In all cases where you can use SRI, there's a better mitigation: Just host a copy of the file yourself.
For self hosted dynamic scripts, I just add a task in my build process to calc the sha and add it to the <src integrity="sha..." >
Otherwise just calc it and hardcode it once for 3rd party, legacy scripts...