Content-Security-Policy should support `upgrade-security-policy` for CSP's
Content-Security-Policy should support
upgrade-security-policyfor CSP's