Policies in GitLab provide security teams a way to require scans of their choice to be run whenever a project pipeline runs according to the configuration specified. Security teams can therefore be confident that the scans they set up have not been changed, altered, or disabled.
Read more about it in our docs: https://docs.gitlab.com/ee/user/appli...