How to bypass "Content Security Policy" on a website when injecting JavaScript?

I’m just trying to inject code (safe) into a website. Not trying to hack.

What is the CSP policy? recently there was a ‘self-src’ csp