Signed-off-by: Paul Meyer <49727155+katexochen@users.noreply.github.com>
* ci: update Syft to 0.72.0 and Grype to 0.57.1 * ci: install Cosign before Syft * ci: directly read private key from environment for Cosign * ci: add --add-cpes-if-none to Grype * ci: use cosign attest directly instead of syft attest