"‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data"
If you're embedding a JS library from a CDN, then you have a lawful basis for passing the IP address of your user to a third party under Art. 6(1)(f). As long as you've performed a reasonable risk assessment about this activity and have records to prove it, you should satisfy your obligations as a controller under Chapter 4. If they go rogue and add a bunch of tracking scripts to the library, they're liable. You'd still need to notify about the breach.
If you're embedding a Javascript ad unit that does a bunch of tracking, you probably don't have a legitimate interest under Art. 6(1)(f), so you'll need consent. You're intentionally passing a bunch of personal data to a third party, so your responsibilities with regards to risk assessment are far greater. You and the ad provider probably constitute joint controllers under Art. 26.
https://gdpr-info.eu/recitals/no-15/
https://gdpr-info.eu/art-6-gdpr/
https://gdpr-info.eu/chapter-4/
https://gdpr-info.eu/art-26-gdpr/
IANAL etc.