Does SRI allow signatures? I want to have a policy where any script signed by my Ed25519 key is valid, I don't want to have to hardcode the hash everywhere.
Libraries were added manually by legions of developers long before one thought he'd need to create a downloadable left-pad "package".
The whole package management issue is overrated.