The Docker-gated probe only planted a root-level .env.t08-* marker, which no Dockerfile COPY instruction ever copies — so it could not observe a nested build-context leak in the image layers. Plant additional marker files at nested paths the Dockerfile's COPY apps/server apps/server would sweep into the build-stage image (apps/server/.env.t08-*, apps/server/secrets/t08-*.pem) so the end-to-end scan actually verifies the 'any depth' exclusion guarantee, not just the root form.