# Import and adapt source

Bring JSON, ZIP, raw source, or a pinned GitHub revision into the reviewed import flow.

JSON and ZIP packages enter a review screen before account installation. ZIP
imports accept one build, prefer `stillmade.block.json` plus edited `src/run.js`
or `src/recipe.json` or `src/comfyui.json`, and `tests/fixtures.json`, and reject unsafe/duplicate paths,
ambiguous builds and excessive expanded source. Included development dependencies
are not installed or executed by the app.

`scanPackage(package)` parses standalone JavaScript and screens unsupported ambient
APIs/modules and dynamic constructor access. `admitPackage(package, {test, run})`
adds fixture tests and a sample through supplied sandbox runners. A passing scan
is not proof of safety; the sandbox remains mandatory. Import confirmation repeats
admission on the server and creates an owner-scoped account copy. It does not create
a public release. The original license and provenance remain intact.

Raw-code adaptation accepts a purpose description, source name, source code and
license/permission terms. AI creates a new SDK package; it never executes the
original code. `manifest.provenance.adaptedFrom` records its digest, name and
license and the original source text (retaining its attribution). Unsupported capabilities return an explanation or a failed editable
draft, not a working-runtime claim. GitHub JSON imports retain the selected
branch/tag/commit and verified Git blob identity.

## GitHub repositories
**Adapt a GitHub repository** resolves a public branch/tag/ref to a full commit
SHA. The in-app adapter selects up to six implementation, README, test, or
dependency-metadata files and then retains every applicable ancestor
LICENSE/COPYING/NOTICE file, up to sixteen regular UTF-8 files and 45 KB combined.
Inspectable source includes JavaScript/TypeScript, Svelte/Vue, HTML/CSS, SVG,
GLSL/WGSL, Python, Rust, Go, shell, and common C/C++/Qt text files. These files
remain untrusted evidence: StillMade does not install dependencies or execute the
repository. A recognized native application may instead produce an independently
authored desktop-only Block using a versioned, allowlisted host adapter. The Block
still has no shell, arbitrary executable, unrestricted filesystem, Qt/OpenFX
plugin, or dependency-install authority. Unrecognized native repositories remain
source evidence only and do not become Blocks merely because they are public.
The app reads a complete bounded Git tree, excludes symlinks, submodules and
unsupported/secret paths, and verifies each blob against its Git SHA-1 identity.
Review the original code and applicable license before requesting adaptation.
No repository dependencies, hooks, scripts, or original source are executed.

The adaptation request refetches the same commit and selected blobs. An LLM rewrites
the relevant behavior into supported SDK recipes/isolated JavaScript; unavailable
capabilities remain unsupported. `manifest.provenance.adaptedFrom` retains the
original selected source, license, source digest, and `origin` with repository,
commit and per-file blob digests. This metadata records origin, not verification
of legal rights or authorship. The final package still requires normal import
admission and user confirmation. Importing does not publish third-party source.

The approved Natron route pins the requested GitHub commit without copying or
executing its GPL application source, generates an MIT SDK integration Block,
and declares one `video` input and output for Project Type composition. Its
desktop adapter can import/open a `.ntp` project and render an authorized local
video through fixed Reader/Writer node names and a bounded frame range. It does
not expose Natron's Python/interpreter flags. Private repositories, arbitrary
large native codebases, dependency installation and Python/ComfyUI execution
remain outside this adaptation runtime. Public GitHub API
rate limits apply; downloaded SDK packages and pasted-source adaptation remain
available alternatives.
