In order to verify `signedEntryTimestamp`, one needs to follow instructions that I could only find [here in this yaml](https://github.com/sigstore/rekor/blob/4fcdcaa58fd5263560a82978d781eb64f5c5f93c/openapi.yaml#L467-L471). That's also the only specification I could find as to what's included in the signature (although I could be mistaken of course). However, that's not easily discoverable in the docs, in particular, it doesn't show up on [swagger docs](https://www.sigstore.dev/swagger/#/). Would be nice if these spec and instructions easily searchable in docs: - In swagger generated doc - Ideally, also somewhere like https://docs.sigstore.dev/verifying/verify/