Without fingerprinting/certification of the entire javascript-source the server could serve a manipulated source code that exfiltrates data
This is actually one of the described use cases of the new webpackage specification: https://tools.ietf.org/html/draft-yasskin-webpackage-use-cas...
Here is the current draft: https://wicg.github.io/webpackage/draft-yasskin-dispatch-web...