This is what worries me about the HTTP "Cache-Control: immutable" proposal. Immmutable caching should come with a reliable way to be sure that the content that is going to become immutable is not corrupted in the first place.
If the file is corrupted at the edge server an SRI attribute [1] can detect it, although it's not supported on IE and Safari yet.
[1] https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
IMHO, anything immutable should be identified with its SHA2+ hash.