I'm just wondering if you maybe can relax some of the CSP rules you have on
the site. Scheme.org don't have any user generate content, it doesn't have
any user input. CSP was mostly to prevent XSS and other similar attacks.
There is not need for such a thing for website like scheme.org.
I'm asking this because I can't run my bookmarklet that create Scheme REPL.
https://lips.js.org/#bookmark
I use only one Domain https://cdn.jsdelivr.net it's CDN (Content Delivery
Network[1]) for files from NPM package registry for JavaScript packages.
[1]: https://en.wikipedia.org/wiki/Content_delivery_network
--
Jakub T. Jankiewicz, Senior Front-End Developer
https://jcubic.pl/me