Adopt PEP 740 digital attestations for Django releases

you are assuming that releases get published via github actions :slight_smile: I do not think we have a release pipeline, do we?

Yes, this will certainly need a ticket and probably some discussion around whether we even want to move the release process to github in the first place.