That seems better, but still a problem for privacy. For various reasons,
like:
How can differentiate between sites who will give a long Expires header,
between those who don't.
I browse the web with the RequestPolicy plugin, so I don't have to constantly
tell everyone what sites I visit, if I don't explicitly permit that. CDN
services like this are real hindrance when you need privacy and browse in
this way.
Sometimes I browse in private mode and there Expires headers aren't
remembered between sessions, if I'm correct.
Just upload the script on your server, please. Especially if you think users
are going to download the script once an year, like you suggest.