TODOs before we can create an issue for Red Hat folks to review:
- create patch files for shim
- Dockerfile for shim
- SBAT for shim
- PGP keys in README
- test the shim with arm and x86_64 QEMU and tianocore EDK II firmware
- github actions for shim
- SBAT for grub
- list of grub modules
- Dockerfile for grub in separate repo
- check SONiC and ONIE Linux kernel for lockdown patches, create if necessary
- SHA256 hashes of shim binaries