Content Security Policy by API
npmjs.com
npmjs.com
For as much as I know, segment.io or intercom.io are still very painful to use with CSP.
Also finding required CSP is often trial and error, since vendors don't publish CSP settings. For example, Stripe do, Braintree don't and refused to when asked.
Best way to have the vendors would maybe be as npm modules - eg, Stripe could publish and update 'stripe-csp'. It's not ideal through as npm is JS specific as someone might be using Ruby or Python or Elixir or Java. But since there's no cross language repo, maybe npm as a JSON repo is a good idea.