Add Pendo to Content-Security-Policy (CSP) whitelist on Staging

We're running a proof of concept with Pendo, and need to run their script on staging.gitlab.com.

Can you please add https://cdn.pendo.io to the CSP whitelist on Staging?