atmos-vendoring

Installation
SKILL.md

Atmos Component Vendoring

For scheduled native Component Updater pull requests, scopes/groups, GitHub permissions, and CI summaries, use references/component-updater.md.

Vendoring copies external components, stacks, and other artifacts into your repository. This gives you full control over when and how dependencies change, with visibility through git diff, an immutable audit trail, and the ability to apply emergency patches without waiting for upstream releases.

Atmos records completed installs in the committed vendor.lock.yaml receipt. The receipt contains credential-free declared and resolved sources, immutable artifact evidence, and the ordered per-file materialization inventory. It applies to both centralized vendor.yaml sources and legacy component.yaml sources and mixins.

Why Vendor

Vendoring is the checked-in model for remote component code: you copy the code into the repository, commit it, and control when updates happen. This provides:

Installs
20
GitHub Stars
1.4K
First Seen
Mar 4, 2026
atmos-vendoring — cloudposse/atmos