OFICIAL Google Cloud Blog

Strengthen your CI/CD pipeline with new Secure Source Manager capabilities

What happened
Based on Google Cloud Blog · Sep 21, 2026

Google Cloud’s Secure Source Manager now offers new capabilities to strengthen CI/CD pipelines against supply chain threats, including unauthorized access blocking and granular code ownership controls.

Strengthen your CI/CD pipeline with new Secure Source Manager capabilities
Google Cloud Blog — Google
Key points
·
SSM now blocks unauthorized access to CI/CD systems even if corporate networks are compromised
·
Code Owners system enforces per-file and per-branch approval requirements for pull requests
·
Developer Connect integrates SSM with Cloud Build via Private Service Connect in private networks

Google Cloud has introduced two new capabilities for Secure Source Manager (SSM) to help organizations secure their continuous integration and continuous delivery (CI/CD) pipelines against supply chain threats. These features are designed to address risks such as unauthorized access to CI/CD systems and unauthorized changes to code by authorized users. The updates aim to provide unified authentication and authorization mechanisms across source code and CI/CD workflows.

Unauthorized access to CI/CD systems poses a significant risk, as attackers can alter a single deployment script to introduce malware. SSM now blocks such unauthorized access across the entire pipeline, from version control to build, artifact, and deployment tools, even if the corporate network is compromised. This capability enhances the security posture of private cloud environments.

To prevent unauthorized code changes, SSM introduces a Code Owners system that manages pull request approver sets at a per-file and per-branch level. This feature allows teams to define granular identity and access management (IAM) rules, ensuring that specific users or groups must approve changes to critical files or directories. The system supports flexible path specifiers, branch-specific governance, and nestable multi-file ownership.

SSM’s new Developer Connect integration enables secure connections between CI/CD systems and runtimes, even across different private networks. The private CI/CD blueprint architecture uses Private Service Connect to link Secure Source Manager with Cloud Build, with all components residing in a private network protected by VPC Service Controls. A new guide provides instructions for securing these integrations.

Original source → Deals on Clipraptor.com →