A plain `docker build .` of a clone stamped `dev`: `.dockerignore` left
out `.git` and the build stage declared `ARG VERSION=dev`. `.git` now
reaches the build context without `.git/config`, which can hold a
credential, and the build stage takes the VERSION build argument when
given, otherwise `git describe --tags --always`. A context that carries
`.git` but yields no version fails the build.
`script/docker` is replaced with the current canonical copy, which
passes the version it derives on the host.
Model: opus-5-5