Submodules are precise, but every clone has to cooperate. The fresh clone pulls the update:
cd ../fresh
git pull -q
git status -s
git -C public/vendor/ui status | head -1
git submodule update
cd ../booknestOutput
M public/vendor/ui HEAD detached at 25b55ab Submodule path 'public/vendor/ui': checked out '0e31a26e08045bd816e8008085e067de22594024'
The pull moved the recorded commit but not the folder, which still held 1.0.0, so a careless git commit -a now would downgrade the library for everyone. The common complaints follow from that design:
Every clone and pull needs git submodule update; submodule.recurse true makes pull and switch do it.
Inside a submodule HEAD is detached, so commits made there belong to no branch.
Pushing the superproject before the submodule publishes a commit nobody can fetch; push.recurseSubmodules check refuses such a push.
CI systems, Docker 514 builds and git archive need extra steps or skip submodules entirely.