That library you linked to is part of a shared repo we use for all of our stuff, https://github.com/candiddev/shared, it's versioned using git modules. We own all of the underlying code. We opted for git submodules because go modules hate CalVer, and we share a bunch of other stuff besides go libraries.
In the end, things are versioned like any other Go program, builds are 100% reproducible.