2be39b8b98
OpenSSF Scorecard's Signed-Releases check scans the GitHub Release *assets* for signed/provenance files (`*.intoto.jsonl`, `*.sig`, ...). It does not look at GitHub's separate attestations store, so although the attestations job has signed the published bytes since v0.4.0, the v0.4.0 release assets carried no provenance file and the check stayed at 0. Attach the Sigstore provenance bundle (already produced by actions/attest-build-provenance) to the release as `wickra-<tag>.provenance.intoto.jsonl`: - github-release now exposes its resolved tag as a job output. - attestations `needs: github-release` (so the Release already exists), gains `contents: write`, gives the attest step an id, and uploads the bundle with `gh release upload --clobber` (idempotent on re-runs). Publishes stay fully isolated — cargo/PyPI/npm all run upstream of github-release, so a Sigstore hiccup here can never block or corrupt a publish; at worst the release just lacks the provenance asset. Signed-Releases climbs over the next releases as each tag carries the bundle.