- More attempts to fix release CI steps by moving them outside of docker containers.
- Fixing uploading provenance on release by providing the tag correctly to that action
- Pulled in zizmor CI/CD security scanning and all related changes it suggests from PR #315