Tie our dependencies to a commit hash instead of a movable version tag

Author: maehneCreated Sep 7, 2026Updated Sep 7, 2026
Labelshelp wantedgood first issue

The thanks to the help of @zdimension re-enabled SonarQube by PR #2967 raised some quality gate issues related to the versioning of our dependencies:

C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

We should address them as suggested in the reports by tying the dependencies to the commit hash instead of a movable tag. Dependabot should still be able to handle the automatic updating of the dependencies.

Source: logisim-evolution/logisim-evolution