Automatically adding URLs to Content Security Policy

What is the best practice to add a URL to the Content Security Policy? We have a module loadable package that needs access to *.googleapis.com. What is the best way to add this to the CSP?