Code Sight is a lightweight IDE plugin that helps developers identify and fix security risks in code during development. The plugin provides development teams with quality and security risk information for code, open source components, and Infrastructure as Code templates directly within the IDE. Code Sight performs fast application security analysis of source code and open source dependencies using integrated static analysis and software composition analysis capabilities. The plugin provides visibility into security risks in both direct and transitive open source dependencies, enabling developers to select secure components and versions while avoiding incompatible licenses. Code Sight integrates Black Duck Assist, which provides AI-driven summaries, step-by-step code analyses, and suggested fixes for resolving issues. The plugin automatically scans code in real time as it is written by developers or generated by AI coding assistants. Code Sight uses scan engines that can analyze large projects quickly in the background with minimal system impact, performing security analysis scans on large files and projects in seconds. The plugin addresses security issues early in the development cycle, reducing downstream rework and preventing undetected vulnerabilities from reaching production. Code Sight is available for widely used IDEs including Visual Studio Code, IntelliJ, Eclipse, and AI code editors such as Cursor and Windsurf.