What
$ hookdeck --hookdeck-config /tmp/c.toml org
Unknown command "--hookdeck-config" for "hookdeck"
The exit code is correct (1) and the command genuinely does not exist, but the name in the message is the flag rather than org. Written the other way round it reports correctly:
$ hookdeck org --hookdeck-config /tmp/c.toml
Unknown command "org" for "hookdeck"
Why it matters
Low severity, but it sends someone looking at their flag instead of their command — and hookdeck org is a command this release removed, so it is a message people will hit.
Also noted during the same pass: connection get "../../etc/passwd" is rejected, but only by the API (422, exit 1, with a noisy level=error log line). The / case has a clean local guard — invalid resource identifier: … contains a path separator — and .. does not.
Found during manual QA of v3.0.0.
What
The exit code is correct (1) and the command genuinely does not exist, but the name in the message is the flag rather than
org. Written the other way round it reports correctly:Why it matters
Low severity, but it sends someone looking at their flag instead of their command — and
hookdeck orgis a command this release removed, so it is a message people will hit.Also noted during the same pass:
connection get "../../etc/passwd"is rejected, but only by the API (422, exit 1, with a noisylevel=errorlog line). The/case has a clean local guard —invalid resource identifier: … contains a path separator— and..does not.Found during manual QA of v3.0.0.