Weekly wrap: September 27 – October 2, 2026
What shipped this week
Between September 27 and October 2, 2026, we published 4 changelog entries and 33 releases across 11 public repos. Three things run through them: more control and predictability for platform teams, fewer gaps for teams moving off GitHub Actions, and more of the platform agents can drive directly.
- Tightened how secrets are handled. Pipeline-scoped secrets live in pipeline settings, the Buildkite CLI (
bk) migrates GitHub Actions secrets, and the agent now redacts anything shaped like a Buildkite-issued token from job logs. Captured errors redact the secrets registered for that job. - Expanded what agents can do. The MCP server added pipeline validation, build comparison, test execution traces, and webhook repair, and each Remote MCP connection now pins to an organization.
- Steadied build environments. Agent v4.1.0 reports cache timings and adds commit, pull request, and author attributes to OpenTelemetry spans. Elastic CI Stack for AWS replaces instances whose agent stops responding, the Kubernetes stack completes its move to agent v4, and the agent scaler stops duplicate scale-ins. New RSS feeds announce macOS base image releases on hosted agents. All v3 agent support ends September 3, 2027.
- Closed more gaps in GitHub Actions workflows on Buildkite. Fourteen releases added a Linux arm64 runtime and broader support for vars, secrets, matrix values, and strategy expressions.
- Moved test splitting toward shared pools. The Buildkite test engine client (
bktec) 3.2.0 adds commands to plan and run tests from shared scheduler pools, with persistent runners and dynamic parallelism.
Changelog entries
Dates are US Pacific time.
| Date | Entry | Summary |
|---|---|---|
| October 1 | Get notified about new macOS base image releases | Subscribe to RSS feeds for macOS base image releases on Buildkite hosted agents. Separate stable and canary feeds cover production images and the latest Xcode betas. |
| September 30 | Choose the organization for each Remote MCP Server connection | Add ?organization=<slug> to the Remote MCP Server URL, including toolset and read-only URLs, to pin each connection to one Buildkite organization. Authorization then preselects it. |
| September 30 | Buildkite agent version support policy | From January 1, 2027, we support each agent minor release line for 1 year from its first stable release, with the last 3 months deprecated. v3.115.x and earlier go unsupported that day, and all v3 support ends September 3, 2027. |
| September 28 | Manage secrets from pipeline settings | Anyone who can edit a pipeline and manage its cluster can now create pipeline-restricted secrets in Pipeline settings → Secrets. Conditions cover branch, queue, build source, or creator, and cluster settings show lock indicators. |
Buildkite
Start turning complexity into an advantage
Create an account to get started for free.