1. Resources
  2. /
  3. Blog
  4. /
  5. What we shipped last week

What we shipped last week

Updated

Summary

Between September 27 and October 3, 2026, we published 4 changelog entries and 35 releases across 13 public repos. Three things run through them: more control and predictability for platform teams, fewer gaps for teams moving off GitHub Actions, and more of the platform agents can drive directly.

  • Tightened how secrets are handled. Pipeline-scoped secrets live in pipeline settings, the Buildkite CLI (bk) migrates GitHub Actions secrets, and the agent now redacts anything shaped like a Buildkite-issued token from job logs. Captured errors redact the secrets registered for that job.
  • Expanded what agents can do. The MCP server added pipeline validation, build comparison, test execution traces, and webhook repair, and each Remote MCP connection now pins to an organization.
  • Steadied build environments. Agent v4.1.0 reports cache timings and adds commit, pull request, and author attributes to OpenTelemetry spans. Elastic CI Stack for AWS replaces instances whose agent stops responding, the Kubernetes stack completes its move to agent v4, and the agent scaler stops duplicate scale-ins. New RSS feeds announce macOS base image releases on hosted agents. All v3 agent support ends September 3, 2027.
  • Closed more gaps in GitHub Actions workflows on Buildkite. Fourteen releases added a Linux arm64 runtime and broader support for vars, secrets, matrix values, and strategy expressions.
  • Moved test splitting toward shared pools. The Buildkite test engine client (`bktec`) 3.2.0 adds commands to plan and run tests from shared scheduler pools, with persistent runners and dynamic parallelism.

Changelog entries

Dates are US Pacific time.

DateEntrySummary
October 1Get notified about new macOS base image releasesSubscribe to RSS feeds for macOS base image releases on Buildkite hosted agents. Separate stable and canary feeds cover production images and the latest Xcode betas.
September 30Choose the organization for each Remote MCP Server connectionAdd ?organization=<slug> to the Remote MCP Server URL, including toolset and read-only URLs, to pin each connection to one Buildkite organization. Authorization then preselects it.
September 30Buildkite agent version support policyFrom January 1, 2027, we support each agent minor release line for 1 year from its first stable release, with the last 3 months deprecated. v3.115.x and earlier go unsupported that day, and all v3 support ends September 3, 2027.
September 28Manage secrets from pipeline settingsAnyone who can edit a pipeline and manage its cluster can now create pipeline-restricted secrets in Pipeline settings → Secrets. Conditions cover branch, queue, build source, or creator, and cluster settings show lock indicators.

What does this mean for you

Secrets move closer to the pipeline

If you can edit a pipeline and manage its cluster, you can now create and manage secrets from Pipeline settings → Secrets. Pipeline secrets are cluster secrets restricted to the current pipeline, and branch, queue, build source, or creator conditions narrow access further. Values stay hidden after creation.

The new view keeps pipeline-specific secrets together, shows how many others the cluster manages, and links through to the cluster's secrets page, where restricted secrets now carry a lock indicator. GitHub Actions pipelines get a dismissible prompt pointing at secrets setup before the first workflow runs.

The Buildkite CLI 3.59.0 adds a command to migrate GitHub Actions secrets, and 3.59.1 fixes relative workflow paths when you do.

Agents get the moves an engineer would make

Log access alone does not debug a build. MCP server v1.23.0 adds validate_pipeline to check pipeline YAML against the official schema before upload, compare_builds to diff a failing build against an earlier success, and Test Engine execution traces with slowest-execution lookups.

v1.24.0 adds create_pipeline_webhook, so an agent can repair a pipeline created without its GitHub webhook instead of recreating it. Both releases sharpen failure summaries.

One v1.23.0 default hid jobs that never ran, and v1.24.0 reversed it after eval runs showed the opt-in forced extra tool calls. Measure, then decide.

v1.23.0 carries one breaking change: create_pipeline now requires create_webhook.

If your agents work across more than one organization, add ?organization=your-organization to the Remote MCP Server URL. The authorization page then preselects it. It works with toolset and read-only URLs, and leaving it off changes nothing.

GitHub Actions workflows on Buildkite

Fourteen buildkite-gha releases this week:

  • Publishes a Linux arm64 runtime in v0.97.0, so the importer and generated jobs run on arm64 agents. Labels such as ubuntu-24.04-arm need an explicit queue mapping, and they never fall back to x86-64 or emulation.
  • Resolves job environment values, named secrets, runtime vars, and matrix values in service container env and credentials, across v0.94.0, v0.95.0, and v0.96.0.
  • Exposes strategy.job-index, job-total, fail-fast, and max-parallel in job and step expressions in v0.93.0. fail-fast reports its configured value but still does not cancel sibling matrix jobs.
  • Ignores branch, tag, and path filters on ten event families in v0.93.1, matching GitHub's behavior.
  • Raises the changed-file limit from 300 to 3,000 in v0.97.2, and fixes path-filtered push workflows that failed when the branch advanced after the push.

You pick these up through the GitHub Actions Buildkite plugin, which installs and verifies the selected CLI release and defaults to the latest stable one. Every release ships with upgrade notes that say exactly what is still unsupported.

Four agent releases, and a clock on v3

Agent v4.1.0 reports cache save and restore timings and sizes back to Buildkite, carries commit, pull request, and build author as OpenTelemetry job span attributes, and fixes intermittent Windows crashes. v4.0.9 redacts Buildkite tokens by prefix in job logs, v4.0.8 redacts captured job errors using the job's registered secrets, and v4.0.7 surfaces cache restore keys, scopes, and policy outcomes in build logs.

Around the agent, Elastic CI Stack for AWS v7.1.0 and v7.2.0 now replace Linux instances whose agent stops responding for three minutes and bundle v4.1.0, the Kubernetes stack completes its move to agent v4 in v0.51.0, and the agent scaler v1.15.0 stores its last scale-in time in SSM Parameter Store so Lambda cold starts stop causing duplicate scale-ins.

From January 1, 2027, we support each minor release line for 1 year from its first stable release, with the final 3 months a deprecation window. Installing an agent or updating to a newer patch does not restart that window.

  • v3.115.x and earlier become unsupported on January 1, 2027.
  • v3.116.x through v3.121.x become deprecated that day, and stay supported until their own windows end.
  • v3 support ends entirely on September 3, 2027.

We will not block out-of-support agents for that reason alone, but we no longer guarantee compatibility. We manage updates for hosted agents, so there is nothing to do there. On self-hosted agents, check the versions across your fleet and plan the move to v4, or read the full agent version support policy.

If you run macOS on hosted agents, new RSS feeds now tell you when a base image changes. The stable feed covers production images, and the canary feed covers the latest Xcode betas and runtimes.

Test splitting moves to shared pools

The Buildkite test engine client 3.2.0 adds bktec pool plan and bktec pool exec for shared Test Scheduler pools, and hosts the protocol and lifecycle for persistent test runners. Pool plan supports dynamic parallelism.

Underneath, bktec releases active leases when it terminates, retains them through transient heartbeat failures, and prefetches the next lease while the current one runs.

Manual test selection comes out of preview, and you can now opt out of git metadata collection. Release candidates went out on September 29 and October 1.

GitHub releases

35 releases across 13 public repos in the buildkite and buildkite-plugins GitHub orgs, newest first. Where one repo shipped a run of releases, they share a row. Dates are US Pacific time.

DateReleaseSummary
October 2Docker Compose plugin v5.15.0Adds a bake option to build and push with docker buildx bake, captures structured Docker Compose errors through the agent, and fixes the pre-exit hook exit code.
October 1Test engine client (bktec) v3.2.0Adds bktec pool plan and bktec pool exec to run tests from shared scheduler pools with persistent runners and dynamic parallelism, takes manual test selection out of preview, and lets you opt out of git metadata collection. Release candidates went out September 29 and October 1.
October 1Elastic CI Stack for AWS v7.1.0 and v7.2.0Replaces Linux instances whose agent stops responding for three minutes, retries transient EC2 metadata failures, bundles agent v4.1.0 and agent scaler v1.15.0, and fixes the instance termination fallback.
October 1GitHub Actions workflows on Buildkite (buildkite-gha) v0.90.1 to v0.97.2Fourteen releases from September 28: a Linux arm64 runtime, vars, named secrets and matrix values in service containers, strategy.* expressions, GitHub-matching event filter behavior, and a path-filter fix that raises the changed-file limit from 300 to 3,000.
September 30Agent v4.1.0Reports cache save and restore timings and sizes to Buildkite, adds commit, pull request, and build author attributes to OpenTelemetry job spans, and fixes intermittent Windows crashes.
September 29CLI 3.59.1Fixes relative workflow paths when migrating secrets.
September 29Go API client (go-buildkite) v5.19.0 to v5.21.0Three releases from September 27 adding cluster cache registry, default cache registry, and repository connections support.
September 29macOS menu bar app 1.0.63Fixes stuck sign-in and lost sessions, makes build notifications more reliable, and adds live build times. 1.0.62 and earlier need a one-time manual update.
September 29MCP server v1.24.0Adds create_pipeline_webhook so agents can repair a pipeline created without its GitHub webhook, and makes failure summaries list jobs that never ran by default, reversing v1.23.0 after evals showed the opt-in cost extra tool calls.
September 29Agent v4.0.9Redacts Buildkite tokens by prefix in job logs and closes each job's log temp file when the job finishes.
September 29Agent scaler v1.15.0Stores the last scale-in time in SSM Parameter Store, so Lambda cold starts no longer cause duplicate scale-ins.
September 29Agent Stack for Kubernetes v0.51.0Completes the agent v4 migration. Breaking: tracing config keys are renamed or removed, and the controller will not start if the old keys remain.
September 28CLI 3.59.0Adds bk commands to migrate GitHub Actions secrets and manage the cache registry, plus clearer guidance when the OAuth credential store is unavailable.
September 28Artifacts plugin v1.10.0Adds an option to expand variables, and fixes a command injection via env-name parsing in post-command upload discovery.
September 28Agent v4.0.8Turns on error capture without an experiment flag, redacts captured job errors using the job's registered secrets, and fixes a file-descriptor leak.
September 28MCP server v1.23.0Adds validate_pipeline, compare_builds, test execution trace and slowest-execution tools, and sharpens failure summaries. Breaking: create_pipeline now requires create_webhook.
September 27Pipeline parser (go-pipeline) v0.18.1Rejects pipeline YAML with excessive alias expansion instead of exhausting memory while parsing.
September 27Agent v4.0.7Shows cache restore keys, scopes, and policy outcomes in build logs, supports provider-specific Git usernames for repository credentials, and preserves Linux mount points during cache restore.
September 27CLI 3.58.0Accepts stdin request bodies in bk api, supports repeated --path flags for artifacts, and keeps cluster secret request bodies out of debug logs.

Subscribe to changelog updates

Point any RSS reader at the Atom feed and new entries arrive as they ship. You can also read the Buildkite changelog.

See you next week!


Related posts

Start turning complexity into an advantage

Create an account to get started for free.

Buildkite Pipelines

Platform

  1. Pipelines
  2. Public pipelines
  3. Test Engine
  4. Package Registries
  5. Mobile Delivery Cloud
  6. Pricing

Hosting options

  1. Self-hosted agents
  2. Mac hosted agents
  3. Linux hosted agents

Resources

  1. Docs
  2. Blog
  3. Changelog
  4. Example pipelines
  5. Plugins
  6. Webinars
  7. Case studies
  8. Events
  9. Migration Services
  10. CI/CD perspectives

Company

  1. About
  2. Careers
  3. Press
  4. Security
  5. Brand assets
  6. Contact

Solutions

  1. Replace Jenkins
  2. Workflows for MLOps
  3. Testing at scale
  4. Monorepo mojo
  5. Bazel orchestration

Compare

  1. Buildkite vs GitHub Actions
  2. Buildkite vs Depot

Legal

  1. Terms of Service
  2. Acceptable Use Policy
  3. Privacy Policy
  4. Subprocessors
  5. Service Level Agreement
  6. Supplier Code of Conduct
  7. Modern Slavery Statement

Support

  1. System status
  2. Forum
© Buildkite Pty Ltd 2026