I want to try my hand at a slightly customised package. While my shell script proficiency is probably good enough (and I promise not to blame anyone else for my mistakes), the whole signing process is slightly beyond me, so I figured I'd start by simply recreating a package and seeing if it was identical to the released version, to check my system is working properly. I got files that seem to be close but not identical. My versions in each case seem to to be a percent or so bigger.
Could this be explained by slightly different versions/default settings of the initial tar, or is there something worse?