Trusted types allow you to lock down insecure parts of the DOM API and prevent client-side cross-site scripting (XSS) attacks.
Modern Web Guidance
How Modern Web Guidance uses this feature
Locks down dangerous DOM injection sinks (such as innerHTML, script src, and code evaluation) to mitigate client-side Cross-Site Scripting (XSS) by requiring string assignments to pass through named policies created by window.trustedTypes.
Recommended fallback strategy
Roll out via Content-Security-Policy-Report-Only: require-trusted-types-for 'script' first to identify and refactor offending sinks without breaking runtime behavior, then define a named sanitization policy via window.trustedTypes.createPolicy().
Community use cases (0)
Voting and comments closed
Baseline newly available (since ). Supported across all major browsers. Signals are closed because cross-browser interoperability has been achieved.