Security
- Release images carry a signed build provenance attestation, and each GitHub release ships the matching
.sigstore.jsonbundle for verification withgh attestation verify. (#737)
.sigstore.json bundle for verification with gh attestation verify. (#737)