1. Content Security Policy Level 2

    Mitigate cross-site scripting attacks by only allowing certain sources of script, style, and other resources. CSP 2 adds hash-source, nonce-source, and five new directives

  2. credentialscontainer api: get: `identity` option: `identity.providers.nonce`

  3. htmlelement api: nonce

  4. mathmlelement api: nonce

  5. navigator api: createauctionnonce

  6. svgelement api: nonce

  7. html attribute: nonce