It's important what the attestation is about. If it is about code, then a cryptographic hash of the code has to be included as the authoritative reference. A git commit id is such a hash. Version tags can move and binaries from all kinds of sources might claim to be Wallet X with version Y.