This link appeared in WDRL 166 on .
GitHub's post-CSP journey
A few months ago, Github shared their learnings from using the Content Security Policy at github.com. Now they share more learnings in “GitHub’s post-CSP journey”. The focus lies on img-src, form nonces, same-site cookies, and more.