That's odd. Why not compute both sha1 and sha256 for all git objects for the foreseeable future?
Failing that, have a kind of git object that wraps another and says hey this is in sha1 don't mess with it