ATTESTATION material type injects the In-toto statement to the policy engine. It would be good if, in addition to the statement: * it verifies the attestation bundle (in Sigstore bundle format), including the certificate chain, TSA and signature * it passes the signing certificate properties to the policy engine * it passes the result of the verification to the policy engine