This PR adds a workflow to automatically publish the package (including
attestations) to Python upon tag/release creation.
Note that this relies on trusted publishing:
https://docs.pypi.org/trusted-publishers/
---------
Signed-off-by: Yuan Tang <terrytangyuan@gmail.com>