On further inspection the root cause of this delta was the reproduce script in #95 adding timestamp tokens to one entity when calling codesign but not the other.
I think our default behavior of adding timestamp tokens when adding CMS signatures is fine.