It seems, that the shishi build generates keys which end up in the store, making the build unreproducible. Can the key generation be extracted from the build?
If yes, then are we able to do the following: use a reproducible substitute without the key, generate the key afterwards, and store it somewhere else.
diffoscope output attached.