Some rebuttals:
> 1) The biggest benefit of using cdn was that scripts stylesheets were often loaded from cache. This is no longer the case anymore.
This is indeed true. However, most websites (despite the relative ease of activating a CDN service) only host their website in a single location. In those cases, library CDNs (to differentiate from other uses of CDNs) can still benefit the website, even when you consider optimisation strategies such as HTTP/2. Additionally, the stress on their servers are decreased because it's handled by their library CDN provider.
> 2) It's adding an unnecessary vulnerability as seen from this case.
> 3) CDN scripts can be (possibly) used to track your website traffic.
Good points and something that I can't rebut easily. It is indeed on the onus of the website to check the reputation of library CDNs, and it may violate privacy guarantees (you're trusting Google/CloudFlare/Microsoft/Amazon/Fastly/MaxCDN etc.) Specifically on 2) however, they knew that they are large: the speed of fixes (as shown) here proves that library CDNs can benefit websites' security, which tends that its software stack is updated slower (by the website operator's fault). You can also leverage subresource integrity (https://developer.mozilla.org/en-US/docs/Web/Security/Subres...) to fail hard.
> 4) They often drop third party cookies which decreases your website load speed among other things.
Citation needed here. As far as I checked (and just verified as I post this, to ensure that this is still true), every library CDNs I knew (even in weird places such as Japan- and China-centric library CDNs) do not place cookies in the library URLs themselves (some do on their websites themselves, but it is usually separated by domain names).
> It's best to just host your script on Digital ocean spaces or S3 and use a Cloudfront proxy.
If you're a large website or basically need to ensure the privacy is guaranteed, sure! I see that large websites do in fact use their own choice of CDN providers (most websites including Amazon themselves uses Fastly though). Some even do a step-up: some websites (for example) use Fastly for their American traffic, KeyCDN for European traffic and Quantil for Asian traffic. However, I only knew of two CDN providers which provides a flat-rate and reasonable costs: CloudFlare (uhh, CDNJS operator) and DDOS-Guard (which some consider shady).