Code Sight Standard Edition: Application security optimised for the needs of developers
Code Sight Standard Edition helps developers find and fix security issues as they code, without switching tools or interrupting their workflow.
As software development accelerates, organisations increasingly seek ways to improve application security testing. One effective approach is to “shift left” by integrating security testing directly into developer tools and workflows. This strategy not only helps teams address issues faster but also more cost-effectively by catching defects early. On the other hand, problems found during later testing stages or in production often lead to expensive rework.
However, it’s important to note that most developers aren’t security experts. Tools designed for security teams are often complex and disruptive for developers. They typically require leaving the interactive development environment (IDE) to analyse issues and find fixes. Consequently, constantly switching tools reduces productivity. Although developers understand the benefits of checking their code and open-source dependencies, they tend to avoid security tools due to their negative impact on productivity.
Introducing Code Sight Standard Edition
To address these challenges, Black Duck has developed Code Sight. Today, we are pleased to announce the availability of Code Sight Standard Edition (SE). Code Sight SE is a standalone version of the Code Sight IDE plug-in. It works independently of application security testing (AST) tools like Coverity and Black Duck, which are usually part of continuous integration (CI) build and test workflows.
Moreover, Code Sight SE provides fast, lightweight security analysis of source code and open-source dependencies within the IDE. It uses integrated Rapid Scan Static and Rapid Scan SCA. Thus, developers don’t need to be security experts. Code Sight SE offers clear defect descriptions, severity data, and guidance to help them fix issues quickly. It’s also optimised to scan large files and projects in seconds with minimal system impact. Even though it doesn’t require a centralised static application security testing (SAST) or software composition analysis (SCA) solution, Code Sight SE enhances central analysis when used in conjunction with tools like Coverity and Black Duck.
The integration of SAST and SCA within the IDE makes Code Sight SE unique and powerful. Developers want to ensure their software is secure and free from bugs. Whether a vulnerability is in their code or in an open-source dependency, it needs to be fixed. Using separate tools for code and open-source analysis is cumbersome; therefore, Code Sight SE allows developers to address security holistically across the entire codebase.
Furthermore, Code Sight SE is available for Visual Studio Code IDE. It supports Java, JavaScript, and TypeScript. Additionally, supported package managers include Maven and npm. Supported Infrastructure as Code (IaC) platforms and file formats include AWS CloudFormation, ELK, Helm, Kubernetes, and Terraform. Additional language and IDE support is available when using the Code Sight IDE plug-in for Coverity SAST or Black Duck SCA.
VisualStudio Marketplace Code Sight Standard Edition Free Trial
Download the Code Sight Standard Edition brochure here



