drop github actions provenance attestation export · parse builder + materials + subject digest · runs locally
drop github actions provenance attestation export · local only
heuristic screener · vendor schema varies · not definitive proof