Consider adding the [`trusted-types`](https://w3c.github.io/webappsec-trusted-types/dist/spec/#trusted-types-csp-directive) and [`require-trusted-types-for`](https://w3c.github.io/webappsec-trusted-types/dist/spec/#require-trusted-types-for-csp-directive) directives.