`gh attestation verify` said yes to an image we never released
A developer demonstrated a four-step container image verification workflow against the soit-ai/soit server v1.0.0 release, showing that fetching by digest, verifying provenance, reading the SBOM, and …