Content-Security-Policy now uses 'strict-dynamic'

strict-dynamic should work with remote scripts loaded via loadScript. In fact, that was the main reason for the switch: we no longer need to list every single external script URL up-front. That’s especially good for people running ads, which often pull in a ton of remote scripts.

Are you seeing errors with loadScript?