go mod tidy will update your go modules whenever it feels it needs to and there's nothing you can do to stop it.
The workaround is vendoring, where you control the versions in a cache.
It is worth noting though that, even without such pinning, `go mod tidy` does not update versions willy-nilly. [edit: the following is inaccurate, see grandchild comment] It only syncs go.mod with what is already being used by the build process. In other words, if you see `go mod tidy` change a version, it means that you haven't tidied the file since making other changes to it, and the listing in go.mod was stale with respect to the resolved set of transitive dependencies actually being used.
If dependencies are incomplete, Go will fail to compile and tell you to run go mod tidy to fix it.
I think the “new” way is much better.
I still run tidy in pipelines to check but that’s only for cleanup.