---
title: "What we shipped last week"
date: "2026-10-02"
author: "Matt Mejia"
description: "Everything Buildkite shipped from September 27 to October 3: pipeline secrets, MCP server v1.24, agent v4.1.0, GitHub Actions arm64, and shared test pools."
tags: "Changelog, Pipelines, Test Engine, Plugin"
---

# What we shipped last week

Everything Buildkite shipped from September 27 to October 3: pipeline secrets, MCP server v1.24, agent v4.1.0, GitHub Actions arm64, and shared test pools.

<h2>Summary </h2><p>Between September 27 and October 3, 2026, we published 4 changelog entries and 35 releases across 13 public repos. Three things run through them: more control and predictability for platform teams, fewer gaps for teams moving off GitHub Actions, and more of the platform agents can drive directly.</p><ul><li><p><strong>Tightened how secrets are handled</strong>. Pipeline-scoped secrets live in pipeline settings, the Buildkite CLI (<code>bk</code>) migrates GitHub Actions secrets, and the agent now redacts anything shaped like a Buildkite-issued token from job logs. Captured errors redact the secrets registered for that job.</p></li><li><p><strong>Expanded what agents can do</strong>. The MCP server added pipeline validation, build comparison, test execution traces, and webhook repair, and each Remote MCP connection now pins to an organization.</p></li><li><p><strong>Steadied build environments</strong>. Agent v4.1.0 reports cache timings and adds commit, pull request, and author attributes to OpenTelemetry spans. Elastic CI Stack for AWS replaces instances whose agent stops responding, the Kubernetes stack completes its move to agent v4, and the agent scaler stops duplicate scale-ins. New RSS feeds announce macOS base image releases on hosted agents. All v3 agent support ends September 3, 2027.</p></li><li><p><strong>Closed more gaps in GitHub Actions workflows on Buildkite</strong>. Fourteen releases added a Linux arm64 runtime and broader support for vars, secrets, matrix values, and strategy expressions.</p></li><li><p><strong>Moved test splitting toward shared pools</strong>. The Buildkite test engine client (`bktec`) 3.2.0 adds commands to plan and run tests from shared scheduler pools, with persistent runners and dynamic parallelism.</p></li></ul><p></p><h2>Changelog entries</h2><p>Dates are US Pacific time.</p><div>| Date | Entry | Summary |
| --- | --- | --- |
| October 1 | [Get notified about new macOS base image releases](https://buildkite.com/resources/changelog/417-get-notified-about-new-macos-base-image-releases/) | Subscribe to RSS feeds for macOS base image releases on Buildkite hosted agents. Separate stable and canary feeds cover production images and the latest Xcode betas. |
| September 30 | [Choose the organization for each Remote MCP Server connection](https://buildkite.com/resources/changelog/416-choose-the-organization-for-each-remote-mcp-server-connection/) | Add `?organization=<slug>` to the Remote MCP Server URL, including toolset and read-only URLs, to pin each connection to one Buildkite organization. Authorization then preselects it. |
| September 30 | [Buildkite agent version support policy](https://buildkite.com/resources/changelog/415-buildkite-agent-version-support-policy/) | From January 1, 2027, we support each agent minor release line for 1 year from its first stable release, with the last 3 months deprecated. v3.115.x and earlier go unsupported that day, and all v3 support ends September 3, 2027. |
| September 28 | [Manage secrets from pipeline settings](https://buildkite.com/resources/changelog/414-manage-secrets-from-pipeline-settings/) | Anyone who can edit a pipeline and manage its cluster can now create pipeline-restricted secrets in Pipeline settings → Secrets. Conditions cover branch, queue, build source, or creator, and cluster settings show lock indicators. |</div><h2>What does this mean for you</h2><div>### Secrets move closer to the pipeline

If you can edit a pipeline and manage its cluster, you can now create and manage secrets from [Pipeline settings → Secrets](https://buildkite.com/resources/changelog/414-manage-secrets-from-pipeline-settings/). Pipeline secrets are cluster secrets restricted to the current pipeline, and branch, queue, build source, or creator conditions narrow access further. Values stay hidden after creation.

The new view keeps pipeline-specific secrets together, shows how many others the cluster manages, and links through to the cluster's secrets page, where restricted secrets now carry a lock indicator. GitHub Actions pipelines get a dismissible prompt pointing at secrets setup before the first workflow runs.

The Buildkite CLI [3.59.0](https://github.com/buildkite/cli/releases/tag/v3.59.0) adds a command to migrate GitHub Actions secrets, and [3.59.1](https://github.com/buildkite/cli/releases/tag/v3.59.1) fixes relative workflow paths when you do.

### Agents get the moves an engineer would make

Log access alone does not debug a build. MCP server [v1.23.0](https://github.com/buildkite/buildkite-mcp-server/releases/tag/v1.23.0) adds `validate_pipeline` to check pipeline YAML against the official schema before upload, `compare_builds` to diff a failing build against an earlier success, and Test Engine execution traces with slowest-execution lookups.

[v1.24.0](https://github.com/buildkite/buildkite-mcp-server/releases/tag/v1.24.0) adds `create_pipeline_webhook`, so an agent can repair a pipeline created without its GitHub webhook instead of recreating it. Both releases sharpen failure summaries.

One v1.23.0 default hid jobs that never ran, and v1.24.0 reversed it after eval runs showed the opt-in forced extra tool calls. Measure, then decide.

v1.23.0 carries one breaking change: `create_pipeline` now requires `create_webhook`.

If your agents work across more than one organization, add `?organization=your-organization` to the [Remote MCP Server URL](https://buildkite.com/resources/changelog/416-choose-the-organization-for-each-remote-mcp-server-connection/). The authorization page then preselects it. It works with toolset and read-only URLs, and leaving it off changes nothing.

### GitHub Actions workflows on Buildkite

Fourteen [buildkite-gha releases](https://github.com/buildkite/buildkite-gha/releases) this week:

- Publishes a Linux arm64 runtime in [v0.97.0](https://github.com/buildkite/buildkite-gha/releases/tag/v0.97.0), so the importer and generated jobs run on arm64 agents. Labels such as `ubuntu-24.04-arm` need an explicit queue mapping, and they never fall back to x86-64 or emulation.
- Resolves job environment values, named secrets, runtime `vars`, and matrix values in service container `env` and `credentials`, across [v0.94.0](https://github.com/buildkite/buildkite-gha/releases/tag/v0.94.0), [v0.95.0](https://github.com/buildkite/buildkite-gha/releases/tag/v0.95.0), and [v0.96.0](https://github.com/buildkite/buildkite-gha/releases/tag/v0.96.0).
- Exposes `strategy.job-index`, `job-total`, `fail-fast`, and `max-parallel` in job and step expressions in [v0.93.0](https://github.com/buildkite/buildkite-gha/releases/tag/v0.93.0). `fail-fast` reports its configured value but still does not cancel sibling matrix jobs.
- Ignores branch, tag, and path filters on ten event families in [v0.93.1](https://github.com/buildkite/buildkite-gha/releases/tag/v0.93.1), matching GitHub's behavior.
- Raises the changed-file limit from 300 to 3,000 in [v0.97.2](https://github.com/buildkite/buildkite-gha/releases/tag/v0.97.2), and fixes path-filtered `push` workflows that failed when the branch advanced after the push.

You pick these up through the [GitHub Actions Buildkite plugin](https://github.com/buildkite-plugins/github-actions-buildkite-plugin), which installs and verifies the selected CLI release and defaults to the latest stable one. Every release ships with upgrade notes that say exactly what is still unsupported.

### Four agent releases, and a clock on v3

Agent [v4.1.0](https://github.com/buildkite/agent/releases/tag/v4.1.0) reports cache save and restore timings and sizes back to Buildkite, carries commit, pull request, and build author as OpenTelemetry job span attributes, and fixes intermittent Windows crashes. [v4.0.9](https://github.com/buildkite/agent/releases/tag/v4.0.9) redacts Buildkite tokens by prefix in job logs, [v4.0.8](https://github.com/buildkite/agent/releases/tag/v4.0.8) redacts captured job errors using the job's registered secrets, and [v4.0.7](https://github.com/buildkite/agent/releases/tag/v4.0.7) surfaces cache restore keys, scopes, and policy outcomes in build logs.

Around the agent, Elastic CI Stack for AWS [v7.1.0](https://github.com/buildkite/elastic-ci-stack-for-aws/releases/tag/v7.1.0) and [v7.2.0](https://github.com/buildkite/elastic-ci-stack-for-aws/releases/tag/v7.2.0) now replace Linux instances whose agent stops responding for three minutes and bundle v4.1.0, the Kubernetes stack completes its move to agent v4 in [v0.51.0](https://github.com/buildkite/agent-stack-k8s/releases/tag/v0.51.0), and the agent scaler [v1.15.0](https://github.com/buildkite/buildkite-agent-scaler/releases/tag/v1.15.0) stores its last scale-in time in SSM Parameter Store so Lambda cold starts stop causing duplicate scale-ins.

From January 1, 2027, we support each minor release line for 1 year from its first stable release, with the final 3 months a deprecation window. Installing an agent or updating to a newer patch does not restart that window.

- v3.115.x and earlier become unsupported on January 1, 2027.
- v3.116.x through v3.121.x become deprecated that day, and stay supported until their own windows end.
- v3 support ends entirely on September 3, 2027.

We will not block out-of-support agents for that reason alone, but we no longer guarantee compatibility. We manage updates for hosted agents, so there is nothing to do there. On self-hosted agents, check the versions across your fleet and plan the [move to v4](https://buildkite.com/docs/agent/v3-v4-upgrade-guide), or read the full [agent version support policy](https://buildkite.com/docs/agent/version-support-policy).

If you run macOS on hosted agents, new RSS feeds now tell you when a base image changes. The [stable feed](https://buildkite.com/hosted-agents/macos/image-changes.rss) covers production images, and the [canary feed](https://buildkite.com/hosted-agents/macos/image-changes-canary.rss) covers the latest Xcode betas and runtimes.

### Test splitting moves to shared pools

The Buildkite test engine client [3.2.0](https://github.com/buildkite/test-engine-client/releases/tag/v3.2.0) adds `bktec pool plan` and `bktec pool exec` for shared Test Scheduler pools, and hosts the protocol and lifecycle for persistent test runners. Pool plan supports dynamic parallelism.

Underneath, bktec releases active leases when it terminates, retains them through transient heartbeat failures, and prefetches the next lease while the current one runs.

Manual test selection comes out of preview, and you can now opt out of git metadata collection. Release candidates went out on September 29 and October 1.</div><h2>GitHub releases</h2><p>35 releases across 13 public repos in the <a href="https://github.com/buildkite">buildkite</a> and <a href="https://github.com/buildkite-plugins">buildkite-plugins</a> GitHub orgs, newest first. Where one repo shipped a run of releases, they share a row. Dates are US Pacific time.</p><div>| Date | Release | Summary |
| --- | --- | --- |
| October 2 | [Docker Compose plugin v5.15.0](https://github.com/buildkite-plugins/docker-compose-buildkite-plugin/releases/tag/v5.15.0) | Adds a `bake` option to build and push with `docker buildx bake`, captures structured Docker Compose errors through the agent, and fixes the `pre-exit` hook exit code. |
| October 1 | [Test engine client (bktec) v3.2.0](https://github.com/buildkite/test-engine-client/releases/tag/v3.2.0) | Adds `bktec pool plan` and `bktec pool exec` to run tests from shared scheduler pools with persistent runners and dynamic parallelism, takes manual test selection out of preview, and lets you opt out of git metadata collection. Release candidates went out September 29 and October 1. |
| October 1 | [Elastic CI Stack for AWS v7.1.0 and v7.2.0](https://github.com/buildkite/elastic-ci-stack-for-aws/releases/tag/v7.2.0) | Replaces Linux instances whose agent stops responding for three minutes, retries transient EC2 metadata failures, bundles agent v4.1.0 and agent scaler v1.15.0, and fixes the instance termination fallback. |
| October 1 | [GitHub Actions workflows on Buildkite (buildkite-gha) v0.90.1 to v0.97.2](https://github.com/buildkite/buildkite-gha/releases) | Fourteen releases from September 28: a Linux arm64 runtime, vars, named secrets and matrix values in service containers, `strategy.*` expressions, GitHub-matching event filter behavior, and a path-filter fix that raises the changed-file limit from 300 to 3,000. |
| September 30 | [Agent v4.1.0](https://github.com/buildkite/agent/releases/tag/v4.1.0) | Reports cache save and restore timings and sizes to Buildkite, adds commit, pull request, and build author attributes to OpenTelemetry job spans, and fixes intermittent Windows crashes. |
| September 29 | [CLI 3.59.1](https://github.com/buildkite/cli/releases/tag/v3.59.1) | Fixes relative workflow paths when migrating secrets. |
| September 29 | [Go API client (go-buildkite) v5.19.0 to v5.21.0](https://github.com/buildkite/go-buildkite/releases/tag/v5.21.0) | Three releases from September 27 adding cluster cache registry, default cache registry, and repository connections support. |
| September 29 | [macOS menu bar app 1.0.63](https://github.com/buildkite/macmenubarapp-releases/releases/tag/v1.0.63) | Fixes stuck sign-in and lost sessions, makes build notifications more reliable, and adds live build times. 1.0.62 and earlier need a one-time manual update. |
| September 29 | [MCP server v1.24.0](https://github.com/buildkite/buildkite-mcp-server/releases/tag/v1.24.0) | Adds `create_pipeline_webhook` so agents can repair a pipeline created without its GitHub webhook, and makes failure summaries list jobs that never ran by default, reversing v1.23.0 after evals showed the opt-in cost extra tool calls. |
| September 29 | [Agent v4.0.9](https://github.com/buildkite/agent/releases/tag/v4.0.9) | Redacts Buildkite tokens by prefix in job logs and closes each job's log temp file when the job finishes. |
| September 29 | [Agent scaler v1.15.0](https://github.com/buildkite/buildkite-agent-scaler/releases/tag/v1.15.0) | Stores the last scale-in time in SSM Parameter Store, so Lambda cold starts no longer cause duplicate scale-ins. |
| September 29 | [Agent Stack for Kubernetes v0.51.0](https://github.com/buildkite/agent-stack-k8s/releases/tag/v0.51.0) | Completes the agent v4 migration. Breaking: tracing config keys are renamed or removed, and the controller will not start if the old keys remain. |
| September 28 | [CLI 3.59.0](https://github.com/buildkite/cli/releases/tag/v3.59.0) | Adds `bk` commands to migrate GitHub Actions secrets and manage the cache registry, plus clearer guidance when the OAuth credential store is unavailable. |
| September 28 | [Artifacts plugin v1.10.0](https://github.com/buildkite-plugins/artifacts-buildkite-plugin/releases/tag/v1.10.0) | Adds an option to expand variables, and fixes a command injection via env-name parsing in post-command upload discovery. |
| September 28 | [Agent v4.0.8](https://github.com/buildkite/agent/releases/tag/v4.0.8) | Turns on error capture without an experiment flag, redacts captured job errors using the job's registered secrets, and fixes a file-descriptor leak. |
| September 28 | [MCP server v1.23.0](https://github.com/buildkite/buildkite-mcp-server/releases/tag/v1.23.0) | Adds `validate_pipeline`, `compare_builds`, test execution trace and slowest-execution tools, and sharpens failure summaries. Breaking: `create_pipeline` now requires `create_webhook`. |
| September 27 | [Pipeline parser (go-pipeline) v0.18.1](https://github.com/buildkite/go-pipeline/releases/tag/v0.18.1) | Rejects pipeline YAML with excessive alias expansion instead of exhausting memory while parsing. |
| September 27 | [Agent v4.0.7](https://github.com/buildkite/agent/releases/tag/v4.0.7) | Shows cache restore keys, scopes, and policy outcomes in build logs, supports provider-specific Git usernames for repository credentials, and preserves Linux mount points during cache restore. |
| September 27 | [CLI 3.58.0](https://github.com/buildkite/cli/releases/tag/v3.58.0) | Accepts stdin request bodies in `bk api`, supports repeated `--path` flags for artifacts, and keeps cluster secret request bodies out of debug logs. |</div><h2><strong>Subscribe to changelog updates</strong></h2><p>Point any RSS reader at the <a href="https://buildkite.com/changelog.atom">Atom feed </a>and new entries arrive as they ship. You can also read the <a href="https://buildkite.com/resources/changelog/">Buildkite changelog</a>. </p><p></p><p>See you next week!</p>