.dockerignore now sends .git but not .git/config, which can hold a
credential and which git describe does not need. The build stage stamps
main.Gitrev from the VERSION build argument when one is given, otherwise
from git describe --tags --always, and fails if .git is present and no
version comes out. script/docker is replaced by the canonical copy,
which passes VERSION; bin/gitrev.sh uses --tags too, so every entrypoint
stamps the same value for a clean commit.
Model: opus-5-5