Just wanted to also confirm that I enrolled my own keys and no vendor keys, and everything works fine!
# sbctl status
Installed: ✓ sbctl is installed
Owner GUID: 40b8c598-846b-421e-95d0-78ec53efa8e8
Setup Mode: ✓ Disabled
Secure Boot: ✓ Enabled
Vendor Keys: none
There are no OpRoms whose signatures would be checked during boot on Frameowrk 13 AMD.
# tpm2 eventlog /sys/kernel/security/tpm0/binary_bios_measurements | grep BOOT_SERVICES_DRIVER || echo 'Nothing!'
Nothing!