A new section of the README should be added to document provenance status. It should include links to the source commit, build workflow and sigstore log entry. Doing so will improve security posture against supply chain attacks and align ourselves with modern security best practices.
Ideally, we create an automation that runs after a successful release to update these values automatically
Example:
Provenance (SLSA)
Built and published from GitHub Actions with npm provenance.