IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
Google Cloud adds tighter code ownership & private CI/CD

Google Cloud adds tighter code ownership & private CI/CD

Tue, 6th Oct 2026 (Yesterday)
Mara Sugue
MARA SUGUE News Editor

Google Cloud has added two generally available features to Secure Source Manager: code ownership controls and private network integration for CI/CD systems.

The updates focus on software supply chain security across development and deployment workflows. They are intended to limit unauthorised access to CI/CD systems and restrict sensitive code changes through more granular approval rules.

One new feature is a Code Owners system for managing pull request approvers at the file and branch level. It adds repository rules for engineers who write, edit and review code, applying extra checks to specific files, directories and branches.

Teams can add CODEOWNERS files to repositories to define required approvers more precisely. The system supports path-based approver sets using glob-style path specifiers, allowing approval rules to be tied to individual files or groups of files.

It also supports branch-specific governance within the same file. That means teams can assign different owners for branches such as main or dev without using separate ownership files, which can create merge conflicts.

Another addition is support for nested CODEOWNERS files in subdirectories. Google Cloud said the model uses a "more local wins" approach, while allowing root-level administrators to retain override authority across the repository.

The feature also includes independent approval sections. With section syntax and approval counts, a pull request can require separate sign-off from more than one group before it can be merged.

Private access

The second update integrates Secure Source Manager with Developer Connect, allowing customers to connect CI/CD systems and runtimes securely when they sit in different private networks.

Google Cloud also outlined a private CI/CD blueprint in which Secure Source Manager connects to Private Service Connect, which then connects to Cloud Build. In that setup, the repository, build pools and artifact storage remain inside a private network.

VPC Service Controls add another layer by limiting access to proxy endpoints. Google Cloud said this arrangement can help block unauthorised access across version control, build, artifact and deployment systems, including when a corporate network has been compromised.

The product changes come as software supply chain attacks continue to draw attention across cloud and enterprise security. Google Cloud cited Wiz research showing that notable supply chain attacks more than doubled in the first half of 2026 compared with the second half of 2025.

Secure Source Manager is Google Cloud's service for managing source code and CI/CD systems under a single authentication and authorisation model. The latest additions extend that approach into approval workflows and network isolation around development pipelines.

For customers using broad IAM approver roles, the Code Owners feature offers a more targeted model by tying review authority to specific paths and branches. In practice, that means a pull request touching deployment scripts, security-sensitive files or particular application areas can be routed to designated reviewers rather than a general approval pool.

Through the private networking model, Google Cloud is positioning Secure Source Manager as part of a more contained software delivery architecture. By keeping source repositories, build infrastructure and stored artifacts inside private environments, organisations can reduce exposure points around code changes and release processes.

The release also reflects a wider shift among cloud providers toward embedding software supply chain controls directly into managed developer tools. Rather than relying only on separate security products, vendors are adding approval policy, identity controls and network restrictions to source management and build services.

Google Cloud said customers can use the private network integration guidance to connect Secure Source Manager to Cloud Build through Developer Connect, and create a root CODEOWNERS file to replace broad IAM approver roles with file-specific ownership.