Google iconGoogleSep 21, 2026 ~1 min source read

Strengthen your CI/CD pipeline with new Secure Source Manager capabilities

A resilient software supply chain is the foundation of modern delivery, and securing your continuous integration and continuous delivery (CI/CD) pipeline is what keeps innovation moving safely. Notable supply chain attacks more than doubled in the first half of 2026 compared to the second half of 2025, according to Wiz's recent Cloud Threat Highlights report.

Strengthen your CI/CD pipeline with new Secure Source Manager capabilities

Share this story

Send the public story page.

Useful takeaways from this story.

A resilient software supply chain is the foundation of modern delivery, and securing your continuous integration and continuous delivery (CI/CD) pipeline is what keeps innovation moving safely.

Notable supply chain attacks more than doubled in the first half of 2026 compared to the second half of 2025, according to Wiz's recent Cloud Threat Highlights report.

It's crucial that your source code not be the weakest link in your private cloud.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

A resilient software supply chain is the foundation of modern delivery, and securing your continuous integration and continuous delivery (CI/CD) pipeline is what keeps innovation moving safely. Notable supply chain attacks more than doubled in the first half of 2026 compared to the second half of 2025, according to Wiz's recent Cloud Threat Highlights report. It's crucial that your source code not be the weakest link in your private cloud.

How it works

  • We now offer two new capabilities, both generally available, that can simplify and secure your development and CI/CD workflows:
  • To help you better address software supply chain threats, Google Cloud Secure Source Manager (SSM) lets you manage your source and CI/CD systems with unified authentication and authorization mechanisms.
  • Attackers only need to alter a single deployment script to turn your CI/CD pipeline into a vehicle for malware.
  • The new Code Owners system manages pull request approver sets at a per-file and per-branch level to help provide more granular identity and access management (IAM).
  • It adds additional guards to files and directories in your repository at a per-file or per-branch level.

Details worth keeping

Code Owners helps engineers who need to write, edit, and review code.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app