Add a new `commit` field to track what the exact commit on which the dependency was built. It should only be included when `SourceKind` is `git`. The final entry would look like this: `commit: "311f9932128667b8b18113becdea276b3d98aace"`