External scripts with matching SRI hash (in default-src) should be allowed.