1. Resources
  2. /
  3. Blog
  4. /
  5. Shipped this week

Shipped this week

Summary

Try these

  • Let agents retry only infrastructure failures with MCP server v1.25.0, and check GitHub installation API quotas with v1.26.0.
  • Use hashFiles() inside composite action steps with buildkite-gha v0.100.0.
  • Track billable active-user usage through the Buildkite API, and send the count to tools such as Datadog.
  • Manage organization memberships, invitations, roles, and single sign-on (SSO) mode with the Buildkite Terraform provider v1.42.0.
  • Skip commands whose results are already in Buildkite Cache with buildkite-agent cache exec in agent v4.2.1. Agent v4.3.0 can also cache Git Large File Storage (LFS) objects in Git mirrors on the same host with the opt-in --git-mirrors-lfs-cache flag.

Check these

  • Update buildkite-gha to v0.101.1 to pick up Go 1.26.9 fixes for reachable standard-library vulnerabilities.
  • Replace buildkite-gha migrate-secrets with bk secret migrate github-actions before moving to buildkite-gha v0.102.0, or the command fails as unknown.
  • Set BUILDKITE_GHA_TELEMETRY_DISABLED=true if you don't want buildkite-gha to send error reports. From v0.101.0, it reports unexpected CLI failures to Bugsnag by default, and the same variable also turns off completion telemetry.
  • Sign in again from your MCP client if you use the Remote MCP Server, to grant the permissions the new tools need.
  • Switch automation that matches E_ENVIRONMENT for GitHub variable lookup failures to E_VARIABLE_RESOLUTION before moving to buildkite-gha v0.98.0.
  • Add the read_organization_settings scope, plus write_organization_settings to change any attribute other than enforce_2fa, to your Terraform token before moving to provider v1.40.0, or Terraform can no longer manage buildkite_organization.
  • Check pipelines, hooks, plugins, and agent config files for removed agent v3 flags and settings before moving to the Elastic CI Stack for AWS Terraform module v1.0.0. Removed flags make commands fail, and the agent silently ignores removed settings.

So what?

Agents go after the failure that blocks the build

We updated the MCP Server tools so your agent spends its time on the job that stopped the build.

MCP server v1.26.1 treats soft-failed jobs as non-blocking and lower priority, and no longer mistakes broken or dependency-failed jobs for root causes. get_build_failure_summary now lists blocking failures first, so soft-failed jobs stop taking max_jobs slots, and compare_builds reports a change in soft_failed as state_changed rather than a new failure.

v1.25.0 adds retry_failed_jobs, which retries only infrastructure failures, such as expired jobs, lost agents, and stack_error. It skips command failures and soft-failed, canceled, and timed-out jobs, and dry_run: true shows the classification before the tool retries anything. The same release adds a cache_registries toolset, without delete, since deleting a registry also deletes its cache metadata.

v1.26.0 adds a repository_connections toolset. When GitHub-backed work slows down or fails, an agent can now tell whether the GitHub installation API quota ran out, rather than confusing it with the Buildkite API rate limit. These tools require organization administrator access. If you import the server as a Go library, v1.26.1 needs Go 1.26 or later, but prebuilt binaries and container images don't change.

All of these MCP tools are also available in the Remote MCP Server. If you use it, sign in again from your MCP client to grant the permissions the new tools need.

The Buildkite CLI 3.61.0 shows flaky test failures for a job and follows failures recursively into triggered builds, and 3.60.0 adds bk repository-connection commands that show GitHub API rate limits.

Two plugins make failures easier to read and retry. Bedrock Summarize v1.2.0 fixes formatting and shell argument-size failures on large logs, and raises the default timeout, the AWS CLI read timeout for each Bedrock request, from 60 seconds to 1 hour. It doesn't cap the hook's total run time, and retries can make the hook run longer. Artifacts v1.11.0 adds download-failure-exit-status, so automatic retry rules can tell a failed download from a failed command.

Builds triggered by pushes or webhooks have no creator, so the macOS menu bar app filtered out their alerts. It doesn't anymore. 1.0.64 also stops duplicate failure alerts and retries alerts macOS rejects.

Fewer gaps for GitHub Actions workflows on Buildkite

Twelve buildkite-gha releases this week bring composite actions, merge queues, and Windows jobs closer to how they run on GitHub:

  • Lets composite action steps call hashFiles() in v0.100.0, so cache keys such as npm-${{ hashFiles('package-lock.json') }} work as they do on GitHub. As on GitHub, it returns an empty string when no file matches, and composite outputs still cannot call it.
  • Runs merge_group workflows declared with types: [destroyed] in v0.99.0. Hosted builds for destroyed merge groups also need us to turn on a flag for your organization.
  • Checks explicit runner mappings before upload in v0.98.0: each mapped queue must exist in the job's cluster, and a hosted queue must have the OS and architecture the label needs. Imports with explicit mappings now stop before upload when that check is unavailable.
  • Fixes checkout on Windows agents running Git for Windows 2.56.0.windows.1 in v0.99.1. v0.98.2 explains how to map unmapped windows-latest jobs to a Windows Server 2022 x86-64 queue, and v0.101.0 documents those jobs as supported.
  • Retries temporary GITHUB_TOKEN failures in v0.102.1, up to 3 attempts within 45 seconds. v0.98.3 explains what to check when GitHub rejects a workflow-token request.

We removed migrate-secrets in v0.102.0. Use bk secret migrate github-actions from CLI v3.59.1 or later, which keeps the same prepare and run flow and still runs workflows the old command generated. v0.98.0 also reports GitHub variable lookup failures as E_VARIABLE_RESOLUTION instead of E_ENVIRONMENT, so update any automation that matches the old code.

From v0.101.0, buildkite-gha reports unexpected CLI failures to Bugsnag by default. Reports keep stack locations and failure classifications but leave out raw error messages, and ordinary workflow failures, cancellations, and workflow timeouts aren't reported. v0.101.1 also leaves out Buildkite build and job IDs and redacts stack filenames that could expose checkout or build paths. To turn off both error reports and completion telemetry, set BUILDKITE_GHA_TELEMETRY_DISABLED=true.

Track usage and manage access in your own tools

You can now monitor billable active-user usage with the Buildkite API and compare it with your contracted allowance. Send the count to observability tools such as Datadog to track it over time, or use it in license, billing, and compliance reporting.

Three Terraform provider releases cover more of your organization:

  • v1.40.0 adds a buildkite_pipelines data source, team and role filters for organization members, and the remaining GitHub trigger settings for pipelines. It also keeps applied changes when a later operation fails.
  • v1.41.0 adds a cluster cache registry resource and bounds GraphQL calls by your timeout settings.
  • v1.42.0 adds buildkite_organization_membership to manage membership, invitations, role, and SSO mode, and lets you import buildkite_team_member by <team slug>/<email>.

In v1.40.0 we moved allowed_api_ip_addresses to the REST API. That's a breaking change: managing buildkite_organization now needs an API token with the read_organization_settings scope, plus write_organization_settings to change any attribute other than enforce_2fa.

The AWS Assume Role with Web Identity plugin v1.8.0 adds an audience option. With a custom audience, a role's trust policy can require a specific agent.buildkite.com:aud, so a token issued for one role cannot assume another role that trusts the same pipeline. It defaults to sts.amazonaws.com, so existing pipelines need no change. If you set a custom audience, add it to your AWS OIDC identity provider's audience list as well.

Builds skip work they have already done

Agent v4.2.1 adds buildkite-agent cache exec, which skips a command when its result is already cached. It also runs repository hooks from the job's working directory, so monorepos can keep hooks in subdirectories, and shows warnings from Buildkite, such as agent version support notices, at startup and in job logs.

v4.3.0 adds --git-mirrors-lfs-cache, off by default, so checkouts on the same host stop downloading the same Git LFS objects. cache save now skips the upload when the store already has an identical archive. v4.2.0 adds --git-fetch-base-branch, so commands in a job diff against the base branch's current tip.

Elastic CI Stack for AWS v7.3.0 and v7.4.0 bundle agent v4.2.1 and v4.3.0. If you are still on v6, v6.71.6 backports a Linux instance termination fix and keeps agent v3.

The Tests plugin v1.1.0 runs only selected tests through manual-selection-command, which needs the test engine client (bktec) 3.3.0 or later. bktec 3.2.1 moves manual selection to selectors, fails when a selection matches none of the listed files, and shows pool planning and lease activity in bktec pool output.

In monorepos, Monorepo Diff v1.12.0 adds skip_on_no_changes, so steps that depend on unmatched steps can still resolve, and supports the array form for step agents.

The Terraform module for Elastic CI Stack moves to agent v4

If you deploy Elastic CI Stack for AWS with Terraform, module v1.0.0 is a breaking upgrade. It deploys v7 AMIs with agent v4 and removes agent v3 support. Removed agent flags make commands fail, and the agent silently ignores removed environment variables and options.

Read the v1 upgrade guide and the agent v3 to v4 upgrade guide before you upgrade. The module's previous release, v0.13.0, stays on agent v3 with Elastic CI Stack v6.71.5.

Shipped on GitHub

40 releases shipped across 14 public repos in the buildkite and buildkite-plugins GitHub orgs. The list runs newest first. Repos with multiple releases appear in a single row.

DateReleaseSummary
October 9GitHub Actions workflows on Buildkite (buildkite-gha) v0.98.0 to v0.102.1Twelve releases from October 5: hashFiles() in composite actions, merge_group destroyed events, runner mapping checks before upload, Windows checkout fixes, GITHUB_TOKEN retries, and Bugsnag error reports, which are on by default. Breaking: v0.102.0 removes migrate-secrets in favor of bk secret migrate github-actions.
October 9Monorepo Diff plugin v1.12.0Adds skip_on_no_changes to keep unmatched steps' depends_on resolvable, supports the array form for step agents, and adds teams to unblock.
October 9macOS menu bar app 1.0.65 and 1.0.66Ships the app as Buildkite.dmg, isolates account state, retries failed first loads, and warns when the app cannot save credentials to the Keychain. 1.0.66 is a maintenance release that confirms updates from 1.0.65 install correctly.
October 9Elastic CI Stack for AWS v6.71.6Backports the Linux instance termination fallback fix to stack v6, keeping agent v3.
October 8Artifacts plugin v1.11.0Adds download-failure-exit-status, so retry rules can tell artifact download failures from command failures. Defaults to 1.
October 8Bedrock Summarize plugin v1.2.0Fixes response formatting and shell argument-size failures on large logs, and raises the default timeout, the AWS CLI read timeout, from 60 seconds to 1 hour.
October 8MCP server v1.26.1Puts blocking failures ahead of soft-failed and broken jobs in agent guidance, get_build_failure_summary, and compare_builds. Importing the module as a library now needs Go 1.26 or later.
October 8CLI 3.61.0 and 3.61.1Shows flaky test failures for jobs, follows failures into triggered builds, adds a global organization flag, and fixes preflight builds with branch filters.
October 8Buildkite Terraform provider v1.41.0 and v1.42.0Adds a cluster cache registry resource and buildkite_organization_membership, imports team members by <team slug>/<email>, and bounds GraphQL calls by your timeout settings.
October 8Elastic CI Stack for AWS v7.3.0 and v7.4.0Bundles agent v4.2.1 and then v4.3.0, and updates the AWS CLI to v2.37.10.
October 8macOS menu bar app 1.0.64Delivers alerts for push- and webhook-triggered builds, stops duplicate alerts, retries rejected alerts, and keeps the status dot current while the panel is closed.
October 7CLI 3.60.0 and 3.60.1Adds bk repository-connection commands that show GitHub API rate limits, sends custom headers from bk api --headers, and fixes skill installation across filesystems.
October 7Tests plugin v1.1.0Runs only selected tests with manual-selection-command, which requires bktec 3.3.0 or later.
October 7Agent v4.3.0Adds opt-in Git LFS caching in Git mirrors, skips cache save uploads when an identical archive exists, and stops cache invalidation from deleting a freshly saved entry.
October 7Test engine client (bktec) v3.2.1 and v3.3.0Moves manual test selection to selectors and reads them from BUILDKITE_TEST_ENGINE_SELECTION_SELECTORS, fails selections that match no listed files, and shows pool planning and lease activity.
October 7Elastic CI Stack for AWS Terraform module v1.0.0Breaking: deploys stack v7 AMIs with agent v4 and removes agent v3 support. Removed agent flags make commands fail, and the agent silently ignores removed settings. Also updates the agent scaler to 1.15.0.
October 6Agent v4.2.1Adds buildkite-agent cache exec to skip cached commands, runs repository hooks from the job's working directory, and shows Buildkite warnings such as version support notices.
October 6Elastic CI Stack for AWS Terraform module v0.13.0Moves to Elastic CI Stack v6.71.5, which runs agent v3.
October 6Buildkite Terraform provider v1.40.0Adds the buildkite_pipelines data source, member filters, GitHub trigger settings, and cluster tracing settings, and keeps applied changes when a later operation fails. Breaking: managing buildkite_organization needs the read_organization_settings scope, plus write_organization_settings for most changes.
October 5MCP server v1.26.0Adds a repository_connections toolset to list source control connections and check their cached GitHub installation API quota.
October 5Agent v4.2.0Adds --git-fetch-base-branch to fetch the base branch during checkout, so commands diff against its current tip.
October 5AWS Assume Role with Web Identity plugin v1.8.0Adds an audience option for the OpenID Connect (OIDC) token request, so trust policies can require a role-specific audience. Defaults to sts.amazonaws.com, and a custom value must also be in the AWS OIDC identity provider's audience list.
October 4MCP server v1.25.0Adds retry_failed_jobs, which retries only infrastructure failures, and a cache_registries toolset without delete.

Browse the full changelog →


Related posts

Start turning complexity into an advantage

Create an account to get started for free.

Buildkite Pipelines

Platform

  1. Pipelines
  2. Public pipelines
  3. Test Engine
  4. Package Registries
  5. Mobile Delivery Cloud
  6. Pricing

Hosting options

  1. Self-hosted agents
  2. Mac hosted agents
  3. Linux hosted agents

Resources

  1. Docs
  2. Blog
  3. Changelog
  4. Example pipelines
  5. Plugins
  6. Webinars
  7. Case studies
  8. Events
  9. Migration Services
  10. CI/CD perspectives

Company

  1. About
  2. Careers
  3. Press
  4. Security
  5. Brand assets
  6. Contact

Solutions

  1. Replace Jenkins
  2. Workflows for MLOps
  3. Testing at scale
  4. Monorepo mojo
  5. Bazel orchestration

Compare

  1. Buildkite vs GitHub Actions
  2. Buildkite vs Depot

Legal

  1. Terms of Service
  2. Acceptable Use Policy
  3. Privacy Policy
  4. Subprocessors
  5. Service Level Agreement
  6. Supplier Code of Conduct
  7. Modern Slavery Statement

Support

  1. System status
  2. Forum
© Buildkite Pty Ltd 2026