Adds outputs for image tags and digest in the build-and-push job and updates the Trivy scanner to reference the image by digest instead of the latest tag. This ensures the vulnerability scan is performed on the exact built image.
Grants the 'attestations: write' permission in the GitHub Actions Docker workflow to enable writing attestations. This may be required for enhanced security or provenance features.
Updates the GitHub Actions workflow to use the correct step ID 'build-and-push' for the Docker image digest output, ensuring the provenance attestation references the correct value.
Grants the workflow 'id-token: write' permission, which may be required for certain authentication steps or integrations in the Docker build and publish process.
Introduced Dockerfile, .dockerignore, and GitHub Actions workflow for building and publishing Docker images. Added server.js as the Express entrypoint for standalone deployment. Updated README with Docker, Docker Compose, and Kubernetes deployment instructions.