"The integrity attribute is missing on a script or link tag served by an
external server. The integrity tag prevents an attacker who have gained
access to this server from injecting a malicious content."
It is not a false positive as the integrity attribute really is missing :P
The fact that you cannot add an integrity attribute is a different problem.
I don't have to deal with PCI compliance, so can't answer that question :D
Cheers,
Simon