A deposit should contain everything required to rebuild, support or recover the protected software if a release event occurs.
Depending on the application and agreement type, this may include source code, documentation, build instructions, configuration files, deployment scripts, databases, third-party dependencies, credentials, environment details and other supporting materials.
The objective is not simply to store files, but to ensure the organisation has access to the information required to successfully recreate and maintain the application if needed.