An in-depth look at SBOM and build provenance Docker image attestation created by Docker/BuildKit, and the major problem of lacking verifiability.| AugmentedMind.de