Problem
Wallet-facing pages are exposed to injection and supply-chain risk without restrictive runtime policy and repeatable dependency checks.
Objective
Deliver a production-quality improvement to production headers and frontend dependency pipeline that creates measurable value for correctness, security, reliability, performance, or maintainability.
Implementation scope
- Add a compatible restrictive CSP; document wallet exceptions; enforce critical vulnerability and license policy in CI.
Acceptance criteria
- Production headers contain the intended policy; critical dependency findings fail CI; wallet flows work only through approved origins.
Required validation
- Header integration, production smoke, and dependency-policy tests.
- Existing tests and CI remain passing.
- Add regression coverage for the original failure mode.
- Do not weaken, delete, or skip unrelated tests to obtain a green build.
PR quality bar
- Keep the PR focused and explain design tradeoffs, compatibility impact, and test evidence.
- Avoid typo-only, documentation-only, cosmetic-only, or unrelated refactor submissions.
Out of scope
- Broad rewrites not required by the acceptance criteria.
- Changes to unrelated services, contracts, or user flows.
Problem
Wallet-facing pages are exposed to injection and supply-chain risk without restrictive runtime policy and repeatable dependency checks.
Objective
Deliver a production-quality improvement to production headers and frontend dependency pipeline that creates measurable value for correctness, security, reliability, performance, or maintainability.
Implementation scope
Acceptance criteria
Required validation
PR quality bar
Out of scope