build1 publisher
A CSP directive turns every string passed to innerHTML into a TypeError
MDN now lists the Trusted Types API as Baseline 2026, newly available. The JavaScript half only lets you sanitize; require-trusted-types-for is the part that makes an unsanitized assignment throw, and the sanitizer stays yours to write.
Publishers:developer.mozilla.org
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+8
- Incentives22
- Confidence63