ci: attest release artifacts with actions/attest
Generate SLSA build-provenance attestations for every released
artifact via actions/attest@v4 (the recommended action that
auto-fills the SLSA v1 predicate).
- static.yaml: switch the three existing attest-build-provenance
calls to actions/attest and add the artifact-metadata:write
permission required by v4.
- windows.yaml: attest the released frankenphp-windows-x86_64.zip.
- docker.yaml: attest each pushed manifest list (builder + runner
per variant) by digest, pushing the attestation to the registry.