upaas uploads its clone as a tar context, which .dockerignore does not
filter, so its builds already carried .git; the binary said "unknown"
because the VERSION build arg defaulted to "unknown". The old .git/
exclusion kept .git out of a directory-context build only. .dockerignore
now lets .git through without its config, which can carry a credential,
and leaves out no tracked file (an excluded one would read as deleted and
mark the version -dirty). The VERSION build arg loses its "unknown"
default, so script/version derives the version inside the build; a given
VERSION still takes precedence.
The builder stage installs git, trusts the copied checkout whoever owns
its files, and fails when its context carries .git and the version still
comes out "unknown". The CI fingerprint is now the commit being checked.
Model: opus-5-5