This is not relevant. We are considering the interaction between our code and the library. If the library has breaking changes to its api our code will no long work with it when the library needs to be updated to the new version and our site will break until our code is changed...
Fair enough. Your question makes sense then. The trouble is without security updates there is bound to be some exploit that will go un-patched so when support for bootstrap 3 finishes we will have to upgrade to 4 whether we like it or not.