Kaspersky KCS, DevSecOps Optimization·GitHub Actions Error Detection Enhanced
Kaspersky has released a new version of its container security solution 'Kaspersky Container Security (KCS)'. This update focuses on streamlining DevSecOps workflows and enhancing software supply chain security, with a newly included GitHub Actions configuration error detection feature.
Kaspersky unveiled the new KCS version on the 5th.
Key additional features include △custom security policy creation per organization △import and export of entire system configurations △control plane cluster deep audit △GitHub Actions configuration error detection.
Kaspersky stated that the entire lifecycle of containerized applications can be protected in on-premises and isolated network environments.
Enterprises can set and apply their organization-specific security standards alongside the default policies provided.
Custom policies can be created in the areas of image assurance, dynamic admission control (DAC), and security benchmarking, and the company explained that it can rapidly respond to changing compliance requirements.
From a supply chain risk perspective, dedicated rules have been introduced to detect unsafe workflow triggers in GitHub Actions, untrustworthy input handling, and inappropriate version management policies.
Security teams can integrate the KCS scanner into CI/CD workflows or operate it in standalone mode.
This version also includes technical improvements that enhance operational efficiency.
Node agent performance has improved 2.5 times compared to the previous version, and DAC processing speed has become 10 times faster, according to the company.
Additionally, scanned container images can be exported as SBOM (Software Bill of Materials), simplifying integration with vulnerability management tools.
A feature to dynamically update node agents without redeployment has also been added.
Anton Lusakov-Rudenko, Senior Product Marketing Manager for Kaspersky's Cloud and Network Security division, stated: "The GitHub Actions scanning feature detects vulnerabilities directly within configuration code, enabling teams to identify and fix errors at the earliest possible stage. This update bridges the gap between rapid deployment and strict compliance, allowing organizations to protect their infrastructure from the latest cyber threats without operational burden."
Lee Hyo-eun, Country Director of Kaspersky Korea, said: "While container workloads have become commonplace in Korea's manufacturing, fintech, and IT sectors, many enterprises struggle to balance between adopting agile DevOps and maintaining domestic compliance. The enhanced supply chain and control plane monitoring capabilities will address these needs."















