
Security News
GitHub Actions Checkout Now Blocks Risky pull_request_target Checkouts
GitHub Actions checkout now blocks risky pull_request_target checkouts by default to help prevent pwn request supply chain attacks.
Oink links a local package into another project so you can test changes without publishing. Full docs: https://olchyk98.github.io/mt-linking/.
~/.config/oink/link/.pnpm install -g oink0.oink learn.oink (--livereload streams updates).oink in any consumer and it reuses the saved setup.package.json, builds if needed, and copies the output folders.oink forget to clear saved packages.Oink spots common layouts and copies their outputs plus package.json:
rollup.config.mjs): dist, web, libbuild script only): dist, web, libamend, lib, and web/dist): amend, boundaries, lib, dist, webamend + lib): amend, boundaries, libMakefile present): dist, web, libsrc or lib): src, lib--livereload watches the source package, skips .gitignore, and relinks after 200 ms.--debounce <ms> sets a different watch delay.--reprompt reopens the package picker after each run.Open an issue for bugs or ideas. Pull requests are by discussion only.
Created by Oles Odynets, 2025.
FAQs
A smart linker for Mediatool repository
We found that oink0 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
GitHub Actions checkout now blocks risky pull_request_target checkouts by default to help prevent pwn request supply chain attacks.

Product
Socket now supports Custom Roles and Repository Access Permissions so organizations can control who can access specific repositories and actions.

Product
Socket MCP now lets AI assistants review org alerts, investigate threats using the Socket threat feed, and inspect package files in addition to dependency scoring.