Cross-project refs treat public models as a stable API, not a package
dbt Labs documentation on packages versus project dependencies that resolve public models through a metadata service.
dbt long supported installing other projects as packages, which pulls in full source code for macros and models. It also supports project dependencies that resolve on-the-fly refs to public models via a metadata service, so downstream teams do not parse or run upstream models. Those models are treated as an API whose maintainer guarantees quality and stability, with Enterprise prerequisites including public access and a production manifest.
Based on: Project dependencies | dbt Developer Hub · dbt Labs