Earlier quoted context omitted.
But that doesn't make it easy to integrate a new script from an author who doesn't provide the hash already.
Vendor your dependencies. It’s better for you as a maintainer anyway, since caching only works[0] with first party domains with any reliability. And once you vendor your dependencies you can calculate the hash yourself [0]: there are caveats to this
I think https and integrity hashes address two very orthogonal attack vectors.