kubbebrowser/vendor/README.md

37 lines
1.1 KiB
Markdown

# Kubbe vendor source policy
`vendor/source/` contains exact, local source snapshots of third-party projects.
No nested `.git` directory or Git file is allowed after synchronization.
The large source payload is intentionally excluded from the Kubbe Git history.
Its reproducible identity is defined by `manifest.lock.json` and the scripts in
`tools/vendor/`. This avoids nested repositories and GitHub repository/file-size
limits while keeping every checkout deterministic.
## Layout
```text
vendor/
├── cache/ downloaded immutable archives
├── source/ extracted source trees without Git metadata
├── tools/ pinned bootstrap tools such as depot_tools
└── work/ disposable synchronization workspaces
```
## Bootstrap
```bash
tools/vendor/bootstrap.sh
```
The bootstrap verifies archive checksums where upstream publishes them, pins
Git-based sources to exact commits, synchronizes V8/Skia dependencies, records
the resolved revisions, and finally strips nested Git metadata.
Verify an existing payload without modifying it:
```bash
tools/vendor/verify.sh
```