It's pretty much a given that moving from one major release to another is going to break things. Since you're using Django as an example then I should point out that this is why Django spent half of it's life in a pre-1.0 state where there were major changes from the .91, .95, and .96 branches which broke every minor version up until 1.0 before it was officially released. Remember when the admin used to be tied to each model instead of decoupled? I sure do - https://docs.djangoproject.com/en/dev/releases/1.0-porting-g...
I'm half surprised you didn't just create a requests-1.0 branch and then give the third party libraries time to upgrade instead of pinning to shas. I have several projects that depend on requests<1.0 which will run just fine for some time.