https://docs.github.com/en/actions/security-guides/using-artifact-attestations-to-establish-provenance-for-builds for jars and docker images