# Kubbe vendor source policy `vendor/source/` contains exact, local source snapshots of third-party projects. No nested `.git` directory or Git file is allowed after synchronization. The large source payload is intentionally excluded from the Kubbe Git history. Its reproducible identity is defined by `manifest.lock.json` and the scripts in `tools/vendor/`. This avoids nested repositories and GitHub repository/file-size limits while keeping every checkout deterministic. ## Layout ```text vendor/ ├── cache/ downloaded immutable archives ├── source/ extracted source trees without Git metadata ├── tools/ pinned bootstrap tools such as depot_tools └── work/ disposable synchronization workspaces ``` ## Bootstrap ```bash tools/vendor/bootstrap.sh ``` The bootstrap verifies archive checksums where upstream publishes them, pins Git-based sources to exact commits, synchronizes V8/Skia dependencies, records the resolved revisions, and finally strips nested Git metadata. Verify an existing payload without modifying it: ```bash tools/vendor/verify.sh ```