Provenance attestation format update
SLSA provenance attestations now include the full BuildKit frontend version and build argument hashes. Existing attestations remain verifiable; new builds emit the richer predicate.
- FEATUREEmit BuildKit frontend version in in-toto predicate
- FEATUREHash-sealed build arguments included in provenance subject
- FIXRekor entry URL was occasionally truncated in verify output
- FIXflareo search --json now emits valid JSONL when 0 results