check / check (push) Failing after 2s
The canonical .dockerignore kept out .git/config and the configs under .git/modules/, but not the config of a submodule that keeps its own .git directory, so its credential reached the image. Both git patterns now carry the **/ prefix. A submodule whose name has a config segment (config, deploy/config, config/lib) still loses its whole git directory, and Go's version stamping fails the build. Closing that needs a wildcard re-include, which makes BuildKit walk every excluded directory on every build, so the file records it as a KNOWN GAP with the remedy, git submodule add --name. REPO_POLICIES.md and both checklists say the same. Model: opus-5-5