These are my top 3 tips for getting started with a Content Security Policy - as proven by a friend who went from failing security scans to passing with flying colours.
https://securinglaravel.com/security-tip-run-your-csp-in-local-development/#Laravel