Magento
Magento already ships CSP: start monitoring it today
Magento 2 has shipped with Content Security Policy enabled by default since version 2.3.5. On current releases, most pages use a report-only policy, while payment pages use an enforced policy by default. Magento does not, however, know where to send violation reports unless you configure an endpoint.