How do I build a reproducible sbsigntool tarball?

cd debian/ && tar --sort=name \
--mtime="@`git -C sbsigntool-$(DOWNLOAD_VERSION) log -1 --pretty=%ct`" \
--owner=0 --group=0 --numeric-owner \,delete=atime,delete=ctime \
--exclude=.git --exclude=lib/ccan.git \
-c sbsigntool-$(DOWNLOAD_VERSION) | xz > ../../sbsigntool_$(DOWNLOAD_VERSION).orig.tar.xz

