You are correct, in the tarball and zip file there are .git directories under the vendors/ directory. This issue is being tracked in http://dev.sourcefabric.org/browse/CS-4915
If you use the .deb or .rpm package versions there should not be any .git directories:
As a consequence, the .deb and .rpm packages are much smaller than the tarball or zip file. If you find any other .git directories in the .deb or .rpm package, please let me know!