CSP Notes
Stop Injected JavaScript with CSP: Defense in Depth That Works
CSP: dropping 'unsafe-inline' — a practical path to 'strict-dynamic'
CSP in 2026
Writing Style Guide
CSP blog post — remaining work
CSP in 2026
Read the blog post
Open the presentation slides