workflows/upload-release-artifact: Upload a separate attestation for each artifact (#171525)
This will simplify the process of verifying the assets, because the
attestation file for $file will be $file.jsonl. Otherwise, it's not
clear which attestation file goes with which asset.