are people doing this? What's the attack surface of a private hosted JS library vs. a well known TLS/SSL secured CDN for JS libraries? Threats are not restricted to CDNs.
CDN's fail. You already have a connection to the 'stuff.com' self-hosted js. If your site is up but the cdn breaks you have another problem.
Also the perf win for using a shared cdn version of for instance jquery is totally overstated. See discussions here too: https://news.ycombinator.com/item?id=11549131