(Note: I don't use go, but this was the situation about 3 years ago when I last looked).
(Note: I don't use go, but this was the situation about 3 years ago when I last looked).
The Go team's solution to this problem was allowing vendored dependencies. Basically you can put the dependencies inside your project in a directory called vendor which will be used instead of whatever is in your $GOPATH/src/. This allows you to pin deps to a specific version and not need to pull deps from the internet at all.
Of course the current 'go get' model has a lot of downsides, e.g. Non deterministic builds. I still think it's worth considering building on, rather than trying to fix semver. All that's really missing is a stable monotonic identifier - something as simple as git tree height may be enough.
Of course for that to work well you'd also need to protect yourself from people deleting their git hub repos, or rewriting git history.