It's 2019, what excuse does Baidu have to not support https for these scripts?
I don't know if what's the reasoning behind that.
If you ever manage to load that CDN over HTTPS/QUIC it sets a HSTS header so all further pageloads will go over HTTPS.
One reason may be that http makes it easier for surveillance or injection.