This is already in the package schema but needs to be actually implemented in the git dependency handling logic. This way you could naturally lock your dependency version in the `lpm.json` itself rather than in (the future) lockfile.