Open
Description
What would you like to be added:
We are now building the RPMs and debs as part of the release process. We should be recording these files in the provenance attestation on staging and accounting for them on the final SBOM after they're signed. We should also try to create an attestation of the OBS build if possible and record the packages there too.
Why is this needed:
Currently we don;t have a record of these files in our build metadata.