check / check (push) Waiting to run
A plain docker build, as upaas runs it, passed no VERSION build arg and had no .git, so every such image stamped "unknown". .dockerignore now sends .git without its config, which can carry a credential, and every tracked file (an excluded one would read as deleted and mark the version -dirty). The VERSION build arg loses its "unknown" default, so script/version derives the version inside the build; a given VERSION still takes precedence. The builder stage installs git, trusts the copied checkout whoever owns its files, and fails when its context carries .git and the version still comes out "unknown". The CI fingerprint is now the commit being checked. Model: opus-5-5