ci: allow attestations in docker workflow

[skip ci]

Change-Id: I0cb649c521996cdb9c3c9dd4c1b62cc1e05526ac
diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml
index dd71b5d..9616acd 100644
--- a/.github/workflows/docker.yml
+++ b/.github/workflows/docker.yml
@@ -2,15 +2,16 @@
 on:
   push:
     tags:
-      - 'NLSR-*'
+      - 'NLSR-[0-9]+*'
   schedule:
     # twice a month
     - cron: '20 9 5,20 * *'
   workflow_dispatch:
 
 permissions:
-  packages: write
+  attestations: write
   id-token: write
+  packages: write
 
 jobs:
   nlsr: