HTML5 Security Cheat Sheet
owasp.org
owasp.org
We're on report only at the moment, and it seems like every major JavaScript library depends on Eval() in one way or another (mostly new function()).
Just this week someone wanted to use Angular (1.3.1) and it generates dozens of CSP reports without ng-csp in the HTML element, but when the attribute exists $http responses (which depend on function()) aren't working (e.g. success(function(data, status, headers, config) {}).
Unfortunately Angular's documentation on CSP is a single page with nothing particularly helpful, and tons of stackoverflow results about Google Chrome extension development.
This is just the tip of the iceberg. Seems like every single major JavaScript library (even things you just take for granted) break CSP or need tons of exceptions.
`Function("a", "console.log(a);")`
Your example is a callback with an anonymous function.
Do you have any links to discussions about your issue?
Note: this isn't an ad, it just seemed relevant to those interested in a "cheat sheet." Automating it by calling out to our API seems really relevant. :)