CSP allows only scripts whose nonce matches the policy:
nonce
Content-Security-Policy: script-src 'nonce-trusted123'
Lines: 0 | Characters: 0