When you serve your JavaScript over a CDN rather than directly from your server, the CDN has access to pretty much everything your users have access to - the CDN can read cookies and local tokens, make actions on behalf of users (such as updating the profile, messaging users, deleting content, making payments), read out financial/sensitive information, and more. A permanent and impossible to fix XSS attack vector that can be abused by your CDN, or anyone who hacks to your CDN.
This, in addition to security issues caused when the CDN proxies requests to your main hostname and not only to your static files (requiring you to surrender your SSL keys to them).
While working on Bitrated, a Bitcoin service that deals with users' private keys and funds on the client-side, this stood out as a very serious issue. We opted to not serve any content from 3rd-party providers, at all (including Analytic services, which suffer from the very same issue), and configured a strict Content-Security-Policy that forbids anything other than hostnames controlled directly by us over SSL.
Edit: I'm aware of SRI, but it is brand new and not yet supported by the majority of browsers in use, so its not really a realistic solution just yet.