---
title: "Shipped this week"
date: "2026-10-09"
author: "Matt Mejia"
description: "What Buildkite shipped from October 2 to 9: MCP server v1.26, billable usage in the API, agent v4.3.0, GitHub Actions fixes, and Terraform memberships."
tags: "Test Engine, Plugin, AI, Infrastructure, Pipelines"
---

# Shipped this week

Buildkite shipped MCP server tools that put blocking failures first and retry only infrastructure failures, closer GitHub Actions compatibility, and billable active-user usage in the Buildkite API between October 2 and October 9, 2026. Platform teams can now manage organization memberships in Terraform, give each AWS role its own OpenID Connect (OIDC) audience, and move the Elastic CI Stack for AWS Terraform module to agent v4. Agent v4.2.1 and v4.3.0 also skip cached commands and cache Git Large File Storage (LFS) objects, and the Tests plugin v1.1.0 adds manual test selection.

<h2>Summary</h2><div>**Try these**

- Let agents retry only infrastructure failures with [MCP server](https://buildkite.com/docs/apis/mcp-server) v1.25.0, and check GitHub installation API quotas with v1.26.0.
- Use `hashFiles()` inside composite action steps with [buildkite-gha](https://buildkite.com/docs/pipelines/migration/run-github-actions-workflows) v0.100.0.
- Track [billable active-user usage](https://buildkite.com/resources/changelog/419-monitor-billable-active-user-usage-with-the-buildkite-api/) through the Buildkite API, and send the count to tools such as Datadog.
- Manage organization memberships, invitations, roles, and single sign-on (SSO) mode with the [Buildkite Terraform provider](https://buildkite.com/docs/platform/terraform-provider) v1.42.0.
- Skip commands whose results are already in [Buildkite Cache](https://buildkite.com/docs/pipelines/configure/cache) with `buildkite-agent cache exec` in agent v4.2.1. Agent v4.3.0 can also cache Git Large File Storage (LFS) objects in Git mirrors on the same host with the opt-in `--git-mirrors-lfs-cache` flag.

**Check these**

- Update [buildkite-gha](https://buildkite.com/docs/pipelines/migration/run-github-actions-workflows) to v0.101.1 to pick up Go 1.26.9 fixes for reachable standard-library vulnerabilities.
- Replace `buildkite-gha migrate-secrets` with [`bk secret migrate github-actions`](https://buildkite.com/docs/pipelines/migration/github-actions-secrets) before moving to buildkite-gha v0.102.0, or the command fails as unknown.
- Set `BUILDKITE_GHA_TELEMETRY_DISABLED=true` if you don't want [buildkite-gha](https://buildkite.com/docs/pipelines/migration/run-github-actions-workflows) to send error reports. From v0.101.0, it reports unexpected CLI failures to Bugsnag by default, and the same variable also turns off completion telemetry.
- Sign in again from your MCP client if you use the [Remote MCP Server](https://buildkite.com/docs/apis/mcp-server), to grant the permissions the new tools need.
- Switch automation that matches `E_ENVIRONMENT` for GitHub variable lookup failures to `E_VARIABLE_RESOLUTION` before moving to [buildkite-gha](https://buildkite.com/docs/pipelines/migration/run-github-actions-workflows) v0.98.0.
- Add the `read_organization_settings` scope, plus `write_organization_settings` to change any attribute other than `enforce_2fa`, to your Terraform token before moving to provider v1.40.0, or Terraform can no longer [manage `buildkite_organization`](https://buildkite.com/docs/platform/terraform-provider/manage-buildkite-organizations).
- Check pipelines, hooks, plugins, and agent config files for removed agent v3 flags and settings before moving to the [Elastic CI Stack for AWS Terraform module](https://buildkite.com/docs/agent/self-hosted/aws/elastic-ci-stack/ec2-linux-and-windows/terraform) v1.0.0. Removed flags make commands fail, and the agent silently ignores removed settings.</div><h2><strong>So what?</strong></h2><p></p><h3><strong>Agents go after the failure that blocks the build</strong></h3><div>We updated the [MCP Server tools](https://buildkite.com/resources/changelog/420-buildkite-mcp-server-updates/) so your agent spends its time on the job that stopped the build.

MCP server [v1.26.1](https://github.com/buildkite/buildkite-mcp-server/releases/tag/v1.26.1) treats soft-failed jobs as non-blocking and lower priority, and no longer mistakes `broken` or dependency-failed jobs for root causes. `get_build_failure_summary` now lists blocking failures first, so soft-failed jobs stop taking `max_jobs` slots, and `compare_builds` reports a change in `soft_failed` as `state_changed` rather than a new failure.

[v1.25.0](https://github.com/buildkite/buildkite-mcp-server/releases/tag/v1.25.0) adds `retry_failed_jobs`, which retries only infrastructure failures, such as expired jobs, lost agents, and `stack_error`. It skips command failures and soft-failed, canceled, and timed-out jobs, and `dry_run: true` shows the classification before the tool retries anything. The same release adds a `cache_registries` toolset, without delete, since deleting a registry also deletes its cache metadata.

[v1.26.0](https://github.com/buildkite/buildkite-mcp-server/releases/tag/v1.26.0) adds a `repository_connections` toolset. When GitHub-backed work slows down or fails, an agent can now tell whether the GitHub installation API quota ran out, rather than confusing it with the Buildkite API rate limit. These tools require organization administrator access. If you import the server as a Go library, v1.26.1 needs Go 1.26 or later, but prebuilt binaries and container images don't change.

All of these MCP tools are also available in the Remote MCP Server. If you use it, sign in again from your MCP client to grant the permissions the new tools need.

The Buildkite CLI [3.61.0](https://github.com/buildkite/cli/releases/tag/v3.61.0) shows flaky test failures for a job and follows failures recursively into triggered builds, and [3.60.0](https://github.com/buildkite/cli/releases/tag/v3.60.0) adds `bk repository-connection` commands that show GitHub API rate limits.

Two plugins make failures easier to read and retry. Bedrock Summarize [v1.2.0](https://github.com/buildkite-plugins/bedrock-summarize-buildkite-plugin/releases/tag/v1.2.0) fixes formatting and shell argument-size failures on large logs, and raises the default `timeout`, the AWS CLI read timeout for each Bedrock request, from 60 seconds to 1 hour. It doesn't cap the hook's total run time, and retries can make the hook run longer. Artifacts [v1.11.0](https://github.com/buildkite-plugins/artifacts-buildkite-plugin/releases/tag/v1.11.0) adds `download-failure-exit-status`, so automatic retry rules can tell a failed download from a failed command.

Builds triggered by pushes or webhooks have no creator, so the macOS menu bar app filtered out their alerts. It doesn't anymore. [1.0.64](https://github.com/buildkite/macmenubarapp-releases/releases/tag/v1.0.64) also stops duplicate failure alerts and retries alerts macOS rejects.
</div><h3><strong>Fewer gaps for GitHub Actions workflows on Buildkite</strong></h3><div>Twelve [buildkite-gha releases](https://github.com/buildkite/buildkite-gha/releases) this week bring composite actions, merge queues, and Windows jobs closer to how they run on GitHub:

- Lets composite action steps call `hashFiles()` in [v0.100.0](https://github.com/buildkite/buildkite-gha/releases/tag/v0.100.0), so cache keys such as `npm-${{ hashFiles('package-lock.json') }}` work as they do on GitHub. As on GitHub, it returns an empty string when no file matches, and composite `outputs` still cannot call it.
- Runs `merge_group` workflows declared with `types: [destroyed]` in [v0.99.0](https://github.com/buildkite/buildkite-gha/releases/tag/v0.99.0). Hosted builds for destroyed merge groups also need us to turn on a flag for your organization.
- Checks explicit runner mappings before upload in [v0.98.0](https://github.com/buildkite/buildkite-gha/releases/tag/v0.98.0): each mapped queue must exist in the job's cluster, and a hosted queue must have the OS and architecture the label needs. Imports with explicit mappings now stop before upload when that check is unavailable.
- Fixes checkout on Windows agents running Git for Windows 2.56.0.windows.1 in [v0.99.1](https://github.com/buildkite/buildkite-gha/releases/tag/v0.99.1). [v0.98.2](https://github.com/buildkite/buildkite-gha/releases/tag/v0.98.2) explains how to map unmapped `windows-latest` jobs to a Windows Server 2022 x86-64 queue, and [v0.101.0](https://github.com/buildkite/buildkite-gha/releases/tag/v0.101.0) documents those jobs as supported.
- Retries temporary `GITHUB_TOKEN` failures in [v0.102.1](https://github.com/buildkite/buildkite-gha/releases/tag/v0.102.1), up to 3 attempts within 45 seconds. [v0.98.3](https://github.com/buildkite/buildkite-gha/releases/tag/v0.98.3) explains what to check when GitHub rejects a workflow-token request.

We removed `migrate-secrets` in [v0.102.0](https://github.com/buildkite/buildkite-gha/releases/tag/v0.102.0). Use `bk secret migrate github-actions` from CLI v3.59.1 or later, which keeps the same `prepare` and `run` flow and still runs workflows the old command generated. v0.98.0 also reports GitHub variable lookup failures as `E_VARIABLE_RESOLUTION` instead of `E_ENVIRONMENT`, so update any automation that matches the old code.

From [v0.101.0](https://github.com/buildkite/buildkite-gha/releases/tag/v0.101.0), buildkite-gha reports unexpected CLI failures to Bugsnag by default. Reports keep stack locations and failure classifications but leave out raw error messages, and ordinary workflow failures, cancellations, and workflow timeouts aren't reported. [v0.101.1](https://github.com/buildkite/buildkite-gha/releases/tag/v0.101.1) also leaves out Buildkite build and job IDs and redacts stack filenames that could expose checkout or build paths. To turn off both error reports and completion telemetry, set `BUILDKITE_GHA_TELEMETRY_DISABLED=true`.</div><h3><strong>Track usage and manage access in your own tools</strong></h3><div>You can now [monitor billable active-user usage with the Buildkite API](https://buildkite.com/resources/changelog/419-monitor-billable-active-user-usage-with-the-buildkite-api/) and compare it with your contracted allowance. Send the count to observability tools such as Datadog to track it over time, or use it in license, billing, and compliance reporting.

Three Terraform provider releases cover more of your organization:

- [v1.40.0](https://github.com/buildkite/terraform-provider-buildkite/releases/tag/v1.40.0) adds a `buildkite_pipelines` data source, `team` and `role` filters for organization members, and the remaining GitHub trigger settings for pipelines. It also keeps applied changes when a later operation fails.
- [v1.41.0](https://github.com/buildkite/terraform-provider-buildkite/releases/tag/v1.41.0) adds a cluster cache registry resource and bounds GraphQL calls by your timeout settings.
- [v1.42.0](https://github.com/buildkite/terraform-provider-buildkite/releases/tag/v1.42.0) adds `buildkite_organization_membership` to manage membership, invitations, role, and SSO mode, and lets you import `buildkite_team_member` by `<team slug>/<email>`.

In v1.40.0 we moved `allowed_api_ip_addresses` to the REST API. That's a breaking change: managing `buildkite_organization` now needs an API token with the `read_organization_settings` scope, plus `write_organization_settings` to change any attribute other than `enforce_2fa`.

The AWS Assume Role with Web Identity plugin [v1.8.0](https://github.com/buildkite-plugins/aws-assume-role-with-web-identity-buildkite-plugin/releases/tag/v1.8.0) adds an `audience` option. With a custom audience, a role's trust policy can require a specific `agent.buildkite.com:aud`, so a token issued for one role cannot assume another role that trusts the same pipeline. It defaults to `sts.amazonaws.com`, so existing pipelines need no change. If you set a custom audience, add it to your AWS OIDC identity provider's audience list as well.</div><h3><strong>Builds skip work they have already done</strong></h3><div>Agent [v4.2.1](https://github.com/buildkite/agent/releases/tag/v4.2.1) adds `buildkite-agent cache exec`, which skips a command when its result is already cached. It also runs repository hooks from the job's working directory, so monorepos can keep hooks in subdirectories, and shows warnings from Buildkite, such as agent version support notices, at startup and in job logs.

[v4.3.0](https://github.com/buildkite/agent/releases/tag/v4.3.0) adds `--git-mirrors-lfs-cache`, off by default, so checkouts on the same host stop downloading the same Git LFS objects. `cache save` now skips the upload when the store already has an identical archive. [v4.2.0](https://github.com/buildkite/agent/releases/tag/v4.2.0) adds `--git-fetch-base-branch`, so commands in a job diff against the base branch's current tip.

Elastic CI Stack for AWS [v7.3.0](https://github.com/buildkite/elastic-ci-stack-for-aws/releases/tag/v7.3.0) and [v7.4.0](https://github.com/buildkite/elastic-ci-stack-for-aws/releases/tag/v7.4.0) bundle agent v4.2.1 and v4.3.0. If you are still on v6, [v6.71.6](https://github.com/buildkite/elastic-ci-stack-for-aws/releases/tag/v6.71.6) backports a Linux instance termination fix and keeps agent v3.

The Tests plugin [v1.1.0](https://github.com/buildkite-plugins/tests-buildkite-plugin/releases/tag/v1.1.0) runs only selected tests through `manual-selection-command`, which needs the test engine client (bktec) [3.3.0](https://github.com/buildkite/test-engine-client/releases/tag/v3.3.0) or later. bktec [3.2.1](https://github.com/buildkite/test-engine-client/releases/tag/v3.2.1) moves manual selection to selectors, fails when a selection matches none of the listed files, and shows pool planning and lease activity in `bktec pool` output.

In monorepos, Monorepo Diff [v1.12.0](https://github.com/buildkite-plugins/monorepo-diff-buildkite-plugin/releases/tag/v1.12.0) adds `skip_on_no_changes`, so steps that depend on unmatched steps can still resolve, and supports the array form for step agents.
</div><h3><strong>The Terraform module for Elastic CI Stack moves to agent v4</strong></h3><div>If you deploy Elastic CI Stack for AWS with Terraform, module [v1.0.0](https://github.com/buildkite/terraform-buildkite-elastic-ci-stack-for-aws/releases/tag/v1.0.0) is a breaking upgrade. It deploys v7 AMIs with agent v4 and removes agent v3 support. Removed agent flags make commands fail, and the agent silently ignores removed environment variables and options.

Read the [v1 upgrade guide](https://github.com/buildkite/terraform-buildkite-elastic-ci-stack-for-aws/blob/main/docs/upgrading-to-v1.md) and the [agent v3 to v4 upgrade guide](https://buildkite.com/docs/agent/v3-v4-upgrade-guide) before you upgrade. The module's previous release, [v0.13.0](https://github.com/buildkite/terraform-buildkite-elastic-ci-stack-for-aws/releases/tag/v0.13.0), stays on agent v3 with Elastic CI Stack v6.71.5.</div><h2><strong>Shipped on GitHub</strong></h2><div>40 releases shipped across 14 public repos in the [buildkite](https://github.com/buildkite) and [buildkite-plugins](https://github.com/buildkite-plugins) GitHub orgs. The list runs newest first. Repos with multiple releases appear in a single row.

| Date | Release | Summary |
| --- | --- | --- |
| October 9 | [GitHub Actions workflows on Buildkite (buildkite-gha) v0.98.0 to v0.102.1](https://github.com/buildkite/buildkite-gha/releases) | Twelve releases from October 5: `hashFiles()` in composite actions, `merge_group` destroyed events, runner mapping checks before upload, Windows checkout fixes, `GITHUB_TOKEN` retries, and Bugsnag error reports, which are on by default. Breaking: v0.102.0 removes `migrate-secrets` in favor of `bk secret migrate github-actions`. |
| October 9 | [Monorepo Diff plugin v1.12.0](https://github.com/buildkite-plugins/monorepo-diff-buildkite-plugin/releases/tag/v1.12.0) | Adds `skip_on_no_changes` to keep unmatched steps' `depends_on` resolvable, supports the array form for step agents, and adds teams to unblock. |
| October 9 | [macOS menu bar app 1.0.65 and 1.0.66](https://github.com/buildkite/macmenubarapp-releases/releases/tag/v1.0.66) | Ships the app as `Buildkite.dmg`, isolates account state, retries failed first loads, and warns when the app cannot save credentials to the Keychain. 1.0.66 is a maintenance release that confirms updates from 1.0.65 install correctly. |
| October 9 | [Elastic CI Stack for AWS v6.71.6](https://github.com/buildkite/elastic-ci-stack-for-aws/releases/tag/v6.71.6) | Backports the Linux instance termination fallback fix to stack v6, keeping agent v3. |
| October 8 | [Artifacts plugin v1.11.0](https://github.com/buildkite-plugins/artifacts-buildkite-plugin/releases/tag/v1.11.0) | Adds `download-failure-exit-status`, so retry rules can tell artifact download failures from command failures. Defaults to `1`. |
| October 8 | [Bedrock Summarize plugin v1.2.0](https://github.com/buildkite-plugins/bedrock-summarize-buildkite-plugin/releases/tag/v1.2.0) | Fixes response formatting and shell argument-size failures on large logs, and raises the default `timeout`, the AWS CLI read timeout, from 60 seconds to 1 hour. |
| October 8 | [MCP server v1.26.1](https://github.com/buildkite/buildkite-mcp-server/releases/tag/v1.26.1) | Puts blocking failures ahead of soft-failed and broken jobs in agent guidance, `get_build_failure_summary`, and `compare_builds`. Importing the module as a library now needs Go 1.26 or later. |
| October 8 | [CLI 3.61.0 and 3.61.1](https://github.com/buildkite/cli/releases/tag/v3.61.1) | Shows flaky test failures for jobs, follows failures into triggered builds, adds a global organization flag, and fixes preflight builds with branch filters. |
| October 8 | [Buildkite Terraform provider v1.41.0 and v1.42.0](https://github.com/buildkite/terraform-provider-buildkite/releases/tag/v1.42.0) | Adds a cluster cache registry resource and `buildkite_organization_membership`, imports team members by `<team slug>/<email>`, and bounds GraphQL calls by your timeout settings. |
| October 8 | [Elastic CI Stack for AWS v7.3.0 and v7.4.0](https://github.com/buildkite/elastic-ci-stack-for-aws/releases/tag/v7.4.0) | Bundles agent v4.2.1 and then v4.3.0, and updates the AWS CLI to v2.37.10. |
| October 8 | [macOS menu bar app 1.0.64](https://github.com/buildkite/macmenubarapp-releases/releases/tag/v1.0.64) | Delivers alerts for push- and webhook-triggered builds, stops duplicate alerts, retries rejected alerts, and keeps the status dot current while the panel is closed. |
| October 7 | [CLI 3.60.0 and 3.60.1](https://github.com/buildkite/cli/releases/tag/v3.60.1) | Adds `bk repository-connection` commands that show GitHub API rate limits, sends custom headers from `bk api --headers`, and fixes skill installation across filesystems. |
| October 7 | [Tests plugin v1.1.0](https://github.com/buildkite-plugins/tests-buildkite-plugin/releases/tag/v1.1.0) | Runs only selected tests with `manual-selection-command`, which requires bktec 3.3.0 or later. |
| October 7 | [Agent v4.3.0](https://github.com/buildkite/agent/releases/tag/v4.3.0) | Adds opt-in Git LFS caching in Git mirrors, skips `cache save` uploads when an identical archive exists, and stops cache invalidation from deleting a freshly saved entry. |
| October 7 | [Test engine client (bktec) v3.2.1 and v3.3.0](https://github.com/buildkite/test-engine-client/releases/tag/v3.3.0) | Moves manual test selection to selectors and reads them from `BUILDKITE_TEST_ENGINE_SELECTION_SELECTORS`, fails selections that match no listed files, and shows pool planning and lease activity. |
| October 7 | [Elastic CI Stack for AWS Terraform module v1.0.0](https://github.com/buildkite/terraform-buildkite-elastic-ci-stack-for-aws/releases/tag/v1.0.0) | Breaking: deploys stack v7 AMIs with agent v4 and removes agent v3 support. Removed agent flags make commands fail, and the agent silently ignores removed settings. Also updates the agent scaler to 1.15.0. |
| October 6 | [Agent v4.2.1](https://github.com/buildkite/agent/releases/tag/v4.2.1) | Adds `buildkite-agent cache exec` to skip cached commands, runs repository hooks from the job's working directory, and shows Buildkite warnings such as version support notices. |
| October 6 | [Elastic CI Stack for AWS Terraform module v0.13.0](https://github.com/buildkite/terraform-buildkite-elastic-ci-stack-for-aws/releases/tag/v0.13.0) | Moves to Elastic CI Stack v6.71.5, which runs agent v3. |
| October 6 | [Buildkite Terraform provider v1.40.0](https://github.com/buildkite/terraform-provider-buildkite/releases/tag/v1.40.0) | Adds the `buildkite_pipelines` data source, member filters, GitHub trigger settings, and cluster tracing settings, and keeps applied changes when a later operation fails. Breaking: managing `buildkite_organization` needs the `read_organization_settings` scope, plus `write_organization_settings` for most changes. |
| October 5 | [MCP server v1.26.0](https://github.com/buildkite/buildkite-mcp-server/releases/tag/v1.26.0) | Adds a `repository_connections` toolset to list source control connections and check their cached GitHub installation API quota. |
| October 5 | [Agent v4.2.0](https://github.com/buildkite/agent/releases/tag/v4.2.0) | Adds `--git-fetch-base-branch` to fetch the base branch during checkout, so commands diff against its current tip. |
| October 5 | [AWS Assume Role with Web Identity plugin v1.8.0](https://github.com/buildkite-plugins/aws-assume-role-with-web-identity-buildkite-plugin/releases/tag/v1.8.0) | Adds an `audience` option for the OpenID Connect (OIDC) token request, so trust policies can require a role-specific audience. Defaults to `sts.amazonaws.com`, and a custom value must also be in the AWS OIDC identity provider's audience list. |
| October 4 | [MCP server v1.25.0](https://github.com/buildkite/buildkite-mcp-server/releases/tag/v1.25.0) | Adds `retry_failed_jobs`, which retries only infrastructure failures, and a `cache_registries` toolset without delete. |</div><h2><strong>Related Updates</strong></h2><div>- [Monitor billable active-user usage with the Buildkite API](https://buildkite.com/resources/changelog/419-monitor-billable-active-user-usage-with-the-buildkite-api/)
- [Buildkite MCP Server updates](https://buildkite.com/resources/changelog/420-buildkite-mcp-server-updates/)

[Browse the full changelog →](https://buildkite.com/resources/changelog/)</div><p></p>