<script src="https://jquery.com/whatever.js" hash="sha256,deadbeef...">
The browser would refuse to load the script if its hash didn't match.This would be far safer than what we currently do.
It would also allow the browser to more aggressively cache scripts -- if it already has a script in the cache from another URI whose hash matches, e.g. because someone else included jquery from Google's CDN, it can substitute it in.
This has an easy legacy story, too; old browsers will just ignore the "hash" tag and behave as they currently do.