-  DISTRIBUTION='unstable'
-  HOME='/root'
-  HOST_ARCH='i386'
+  BASH=/bin/sh
+  BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath
+  BASH_ALIASES=()
+  BASH_ARGC=()
+  BASH_ARGV=()
+  BASH_CMDS=()
+  BASH_LINENO=([0]="12" [1]="0")
+  BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:.
+  BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment")
+  BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="i686-pc-linux-gnu")
+  BASH_VERSION='5.2.37(1)-release'
+  BUILDDIR=/build/reproducible-path
+  BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other'
+  BUILDUSERNAME=pbuilder2
+  BUILD_ARCH=i386
+  DEBIAN_FRONTEND=noninteractive
+  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=21 '
+  DIRSTACK=()
+  DISTRIBUTION=unstable
+  EUID=0
+  FUNCNAME=([0]="Echo" [1]="main")
+  GROUPS=()
+  HOME=/root
+  HOSTNAME=i-capture-the-hostname
+  HOSTTYPE=i686
+  HOST_ARCH=i386
   IFS=' 	
   '
-  INVOCATION_ID='23c147ba5cb8456d85bbe093e00f9271'
-  LANG='C'
-  LANGUAGE='en_US:en'
-  LC_ALL='C'
-  LD_LIBRARY_PATH='/usr/lib/libeatmydata'
-  LD_PRELOAD='libeatmydata.so'
-  MAIL='/var/mail/root'
-  OPTIND='1'
-  PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games'
-  PBCURRENTCOMMANDLINEOPERATION='build'
-  PBUILDER_OPERATION='build'
-  PBUILDER_PKGDATADIR='/usr/share/pbuilder'
-  PBUILDER_PKGLIBDIR='/usr/lib/pbuilder'
-  PBUILDER_SYSCONFDIR='/etc'
-  PPID='31500'
-  PS1='# '
-  PS2='> '
+  INVOCATION_ID=7a39e8b3f23c4737ab614ee7053bdb28
+  LANG=C
+  LANGUAGE=de_CH:de
+  LC_ALL=C
+  LD_LIBRARY_PATH=/usr/lib/libeatmydata
+  LD_PRELOAD=libeatmydata.so
+  MACHTYPE=i686-pc-linux-gnu
+  MAIL=/var/mail/root
+  OPTERR=1
+  OPTIND=1
+  OSTYPE=linux-gnu
+  PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path
+  PBCURRENTCOMMANDLINEOPERATION=build
+  PBUILDER_OPERATION=build
+  PBUILDER_PKGDATADIR=/usr/share/pbuilder
+  PBUILDER_PKGLIBDIR=/usr/lib/pbuilder
+  PBUILDER_SYSCONFDIR=/etc
+  PIPESTATUS=([0]="0")
+  POSIXLY_CORRECT=y
+  PPID=5639
   PS4='+ '
-  PWD='/'
-  SHELL='/bin/bash'
-  SHLVL='2'
-  SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.BhBOri68/pbuilderrc_Wz0I --distribution unstable --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.BhBOri68/b1 --logfile b1/build.log rekor_1.3.7-1.dsc'
-  SUDO_GID='112'
-  SUDO_UID='107'
-  SUDO_USER='jenkins'
-  TERM='unknown'
-  TZ='/usr/share/zoneinfo/Etc/GMT+12'
-  USER='root'
-  _='/usr/bin/systemd-run'
-  http_proxy='http://46.16.76.132:3128'
+  PWD=/
+  SHELL=/bin/bash
+  SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix
+  SHLVL=3
+  SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.BhBOri68/pbuilderrc_BO4d --distribution unstable --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.BhBOri68/b2 --logfile b2/build.log rekor_1.3.7-1.dsc'
+  SUDO_GID=112
+  SUDO_UID=107
+  SUDO_USER=jenkins
+  TERM=unknown
+  TZ=/usr/share/zoneinfo/Etc/GMT-14
+  UID=0
+  USER=root
+  _='I: set'
+  http_proxy=http://213.165.73.152:3128
 I: uname -a
-  Linux ionos12-i386 6.1.0-30-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.124-1 (2025-01-12) x86_64 GNU/Linux
+  Linux i-capture-the-hostname 6.1.0-30-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.124-1 (2025-01-12) x86_64 GNU/Linux
 I: ls -l /bin
-  lrwxrwxrwx 1 root root 7 Nov 22 14:40 /bin -> usr/bin
-I: user script /srv/workspace/pbuilder/31500/tmp/hooks/D02_print_environment finished
+  lrwxrwxrwx 1 root root 7 Nov 22  2024 /bin -> usr/bin
+I: user script /srv/workspace/pbuilder/5639/tmp/hooks/D02_print_environment finished
  -> Attempting to satisfy build-dependencies
  -> Creating pbuilder-satisfydepends-dummy package
 Package: pbuilder-satisfydepends-dummy
@@ -654,7 +686,7 @@
 Get: 486 http://deb.debian.org/debian unstable/main i386 golang-k8s-sigs-release-utils-dev all 0.8.5-1 [37.2 kB]
 Get: 487 http://deb.debian.org/debian unstable/main i386 golang-webpki-org-jsoncanonicalizer-dev all 1.0.1-2 [6908 B]
 Get: 488 http://deb.debian.org/debian unstable/main i386 help2man i386 1.49.3 [198 kB]
-Fetched 229 MB in 7s (31.8 MB/s)
+Fetched 229 MB in 5s (49.7 MB/s)
 Preconfiguring packages ...
 Selecting previously unselected package golang-golang-x-sys-dev.
 (Reading database ... 
(Reading database ... 5%
(Reading database ... 10%
(Reading database ... 15%
(Reading database ... 20%
(Reading database ... 25%
(Reading database ... 30%
(Reading database ... 35%
(Reading database ... 40%
(Reading database ... 45%
(Reading database ... 50%
(Reading database ... 55%
(Reading database ... 60%
(Reading database ... 65%
(Reading database ... 70%
(Reading database ... 75%
(Reading database ... 80%
(Reading database ... 85%
(Reading database ... 90%
(Reading database ... 95%
(Reading database ... 100%
(Reading database ... 19837 files and directories currently installed.)
@@ -2217,8 +2249,8 @@
 Setting up tzdata (2024b-6) ...
 
 Current default time zone: 'Etc/UTC'
-Local time is now:      Fri Jan 17 19:34:33 UTC 2025.
-Universal Time is now:  Fri Jan 17 19:34:33 UTC 2025.
+Local time is now:      Fri Feb 20 02:03:38 UTC 2026.
+Universal Time is now:  Fri Feb 20 02:03:38 UTC 2026.
 Run 'dpkg-reconfigure tzdata' if you wish to change it.
 
 Setting up golang-github-coreos-go-semver-dev (0.3.0-1) ...
@@ -2627,7 +2659,11 @@
 Building tag database...
  -> Finished parsing the build-deps
 I: Building the package
-I: Running cd /build/reproducible-path/rekor-1.3.7/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S  > ../rekor_1.3.7-1_source.changes
+I: user script /srv/workspace/pbuilder/5639/tmp/hooks/A99_set_merged_usr starting
+Not re-configuring usrmerge for unstable
+I: user script /srv/workspace/pbuilder/5639/tmp/hooks/A99_set_merged_usr finished
+hostname: Name or service not known
+I: Running cd /build/reproducible-path/rekor-1.3.7/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S  > ../rekor_1.3.7-1_source.changes
 dpkg-buildpackage: info: source package rekor
 dpkg-buildpackage: info: source version 1.3.7-1
 dpkg-buildpackage: info: source distribution unstable
@@ -2647,522 +2683,522 @@
    debian/rules override_dh_auto_build
 make[1]: Entering directory '/build/reproducible-path/rekor-1.3.7'
 rm -rfv _build/src/github.com/sigstore/rekor/pkg/types/rpm
-removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/e2e_test.go'
-removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/v0.0.1/entry_test.go'
-removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/v0.0.1/entry.go'
 removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/v0.0.1/fuzz_test.go'
+removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/v0.0.1/entry.go'
+removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/v0.0.1/entry_test.go'
 removed directory '_build/src/github.com/sigstore/rekor/pkg/types/rpm/v0.0.1'
+removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/e2e_test.go'
+removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/e2e.go'
 removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/rpm.go'
 removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/rpm_test.go'
-removed '_build/src/github.com/sigstore/rekor/pkg/types/rpm/e2e.go'
 removed directory '_build/src/github.com/sigstore/rekor/pkg/types/rpm'
 rm -rfv _build/src/github.com/sigstore/rekor/pkg/types/tuf
 removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/tuf_test.go'
-removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/v0.0.1/entry_test.go'
-removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/v0.0.1/entry.go'
 removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/v0.0.1/fuzz_test.go'
+removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/v0.0.1/entry.go'
+removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/v0.0.1/entry_test.go'
 removed directory '_build/src/github.com/sigstore/rekor/pkg/types/tuf/v0.0.1'
 removed '_build/src/github.com/sigstore/rekor/pkg/types/tuf/tuf.go'
 removed directory '_build/src/github.com/sigstore/rekor/pkg/types/tuf'
 rm -rfv _build/src/github.com/sigstore/rekor/pkg/pki/tuf
 removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/tuf_test.go'
 removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/e2e_test.go'
+removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/tuf_e2e_test.go'
+removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/tuf.go'
+removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/other_root.json'
 removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/bogus.json'
 removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/timestamp.json'
 removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/unsigned_root.json'
-removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/other_root.json'
 removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/reformat.1.root.json'
 removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata/1.root.json'
 removed directory '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/testdata'
-removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/tuf.go'
-removed '_build/src/github.com/sigstore/rekor/pkg/pki/tuf/tuf_e2e_test.go'
 removed directory '_build/src/github.com/sigstore/rekor/pkg/pki/tuf'
 dh_auto_build 
-	cd _build && go install -trimpath -v -p 11 github.com/sigstore/rekor/cmd/rekor-cli
-internal/profilerecord
+	cd _build && go install -trimpath -v -p 21 github.com/sigstore/rekor/cmd/rekor-cli
 internal/goarch
-internal/coverage/rtcov
-internal/goos
-internal/godebugs
-internal/byteorder
 internal/unsafeheader
-internal/goexperiment
-internal/runtime/atomic
-internal/runtime/syscall
-internal/cpu
-runtime/internal/math
-runtime/internal/sys
-internal/race
-internal/abi
-sync/atomic
-unicode
-unicode/utf8
-internal/chacha8rand
 internal/itoa
-internal/asan
+internal/profilerecord
+internal/godebugs
 internal/msan
+internal/asan
+internal/coverage/rtcov
 math/bits
 crypto/internal/alias
-crypto/internal/boring/sig
+internal/byteorder
+internal/goos
+internal/race
+unicode/utf8
+internal/goexperiment
+unicode
 cmp
 unicode/utf16
+runtime/internal/math
 vendor/golang.org/x/crypto/cryptobyte/asn1
 internal/nettrace
-internal/runtime/exithook
+runtime/internal/sys
 encoding
 container/list
 vendor/golang.org/x/crypto/internal/alias
-internal/bytealg
 log/internal
 go.mongodb.org/mongo-driver/bson/bsonoptions
-math
 go.mongodb.org/mongo-driver/bson/bsontype
+crypto/internal/boring/sig
 google.golang.org/protobuf/internal/flags
-google.golang.org/protobuf/internal/set
 github.com/sigstore/rekor/pkg/pki/identity
+internal/runtime/atomic
+sync/atomic
+internal/runtime/syscall
+internal/abi
+internal/chacha8rand
 golang.org/x/crypto/internal/alias
-golang.org/x/crypto/salsa20/salsa
-image/color
+internal/cpu
 golang.org/x/exp/constraints
-github.com/pelletier/go-toml/v2/internal/characters
+image/color
 log/slog/internal
-go.opentelemetry.io/otel/trace/embedded
 go.opentelemetry.io/otel/metric/embedded
-golang.org/x/exp/slices
+github.com/pelletier/go-toml/v2/internal/characters
+go.opentelemetry.io/otel/trace/embedded
 google.golang.org/grpc/serviceconfig
+math
+google.golang.org/protobuf/internal/set
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/common
 github.com/transparency-dev/merkle
+golang.org/x/crypto/salsa20/salsa
+golang.org/x/exp/slices
+internal/runtime/exithook
+internal/bytealg
 internal/stringslite
-runtime
 go.opentelemetry.io/otel/internal
+runtime
+iter
 crypto/subtle
 internal/reflectlite
-sync
-iter
 internal/weak
-slices
+sync
 maps
-internal/bisect
-internal/singleflight
+slices
 internal/testlog
 github.com/josharian/intern
-google.golang.org/protobuf/internal/pragma
+internal/bisect
 go.uber.org/zap/internal/pool
-github.com/spf13/viper/internal/encoding
+google.golang.org/protobuf/internal/pragma
+internal/singleflight
 log/slog/internal/buffer
+github.com/spf13/viper/internal/encoding
 runtime/cgo
 errors
-internal/godebug
+sort
 internal/oserror
+internal/godebug
+path
+google.golang.org/grpc/internal/buffer
 io
-sort
-math/rand
 vendor/golang.org/x/net/dns/dnsmessage
-math/rand/v2
-syscall
 crypto/internal/edwards25519/field
-crypto/internal/nistec/fiat
-path
+golang.org/x/crypto/cast5
+github.com/sassoftware/relic/signers/sigerrors
+github.com/hashicorp/hcl/hcl/strconv
+math/rand/v2
 strconv
-bytes
+crypto/internal/nistec/fiat
+math/rand
+crypto/internal/edwards25519
+syscall
 hash
 crypto/internal/randutil
-strings
-crypto/internal/edwards25519
 internal/concurrent
+bytes
+internal/saferio
+strings
+hash/fnv
 hash/crc32
+hash/adler32
 unique
-hash/fnv
-internal/saferio
+google.golang.org/grpc/internal/grpcrand
+crypto/rc4
+golang.org/x/crypto/openpgp/errors
+crypto
+golang.org/x/crypto/blowfish
+encoding/base32
+github.com/x448/float16
+reflect
+net/netip
+golang.org/x/crypto/openpgp/s2k
+crypto/md5
 crypto/cipher
 vendor/golang.org/x/text/transform
-hash/adler32
-golang.org/x/crypto/cast5
-github.com/sassoftware/relic/signers/sigerrors
 golang.org/x/text/transform
-github.com/hashicorp/hcl/hcl/strconv
-html
-bufio
 net/http/internal/ascii
-golang.org/x/text/runes
-google.golang.org/grpc/internal/grpcrand
-google.golang.org/grpc/internal/buffer
-crypto
-crypto/des
-net/netip
-reflect
+bufio
 regexp/syntax
-crypto/rc4
+html
+golang.org/x/text/runes
 crypto/internal/boring
-crypto/md5
-golang.org/x/crypto/openpgp/errors
-compress/bzip2
-image
-crypto/sha256
-crypto/aes
+crypto/des
 crypto/sha512
 crypto/sha1
+crypto/sha256
+crypto/aes
 crypto/hmac
-golang.org/x/crypto/openpgp/s2k
-golang.org/x/crypto/blowfish
+compress/bzip2
+image
 vendor/golang.org/x/crypto/hkdf
 golang.org/x/crypto/pbkdf2
-encoding/base32
-github.com/x448/float16
 golang.org/x/crypto/ssh/internal/bcrypt_pbkdf
 github.com/transparency-dev/merkle/rfc6962
-image/internal/imageutil
-internal/syscall/unix
 internal/syscall/execenv
+internal/syscall/unix
 time
-image/jpeg
+image/internal/imageutil
 regexp
+image/jpeg
 crypto/internal/nistec
-io/fs
-context
-google.golang.org/grpc/backoff
 go.uber.org/zap/buffer
+context
 google.golang.org/grpc/keepalive
+io/fs
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.1
-internal/poll
+google.golang.org/grpc/backoff
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v0.2
 github.com/in-toto/in-toto-golang/in_toto/slsa_provenance/v1
+internal/poll
+crypto/ecdh
 go.uber.org/zap/internal/bufferpool
+internal/fmtsort
+go.opentelemetry.io/otel/internal/attribute
+encoding/binary
 go.uber.org/zap/internal/stacktrace
 go.opentelemetry.io/otel/internal/baggage
 google.golang.org/grpc/internal/backoff
 google.golang.org/grpc/internal/grpcsync
+github.com/spf13/afero/internal/common
 internal/filepathlite
 embed
-github.com/spf13/afero/internal/common
-os
-google.golang.org/protobuf/internal/editiondefaults
-internal/fmtsort
-go.opentelemetry.io/otel/internal/attribute
-encoding/binary
-crypto/ecdh
 golang.org/x/crypto/curve25519
+google.golang.org/protobuf/internal/editiondefaults
+os
+encoding/base64
 vendor/golang.org/x/crypto/chacha20
 vendor/golang.org/x/crypto/internal/poly1305
-encoding/base64
-golang.org/x/crypto/internal/poly1305
 golang.org/x/crypto/scrypt
-golang.org/x/crypto/chacha20
 software.sslmate.com/src/go-pkcs12/internal/rc2
+golang.org/x/crypto/internal/poly1305
+golang.org/x/crypto/chacha20
 golang.org/x/crypto/blake2b
 golang.org/x/sys/unix
 golang.org/x/crypto/nacl/secretbox
 encoding/pem
 golang.org/x/crypto/openpgp/armor
 vendor/golang.org/x/crypto/chacha20poly1305
-path/filepath
 io/ioutil
 google.golang.org/protobuf/internal/detrand
 go.uber.org/zap/internal/exit
-golang.org/x/sys/cpu
-fmt
-vendor/golang.org/x/sys/cpu
 internal/sysinfo
+path/filepath
 google.golang.org/grpc/internal/envconfig
+fmt
+golang.org/x/sys/cpu
+vendor/golang.org/x/sys/cpu
 net
-golang.org/x/crypto/sha3
 vendor/golang.org/x/crypto/sha3
+golang.org/x/crypto/sha3
 github.com/spf13/afero/mem
 github.com/shibumi/go-pathspec
 github.com/sassoftware/relic/lib/atomicfile
 os/exec
 github.com/mitchellh/go-homedir
 encoding/hex
-encoding/csv
-encoding/json
 net/url
 log
-compress/flate
-math/big
-encoding/xml
-vendor/golang.org/x/text/unicode/norm
-vendor/golang.org/x/net/http2/hpack
-mime
-vendor/golang.org/x/text/unicode/bidi
 mime/quotedprintable
 net/http/internal
 database/sql/driver
-gopkg.in/yaml.v3
-compress/gzip
-golang.org/x/sync/errgroup
+encoding/xml
 google.golang.org/protobuf/internal/errors
-go/token
-google.golang.org/protobuf/encoding/protowire
-github.com/oklog/ulid
-google.golang.org/protobuf/reflect/protoreflect
-vendor/golang.org/x/text/secure/bidirule
+compress/flate
+encoding/csv
 google.golang.org/protobuf/internal/version
-internal/profile
+golang.org/x/sync/errgroup
+encoding/json
+mime
+vendor/golang.org/x/net/http2/hpack
+go/token
+math/big
+vendor/golang.org/x/text/unicode/norm
+gopkg.in/yaml.v3
 text/tabwriter
-github.com/mailru/easyjson/jlexer
+google.golang.org/protobuf/encoding/protowire
 runtime/trace
 runtime/debug
 flag
-go.uber.org/atomic
-runtime/pprof
-vendor/golang.org/x/net/idna
 go.uber.org/zap/internal/color
-github.com/go-openapi/analysis/internal/debug
+github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer
+google.golang.org/protobuf/reflect/protoreflect
 encoding/gob
-go.uber.org/multierr
+github.com/opencontainers/go-digest
+text/template/parse
+golang.org/x/text/unicode/norm
+vendor/golang.org/x/text/unicode/bidi
+github.com/oklog/ulid
+github.com/go-openapi/analysis/internal/debug
 github.com/go-openapi/jsonreference/internal
-github.com/blang/semver
-go.uber.org/zap/zapcore
-github.com/cyberphone/json-canonicalization/go/src/webpki.org/jsoncanonicalizer
+github.com/spf13/jwalterweatherman
+github.com/subosito/gotenv
+github.com/hashicorp/hcl/hcl/token
+github.com/pelletier/go-toml/v2/internal/danger
+gopkg.in/ini.v1
+github.com/go-openapi/runtime/logger
+compress/gzip
+compress/zlib
+github.com/opentracing/opentracing-go/log
+github.com/hashicorp/hcl/hcl/ast
+github.com/hashicorp/hcl/hcl/scanner
+github.com/hashicorp/hcl/json/token
+github.com/pelletier/go-toml/v2/unstable
+go.opentelemetry.io/otel/baggage
+github.com/hashicorp/hcl/json/scanner
+golang.org/x/net/internal/timeseries
+internal/profile
+runtime/pprof
+google.golang.org/grpc/internal/grpclog
+github.com/hashicorp/hcl/hcl/parser
+github.com/hashicorp/hcl/json/parser
+google.golang.org/grpc/attributes
+google.golang.org/grpc/internal/idle
 google.golang.org/protobuf/internal/descfmt
 google.golang.org/protobuf/internal/descopts
 google.golang.org/protobuf/internal/strs
 google.golang.org/protobuf/internal/encoding/messageset
 google.golang.org/protobuf/internal/genid
 google.golang.org/protobuf/internal/order
-google.golang.org/protobuf/internal/encoding/text
-google.golang.org/protobuf/reflect/protoregistry
+vendor/golang.org/x/text/secure/bidirule
 google.golang.org/protobuf/runtime/protoiface
+github.com/fsnotify/fsnotify/internal
 golang.org/x/term
-github.com/opencontainers/go-digest
-compress/zlib
+github.com/hashicorp/hcl
+github.com/hashicorp/hcl/hcl/printer
+text/template
+github.com/pelletier/go-toml/v2/internal/tracker
+golang.org/x/text/unicode/bidi
+golang.org/x/net/http2/hpack
+github.com/google/trillian/types/internal/tls
+google.golang.org/protobuf/reflect/protoregistry
+vendor/golang.org/x/net/idna
+google.golang.org/protobuf/internal/encoding/text
+github.com/mailru/easyjson/jlexer
+go.uber.org/atomic
+github.com/blang/semver
+google.golang.org/protobuf/internal/encoding/json
+github.com/fsnotify/fsnotify
+github.com/spf13/viper/internal/encoding/json
+github.com/pelletier/go-toml/v2
+log/slog
+go.opentelemetry.io/otel/attribute
+go.opentelemetry.io/otel/codes
+github.com/spf13/viper/internal/encoding/hcl
+google.golang.org/grpc/grpclog
+google.golang.org/protobuf/proto
+sigs.k8s.io/yaml/goyaml.v2
+os/user
+github.com/secure-systems-lab/go-securesystemslib/cjson
 crypto/dsa
 crypto/elliptic
-crypto/internal/bigmod
 crypto/internal/boring/bbig
+crypto/internal/bigmod
 encoding/asn1
 crypto/rand
 google.golang.org/protobuf/internal/encoding/defval
-google.golang.org/protobuf/proto
-text/template/parse
+go.uber.org/multierr
+testing
+github.com/fxamacker/cbor
+golang.org/x/text/secure/bidirule
+go.uber.org/zap/zapcore
 crypto/ed25519
 crypto/internal/hpke
 crypto/internal/mlkem768
-crypto/rsa
 go.mongodb.org/mongo-driver/bson/primitive
-golang.org/x/crypto/ed25519
-github.com/jedisct1/go-minisign
 github.com/secure-systems-lab/go-securesystemslib/encrypted
 golang.org/x/crypto/openpgp/elgamal
-google.golang.org/protobuf/internal/encoding/json
-github.com/fsnotify/fsnotify/internal
-golang.org/x/text/unicode/norm
-go.mongodb.org/mongo-driver/x/bsonx/bsoncore
-github.com/sigstore/sigstore/pkg/signature/options
-crypto/x509/pkix
-vendor/golang.org/x/crypto/cryptobyte
-go.uber.org/zap/internal
-github.com/fsnotify/fsnotify
-github.com/spf13/jwalterweatherman
-google.golang.org/protobuf/internal/filedesc
-google.golang.org/protobuf/encoding/prototext
-github.com/subosito/gotenv
-github.com/hashicorp/hcl/hcl/token
-gopkg.in/ini.v1
-text/template
-github.com/spf13/viper/internal/encoding/json
-github.com/pelletier/go-toml/v2/internal/danger
-crypto/ecdsa
 github.com/spf13/viper/internal/encoding/yaml
-github.com/hashicorp/hcl/hcl/ast
-github.com/hashicorp/hcl/json/token
-github.com/hashicorp/hcl/hcl/scanner
-github.com/pelletier/go-toml/v2/unstable
-github.com/hashicorp/hcl/json/scanner
-github.com/hashicorp/hcl/hcl/parser
-github.com/hashicorp/hcl/json/parser
-golang.org/x/mod/sumdb/note
-golang.org/x/crypto/openpgp/packet
-github.com/hashicorp/hcl/hcl/printer
-github.com/pelletier/go-toml/v2/internal/tracker
-github.com/hashicorp/hcl
-github.com/go-openapi/runtime/logger
-github.com/pelletier/go-toml/v2
-github.com/opentracing/opentracing-go/log
-log/slog
-go.opentelemetry.io/otel/attribute
-github.com/spf13/viper/internal/encoding/hcl
-go.opentelemetry.io/otel/codes
-go.mongodb.org/mongo-driver/bson/bsonrw
-go.opentelemetry.io/otel/baggage
-golang.org/x/net/internal/timeseries
-google.golang.org/grpc/internal/grpclog
-google.golang.org/grpc/attributes
-google.golang.org/grpc/internal/idle
-google.golang.org/grpc/grpclog
 go.opentelemetry.io/otel/metric
+crypto/rsa
 go.opentelemetry.io/otel/trace
 go.opentelemetry.io/otel/semconv/v1.17.0
-html/template
 google.golang.org/grpc/connectivity
-golang.org/x/text/unicode/bidi
-google.golang.org/protobuf/internal/encoding/tag
-google.golang.org/protobuf/encoding/protojson
-golang.org/x/crypto/openpgp
-golang.org/x/net/http2/hpack
-google.golang.org/protobuf/internal/impl
+golang.org/x/crypto/ed25519
+golang.org/x/mod/sumdb/note
+golang.org/x/net/idna
+archive/zip
+golang.org/x/crypto/ssh/terminal
+github.com/jedisct1/go-minisign
+google.golang.org/protobuf/internal/filedesc
+google.golang.org/protobuf/encoding/prototext
+go.mongodb.org/mongo-driver/x/bsonx/bsoncore
+html/template
+github.com/howeyc/gopass
+github.com/sigstore/sigstore/pkg/signature/options
+vendor/golang.org/x/crypto/cryptobyte
+crypto/x509/pkix
 github.com/go-logr/logr
-github.com/google/trillian/types/internal/tls
+github.com/sassoftware/relic/lib/binpatch
 github.com/spf13/viper/internal/encoding/toml
-sigs.k8s.io/yaml/goyaml.v2
-golang.org/x/text/secure/bidirule
-os/user
-github.com/secure-systems-lab/go-securesystemslib/cjson
+github.com/transparency-dev/merkle/compact
+github.com/common-nighthawk/go-figure
 github.com/go-logr/logr/funcr
-golang.org/x/net/idna
-testing
-github.com/fxamacker/cbor
-github.com/spf13/cast
+github.com/transparency-dev/merkle/proof
+crypto/ecdsa
 github.com/go-logr/stdr
-archive/zip
-go.mongodb.org/mongo-driver/bson/bsoncodec
-golang.org/x/crypto/ssh/terminal
+go.uber.org/zap/internal
+golang.org/x/crypto/openpgp/packet
+github.com/spf13/cast
+sigs.k8s.io/yaml
+go.mongodb.org/mongo-driver/bson/bsonrw
+google.golang.org/protobuf/internal/encoding/tag
+google.golang.org/protobuf/encoding/protojson
 github.com/spf13/viper/internal/encoding/dotenv
 github.com/spf13/viper/internal/encoding/ini
-net/textproto
-crypto/x509
+github.com/veraison/go-cose
+google.golang.org/protobuf/internal/impl
+archive/tar
+golang.org/x/crypto/openpgp
+github.com/sassoftware/relic/lib/zipslicer
+go.mongodb.org/mongo-driver/bson/bsoncodec
 vendor/golang.org/x/net/http/httpproxy
+net/textproto
+github.com/mailru/easyjson/buffer
 github.com/google/uuid
 github.com/mitchellh/mapstructure
+google.golang.org/grpc/internal/syscall
+crypto/x509
+github.com/google/go-containerregistry/pkg/name
+google.golang.org/grpc/internal/resolver/dns/internal
+google.golang.org/grpc/internal
+github.com/spf13/pflag
+github.com/godbus/dbus
+github.com/mailru/easyjson/jwriter
+google.golang.org/grpc/metadata
+google.golang.org/grpc/codes
+github.com/sigstore/sigstore/pkg/signature/payload
 vendor/golang.org/x/net/http/httpguts
 mime/multipart
 net/mail
-github.com/mailru/easyjson/buffer
-github.com/mailru/easyjson/jwriter
-github.com/google/go-containerregistry/pkg/name
-github.com/spf13/pflag
-google.golang.org/grpc/internal
 golang.org/x/net/http/httpguts
-google.golang.org/grpc/internal/syscall
-google.golang.org/grpc/internal/resolver/dns/internal
-sigs.k8s.io/yaml
 golang.org/x/crypto/openpgp/clearsign
-google.golang.org/grpc/metadata
-google.golang.org/grpc/codes
-github.com/howeyc/gopass
 google.golang.org/grpc/internal/grpcutil
-github.com/sigstore/sigstore/pkg/signature/payload
 google.golang.org/grpc/internal/balancerload
 google.golang.org/grpc/stats
 google.golang.org/grpc/tap
 google.golang.org/grpc/encoding
-github.com/sassoftware/relic/lib/binpatch
-github.com/transparency-dev/merkle/compact
-github.com/common-nighthawk/go-figure
-github.com/transparency-dev/merkle/proof
-github.com/godbus/dbus
-archive/tar
-github.com/veraison/go-cose
-github.com/sigstore/sigstore/pkg/cryptoutils
-github.com/asaskevich/govalidator
-golang.org/x/crypto/ssh
-crypto/tls
-github.com/sigstore/sigstore/pkg/signature
 go.mongodb.org/mongo-driver/bson
-github.com/secure-systems-lab/go-securesystemslib/signerverifier
-software.sslmate.com/src/go-pkcs12
-github.com/sassoftware/relic/lib/zipslicer
-github.com/sigstore/rekor/pkg/pki/minisign
-github.com/spf13/cobra
-github.com/sigstore/rekor/pkg/pki/x509
 google.golang.org/protobuf/internal/filetype
-sigs.k8s.io/release-utils/version
+github.com/spf13/cobra
 google.golang.org/protobuf/runtime/protoimpl
-google.golang.org/protobuf/types/descriptorpb
+github.com/secure-systems-lab/go-securesystemslib/signerverifier
+github.com/sigstore/sigstore/pkg/cryptoutils
+software.sslmate.com/src/go-pkcs12
+github.com/asaskevich/govalidator
+crypto/tls
+golang.org/x/crypto/ssh
+google.golang.org/protobuf/protoadapt
 google.golang.org/protobuf/types/known/timestamppb
 google.golang.org/protobuf/types/known/anypb
-google.golang.org/protobuf/protoadapt
 google.golang.org/protobuf/types/known/durationpb
 google.golang.org/protobuf/types/known/fieldmaskpb
+google.golang.org/protobuf/types/descriptorpb
 google.golang.org/grpc/encoding/proto
 google.golang.org/grpc/internal/pretty
+github.com/sigstore/sigstore/pkg/signature
+github.com/golang/protobuf/ptypes/duration
 google.golang.org/genproto/googleapis/rpc/status
 github.com/golang/protobuf/ptypes/timestamp
-github.com/golang/protobuf/ptypes/duration
-github.com/zalando/go-keyring/secret_service
 google.golang.org/grpc/internal/status
 google.golang.org/grpc/binarylog/grpc_binarylog_v1
+github.com/zalando/go-keyring/secret_service
 google.golang.org/grpc/status
-github.com/secure-systems-lab/go-securesystemslib/dsse
+github.com/sigstore/rekor/pkg/pki/minisign
 github.com/zalando/go-keyring
-github.com/sigstore/sigstore/pkg/signature/dsse
-github.com/in-toto/in-toto-golang/in_toto
-github.com/sassoftware/relic/lib/passprompt
 google.golang.org/grpc/internal/binarylog
+sigs.k8s.io/release-utils/version
+github.com/sigstore/rekor/pkg/pki/x509
+github.com/sassoftware/relic/lib/passprompt
 google.golang.org/genproto/googleapis/api/annotations
-github.com/sassoftware/relic/lib/x509tools
-google.golang.org/grpc/internal/credentials
+github.com/sigstore/protobuf-specs/gen/pb-go/common/v1
+github.com/sigstore/protobuf-specs/gen/pb-go/rekor/v1
+github.com/secure-systems-lab/go-securesystemslib/dsse
+github.com/sigstore/sigstore/pkg/signature/dsse
+github.com/in-toto/in-toto-golang/in_toto
 net/http/httptrace
+google.golang.org/grpc/internal/credentials
+github.com/sassoftware/relic/lib/x509tools
 google.golang.org/grpc/credentials
 net/http
-github.com/sigstore/protobuf-specs/gen/pb-go/common/v1
 google.golang.org/grpc/credentials/insecure
 google.golang.org/grpc/peer
 google.golang.org/grpc/resolver
 google.golang.org/grpc/internal/channelz
 google.golang.org/grpc/internal/metadata
 google.golang.org/grpc/internal/resolver/passthrough
-google.golang.org/grpc/balancer/grpclb/state
 google.golang.org/grpc/internal/transport/networktype
-github.com/sassoftware/relic/lib/pkcs7
+google.golang.org/grpc/balancer/grpclb/state
 google.golang.org/grpc/internal/resolver/dns
 google.golang.org/grpc/internal/resolver/unix
-github.com/sigstore/protobuf-specs/gen/pb-go/rekor/v1
+github.com/sassoftware/relic/lib/pkcs7
 google.golang.org/grpc/resolver/dns
-google.golang.org/grpc/channelz
 github.com/sigstore/rekor/pkg/pki/pkcs7
+google.golang.org/grpc/channelz
 google.golang.org/grpc/balancer
-google.golang.org/grpc/internal/serviceconfig
 google.golang.org/grpc/balancer/base
+google.golang.org/grpc/internal/serviceconfig
 google.golang.org/grpc/internal/resolver
 google.golang.org/grpc/balancer/roundrobin
 google.golang.org/grpc/internal/balancer/gracefulswitch
-github.com/go-openapi/errors
-github.com/sigstore/rekor/pkg/pki/ssh
-github.com/sigstore/rekor/pkg/pki/pgp
 expvar
-github.com/go-chi/chi
+github.com/go-openapi/runtime/middleware/header
+github.com/sigstore/rekor/pkg/pki/pgp
+github.com/go-openapi/runtime/middleware/denco
+go.opentelemetry.io/otel/semconv/internal/v2
+github.com/hashicorp/go-cleanhttp
 github.com/sigstore/rekor/pkg/util
+go.opentelemetry.io/otel/propagation
+github.com/opentracing/opentracing-go
 net/http/pprof
+github.com/sigstore/rekor/pkg/pki/ssh
+github.com/sassoftware/relic/lib/pkcs9
+github.com/go-openapi/errors
+net/http/httputil
 github.com/go-openapi/swag
+github.com/go-chi/chi
 github.com/magiconair/properties
-go.uber.org/zap
 github.com/spf13/afero
-github.com/go-openapi/runtime/middleware/denco
-github.com/go-openapi/runtime/middleware/header
-github.com/sigstore/rekor/pkg/pki
+golang.org/x/net/trace
+go.uber.org/zap
+golang.org/x/net/http2
+github.com/hashicorp/go-retryablehttp
+go.opentelemetry.io/otel/internal/global
+github.com/sassoftware/relic/lib/certloader
+github.com/opentracing/opentracing-go/ext
 github.com/sigstore/rekor/cmd/rekor-cli/app/state
+github.com/sigstore/rekor/pkg/pki
+go.opentelemetry.io/otel/semconv/v1.17.0/httpconv
 github.com/go-openapi/strfmt
-github.com/opentracing/opentracing-go
-go.opentelemetry.io/otel/propagation
-go.opentelemetry.io/otel/semconv/internal/v2
-net/http/httputil
-github.com/hashicorp/go-cleanhttp
+github.com/sassoftware/relic/config
 github.com/go-chi/chi/middleware
-github.com/opentracing/opentracing-go/ext
-go.opentelemetry.io/otel/internal/global
-go.opentelemetry.io/otel/semconv/v1.17.0/httpconv
-github.com/hashicorp/go-retryablehttp
 github.com/spf13/viper/internal/encoding/javaproperties
-golang.org/x/net/trace
-github.com/sassoftware/relic/lib/pkcs9
-golang.org/x/net/http2
+github.com/sassoftware/relic/lib/signjar
+go.opentelemetry.io/otel
 github.com/go-openapi/jsonpointer
-github.com/sassoftware/relic/lib/certloader
 github.com/go-openapi/jsonreference
-go.opentelemetry.io/otel
+github.com/spf13/viper
 github.com/go-openapi/spec
-github.com/go-openapi/runtime
-github.com/sassoftware/relic/config
-github.com/sassoftware/relic/lib/signjar
 github.com/sigstore/rekor/pkg/log
-github.com/spf13/viper
-github.com/go-openapi/runtime/security
+github.com/go-openapi/runtime
 github.com/go-openapi/runtime/yamlpc
-github.com/go-openapi/analysis/internal/flatten/normalize
+github.com/go-openapi/runtime/security
 github.com/go-openapi/analysis/internal/flatten/operations
-github.com/go-openapi/analysis/internal/flatten/schutils
+github.com/go-openapi/analysis/internal/flatten/normalize
 github.com/go-openapi/analysis/internal/flatten/replace
+github.com/go-openapi/analysis/internal/flatten/schutils
 github.com/go-openapi/analysis/internal/flatten/sortref
 github.com/go-openapi/analysis
 google.golang.org/grpc/internal/transport
@@ -3175,41 +3211,41 @@
 github.com/go-openapi/runtime/client
 github.com/google/trillian
 github.com/sigstore/rekor/pkg/types
-github.com/sigstore/rekor/pkg/generated/client/index
 github.com/sigstore/rekor/pkg/generated/client/pubkey
+github.com/sigstore/rekor/pkg/generated/client/index
 github.com/sigstore/rekor/pkg/generated/client/tlog
 github.com/sigstore/rekor/pkg/generated/client/entries
-github.com/sigstore/rekor/pkg/tle
-github.com/sigstore/rekor/pkg/types/cose
 github.com/sigstore/rekor/pkg/types/dsse
 github.com/sigstore/rekor/pkg/types/hashedrekord
 github.com/sigstore/rekor/pkg/types/helm
-github.com/sigstore/rekor/pkg/types/intoto
 github.com/sigstore/rekor/pkg/types/jar
-github.com/sigstore/rekor/pkg/types/alpine
+github.com/sigstore/rekor/pkg/tle
 github.com/sigstore/rekor/pkg/types/rekord
-github.com/sigstore/rekor/pkg/types/cose/v0.0.1
-github.com/sigstore/rekor/pkg/generated/client
-github.com/sigstore/rekor/cmd/rekor-cli/app/format
+github.com/sigstore/rekor/pkg/types/cose
+github.com/sigstore/rekor/pkg/types/intoto
+github.com/sigstore/rekor/pkg/types/alpine
+github.com/sigstore/rekor/pkg/types/rfc3161
+github.com/google/trillian/types
 github.com/sigstore/rekor/pkg/types/dsse/v0.0.1
 github.com/sigstore/rekor/pkg/types/hashedrekord/v0.0.1
+github.com/sigstore/rekor/cmd/rekor-cli/app/format
 github.com/sigstore/rekor/pkg/types/jar/v0.0.1
-github.com/sigstore/rekor/pkg/types/rekord/v0.0.1
-github.com/sigstore/rekor/pkg/types/helm/v0.0.1
-github.com/google/trillian/types
+github.com/sigstore/rekor/pkg/types/rfc3161/v0.0.1
+github.com/sigstore/rekor/pkg/types/cose/v0.0.1
 github.com/sigstore/rekor/pkg/types/intoto/v0.0.1
-github.com/sigstore/rekor/pkg/client
 github.com/sigstore/rekor/pkg/types/intoto/v0.0.2
+github.com/sigstore/rekor/pkg/types/rekord/v0.0.1
 github.com/sigstore/rekor/pkg/sharding
-github.com/sigstore/rekor/pkg/types/rfc3161
-github.com/sigstore/rekor/pkg/verify
+github.com/sigstore/rekor/pkg/types/helm/v0.0.1
+github.com/sigstore/rekor/pkg/generated/client
 github.com/sigstore/rekor/pkg/types/alpine/v0.0.1
-github.com/sigstore/rekor/pkg/types/rfc3161/v0.0.1
+github.com/sigstore/rekor/pkg/client
+github.com/sigstore/rekor/pkg/verify
 github.com/sigstore/rekor/cmd/rekor-cli/app
 github.com/sigstore/rekor/cmd/rekor-cli
 make[1]: Leaving directory '/build/reproducible-path/rekor-1.3.7'
    dh_auto_test -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go test -vet=off -v -p 11 github.com/sigstore/rekor/cmd/rekor-cli
+	cd _build && go test -vet=off -v -p 21 github.com/sigstore/rekor/cmd/rekor-cli
 === RUN   TestCover
 Rekor command line interface tool
 
@@ -3239,7 +3275,7 @@
 Use "rekor-cli [command] --help" for more information about a command.
 --- PASS: TestCover (0.00s)
 PASS
-ok  	github.com/sigstore/rekor/cmd/rekor-cli	0.055s
+ok  	github.com/sigstore/rekor/cmd/rekor-cli	0.010s
    create-stamp debian/debhelper-build-stamp
    dh_testroot -O--builddirectory=_build -O--buildsystem=golang
    dh_prep -O--builddirectory=_build -O--buildsystem=golang
@@ -3254,7 +3290,7 @@
 mkdir: created directory '/build/reproducible-path/rekor-1.3.7/debian/rekor/usr/share'
 mkdir: created directory '/build/reproducible-path/rekor-1.3.7/debian/rekor/usr/share/man'
 mkdir: created directory '/build/reproducible-path/rekor-1.3.7/debian/rekor/usr/share/man/man1'
-env PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/build/reproducible-path/rekor-1.3.7/debian/tmp/usr/bin \
+env PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path:/build/reproducible-path/rekor-1.3.7/debian/tmp/usr/bin \
 	help2man --no-info --version-string="1.3.7-1" \
 	--no-discard-stderr -Idebian/rekor-cli.h2m \
 	rekor-cli -o /build/reproducible-path/rekor-1.3.7/debian/rekor/usr/share/man/man1/rekor-cli.1
@@ -3289,12 +3325,14 @@
 dpkg-buildpackage: info: binary-only upload (no source included)
 dpkg-genchanges: info: including full source code in upload
 I: copying local configuration
+I: user script /srv/workspace/pbuilder/5639/tmp/hooks/B01_cleanup starting
+I: user script /srv/workspace/pbuilder/5639/tmp/hooks/B01_cleanup finished
 I: unmounting dev/ptmx filesystem
 I: unmounting dev/pts filesystem
 I: unmounting dev/shm filesystem
 I: unmounting proc filesystem
 I: unmounting sys filesystem
 I: cleaning the build env 
-I: removing directory /srv/workspace/pbuilder/31500 and its subdirectories
-I: Current time: Fri Jan 17 07:39:37 -12 2025
-I: pbuilder-time-stamp: 1737142777
+I: removing directory /srv/workspace/pbuilder/5639 and its subdirectories
+I: Current time: Fri Feb 20 16:04:33 +14 2026
+I: pbuilder-time-stamp: 1771553073