- use github token to fetch releases JSON from CDN if available by @crazy-max in #819
 - sigstore class to sign and verify BuildKit attestation manifests and provenance blobs by @crazy-max in #820 #830
 - cosign install and command support by @crazy-max in #826 #827 #828 #825
 - buildx(imagetools): return attestations digests by @crazy-max in #823
 - docker(install): update lima images by @crazy-max in #821
 - docker(install): don't use local system resolver with lima and increase timeouts by @crazy-max in #837 #839
 - Bump @actions/artifact from 2.3.2 to 4.0.0 in #818
 
Full Changelog: v0.64.0...v0.65.0