Image is allowed here:
iframe with srcdoc attribute and very restrictive csp not allowing javascript or any external resources:
This link should always be allowed to execute javascript:
Trigger alert