Via @bureado Buildkit can trace docker builds. See https://docs.docker.com/build/metadata/attestations/slsa-provenance/