Skip to main content

mrva

mrva is a terminal-first approach to CodeQL multi-repo variant analysis. You can download existing CodeQL databases from the GitHub API, run variant analyses, and view results all from your local machine. This tool was inspired by the VSCode CodeQL extension, but instead runs as a standalone CLI tool.

Table of contents:

Installing

Currently mrva must be installed from the git source. If/when it is open sourced we will upload it to PyPI.

To install:

$ git clone https://github.com/trailofbits/mrva.git
$ python -m pip install mrva/
$ mrva -h

Using

mrva has the following command tree:

  • mrva
    • download
      • top
      • org
      • repo
      • query
      • from-file
    • analyze
    • pprint
    • print-ast (experimental)

Using mrva generally requires three steps:

  1. Downloading existing CodeQL databases from the GitHub API
  2. Running CodeQL variant analyses against these databases
  3. Viewing the results

First, ensure you have a codeql binary in your $PATH (releases here).

Next, create a directory to store mrva data:

$ mkdir dbs/

This directory will eventually contain CodeQL databases, tool configuration, SARIF results, and other information mrva needs to operate.

Use the mrva download command to download CodeQL databases:

$ mrva download --token $GITHUB_TOKEN --language ruby dbs/ top --limit 100

[!NOTE] download will automatically use the $GITHUB_TOKEN environment variable if it's available.

This command will download CodeQL databases of the top 100 GitHub Ruby projects (by star count). You can download other databases by specifying a different --language, or using a different download strategy like download org or download repo.

Use the mrva analyze command to analyze the downloaded databases:

$ mrva analyze dbs/ /path/to/queries -- --rerun --threads=0

Any flags included after -- are passed directly to the CodeQL binary.

[!NOTE] mrva recommends using the --threads flag to process multiple queries within a single CodeQL analysis instead of parallelizing multiple CodeQL analyses. This prevents contention between mrva and CodeQL.

Use the mrva pprint command to view analysis results:

$ mrva pprint dbs/

You can also use the pprint command to print raw CodeQL SARIF results:

$ codeql database analyze \
    --format sarif-latest \
    --sarif-add-file-contents \
    --output output.sarif \
    -- db/ query.ql
$ mrva pprint output.sarif

Many of these commands take additional flags to modify their functionality. For example, analyze and pprint take --select and --ignore flags to filter repositories. Use the --help flag to explore all functionality provided by a given command.

Developing

mrva uses poetry for dependency and configuration management.

Before proceeding, install project dependencies with the following command:

$ poetry install --with dev

[!NOTE] When running mrva analyze in the Poetry environment you may need to pass -- to poetry run like poetry run -- mrva analyze. This prevents Poetry from getting confused about which arguments are its arguments, mrva's arguments, and codeql's arguments.

Linting

Lint all project files with the following command:

$ poetry run pre-commit run --all-files

Testing

Run Python tests with the following command:

$ poetry run pytest --cov

Metadata

Release files for mrva 0.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mrva 0.5.0
File Size Uploaded
mrva-0.5.0.tar.gz 25.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mrva 0.5.0
File Interpreter ABI Platform
mrva-0.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 56.0 kB

Release files / mrva-0.5.0.tar.gz

Download URL mrva-0.5.0.tar.gz
Size 25.7 kB
Tags Source
SHA-256 checksum
How to use checksums
216b147141409349541c33253e3fb0b2c38d50853e5dcabdccd795789e61f548
BLAKE2b-256 checksum
How to use checksums
efd6b84196d9d475904cda1d5e237c97840e49d2ff15ee23310ea6537044d243
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 10, 2025.

Transparency log

Release files / mrva-0.5.0-py3-none-any.whl

Download URL mrva-0.5.0-py3-none-any.whl
Size 30.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ace0878cfebae97c6783eb0200f0cee723696c1d075f0194cf1a88bad5c70a22
BLAKE2b-256 checksum
How to use checksums
367762dda67167b57e39fce4d2ae0ba279dcc128bbf8cd9520ca89e7e4b7893b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 10, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.5.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page