I still don't really understand why we can't just run any files in cache (from other sites) with the same hash.
If I have the sha-256 of an exe file, I'm perfectly happy to run any exe file with the same sha256 simply because collisions don't happen. Why is this different for JavaScript?
If an attacker can inject HTML script tags into your website haven't you already lost?