The author would say "the current version is 0.6.4 and its JS hashes to this SHA256 hash: xxx"
Open source already does this for binaries. Why not JS?
This assumes it's even possible to get a consistent hash of all javascript executing on a page, though.