← The Dino Dispatch
Featurev1.2.1

When Dino stops, it tells you whose problem it is

September 29, 2026

A black operator sorts returned envelopes into cubbies marked 2 usage and 5 config, leaving the 70 cubby nearly empty

A mistake in your command or config now exits 2 or 5 with what to fix, never "Dino crashed". Tenant auth reaches every probe, a bad credential stops the scan instead of becoming a finding, and Dino reports fewer false findings.

Exit codes you can script against

Dino 1.2.1 is the first release of the 1.2 line. (1.2.0 was never published: its release stopped at a pre-release check before anything shipped.)

When a Dino run stops, the exit code now says whose problem it is:

  • 2 means the command itself was wrong: a missing flag, or a value Dino can't use.
  • 5 means your configuration or credentials need attention.
  • 4 means your API or an upstream service couldn't be reached, so a retry may work.
  • 70 is reserved for a genuine bug in Dino.

Before, many ordinary mistakes (a malformed endpoint, a broken operations file, an empty tool selection) ended as 70, "Dino crashed". Every failure now declares its outcome, and the message on screen and the JSON error on stderr always say the same thing.

If your CI treats any non-zero exit the same way, nothing changes for you. If you matched on 70, look for 2 and 5 instead.

Tenant authentication you can rely on

  • The jwt adapter signs its own token. Before, it sent an empty request to your API and never authenticated.
  • Input fuzzing, response validation and rate-limit probes on GraphQL now carry your tenant's token. The one probe that must be anonymous is marked anonymous on purpose.
  • A rejected or unreachable OAuth2 credential stops the scan: exit 5 when the provider rejects it, exit 4 when the provider is down. It no longer shows up as a finding against your API.
  • auth.enabled: true with a tenant that has no auth adapter is refused before any request, with exit 5.
A black operator threads one key on a long string through a row of doors, skipping the one marked anonymous on purpose
One key, every door, except the one that's meant to stay open.

Fewer false findings

Dino no longer reports a finding from a request it couldn't send correctly. When an operation needs a query parameter or a request body Dino can't supply, the error-code validator, rate-limit check and response validator report it as not tested, instead of blaming your API for rejecting an incomplete request.

A leak pattern also no longer matches across two unrelated error messages.

A black operator catches its own half-packed parcel before it lands on the findings pile and drops it in the not tested tray
If Dino packed it wrong, it isn't your finding.

Also in 1.2.1

  • A file named in your configuration can't be read through a symlink that points outside its directory.
  • dino verify, dino whoami and dino runner register no longer mark a failed request as retryable when retrying can't help.
  • dino schema says where --format json output goes: the result on stdout, errors on stderr.

Update with brew upgrade dino, npm install -g @dino-hq/cli@latest, or by running the installer again.