1.1 KiB
1.1 KiB
Kubbe vendor source policy
vendor/source/ contains exact, local source snapshots of third-party projects.
No nested .git directory or Git file is allowed after synchronization.
The large source payload is intentionally excluded from the Kubbe Git history.
Its reproducible identity is defined by manifest.lock.json and the scripts in
tools/vendor/. This avoids nested repositories and GitHub repository/file-size
limits while keeping every checkout deterministic.
Layout
vendor/
├── cache/ downloaded immutable archives
├── source/ extracted source trees without Git metadata
├── tools/ pinned bootstrap tools such as depot_tools
└── work/ disposable synchronization workspaces
Bootstrap
tools/vendor/bootstrap.sh
The bootstrap verifies archive checksums where upstream publishes them, pins Git-based sources to exact commits, synchronizes V8/Skia dependencies, records the resolved revisions, and finally strips nested Git metadata.
Verify an existing payload without modifying it:
tools/vendor/verify.sh