In more detail
A policy such as default-src 'self' blocks anything loaded from elsewhere, which greatly limits the damage of a cross-site scripting (Cross-site scripting (XSS)) bug because injected scripts cannot run. Policies are usually rolled out in report-only mode first, then enforced.