37 lines
1.1 KiB
Markdown
37 lines
1.1 KiB
Markdown
# Kubbe vendor source policy
|
|
|
|
`vendor/source/` contains exact, local source snapshots of third-party projects.
|
|
No nested `.git` directory or Git file is allowed after synchronization.
|
|
|
|
The large source payload is intentionally excluded from the Kubbe Git history.
|
|
Its reproducible identity is defined by `manifest.lock.json` and the scripts in
|
|
`tools/vendor/`. This avoids nested repositories and GitHub repository/file-size
|
|
limits while keeping every checkout deterministic.
|
|
|
|
## Layout
|
|
|
|
```text
|
|
vendor/
|
|
├── cache/ downloaded immutable archives
|
|
├── source/ extracted source trees without Git metadata
|
|
├── tools/ pinned bootstrap tools such as depot_tools
|
|
└── work/ disposable synchronization workspaces
|
|
```
|
|
|
|
## Bootstrap
|
|
|
|
```bash
|
|
tools/vendor/bootstrap.sh
|
|
```
|
|
|
|
The bootstrap verifies archive checksums where upstream publishes them, pins
|
|
Git-based sources to exact commits, synchronizes V8/Skia dependencies, records
|
|
the resolved revisions, and finally strips nested Git metadata.
|
|
|
|
Verify an existing payload without modifying it:
|
|
|
|
```bash
|
|
tools/vendor/verify.sh
|
|
```
|
|
|