The canonical .dockerignore kept out .git/config but not the config in
each submodule's git directory under .git/modules/, nested again for a
submodule's own submodules, which can hold the same credential. Add
.git/modules/**/config and say so in REPO_POLICIES.md and both
checklists.
The pattern stays under .git/modules/: .git/**/config would also drop a
branch or tag named config in the top-level repository, which
git describe may need.
Model: opus-5-5