Checks

CSP missing upgrade-insecure-requests

The policy does not include upgrade-insecure-requests.

Why it matters

Browsers will not rewrite http:// subresources to HTTPS on their own.

What to do

Add upgrade-insecure-requests, and still fix hardcoded HTTP URLs in the HTML.

Reference

CSP Level 3 defines the directives and source lists this check evaluates.

W3C CSP Level 3