What you can do with some CDNs is have a self-served loader that pulls the files from the CDN using XHR (requiring CORS headers...), verifies the content hash, then injects it into the page if it looks good. I have a PoC on github https://github.com/ryancdotorg/verifyjs - same sort of thing could be modified to support signed files rather than hashed, which SRI can't do.