This isn't a concern with our implementation because a hash of the asset bundle is also included in the URL. This is a pretty common cache-busting technique for static assets and lets you send more aggressive cache directives to the browser.
Maybe I should refrain from posting my gut reactions (or at least wait until I'm awake first). =)
If indeed this is the case, subresource integrity needs a big warning sign about that. For me, your comment was that warning sign, so please keep posting while you're not awake yet.
1) Load the resource specified in src (from network or cache)
2) If there's an integrity attribute, verify its hash