Doesn't SRI require the hashes to be in the __loaded__ html? I believe parent is referring to a page which is the same, but has been compromised on the server side, meaning you can't trust the html, even if the server is who it says it is.
data:text/html,<script crossorigin="anonymous" integrity="..." src="...">
In total that should be a lot smaller than the linked codegolf answer.