3 directives

Content-Security-Policy

default-src Keyword
'self'
default-src Keyword
'unsafe-inline'

Content-Security-Policy-Report-Only

require-trusted-types-for Keyword
'script'