ci: allow attestations in docker workflow

[skip ci]

Change-Id: I0fe34e639c89aa15f09e1d8b6313131f86e507ed
diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml
index e054ec3..cc53289 100644
--- a/.github/workflows/docker.yml
+++ b/.github/workflows/docker.yml
@@ -2,15 +2,16 @@
 on:
   push:
     tags:
-      - 'NFD-*'
+      - 'NFD-[0-9]+*'
   schedule:
     # twice a month
     - cron: '20 8 5,20 * *'
   workflow_dispatch:
 
 permissions:
-  packages: write
+  attestations: write
   id-token: write
+  packages: write
 
 jobs:
   nfd-build: