Introducing mrva, a terminal-first approach to CodeQL multi-repo variant analysis
infonews
securityresearch
Source: Trail of Bits BlogDecember 11, 2025
Summary
GitHub's CodeQL multi-repository variant analysis (MRVA) lets you run security bug-finding queries across thousands of projects quickly, but it's built mainly for VS Code. A developer created mrva, a terminal-based alternative that runs on your machine and works with command-line tools, letting you download pre-built CodeQL databases (collections of code information), analyze them with queries, and display results in the terminal.
Classification
Attack SophisticationModerate
Original source: https://blog.trailofbits.com/2025/12/11/introducing-mrva-a-terminal-first-approach-to-codeql-multi-repo-variant-analysis/
First tracked: February 12, 2026 at 02:20 PM
Classified by LLM (prompt v3) · confidence: 72%