Yes attestation has to attest to the execution of a program and there's no program that can tell you the developer was competent/honest/not compromised. But what it can do is, for example, tell you that a build was done in a clean and verified environment i.e. one free of attackers/malware. And importantly this guarantee can be made also considering the cloud vendor as an attacker. Think about how horrific it'd be if an attacker got privileged access to AWS or GitHub Actions, for example.