CSP may be implemented with http header in <meta http-equiv='Content-Security-Policy' content='...'> This is the only way to do it with github pages. Should be supported, to avoid false-positive of -25 in HTTP scores