Matters

A product · December 2025

CMS Patch Pilot: security updates without the weekend

Detects CMS security updates, applies them in a test environment, checks every page still looks right, and waits for a person to approve.

CMS Patch Pilot watches for security advisories, applies the update in an isolated environment, runs visual regression and HTML diff tests, and opens a ready-to-merge pull request with the results.

DetectsSecurity advisories for core and contributed modules, as soon as they are published.
TestsEvery page compared before and after the update at four screen sizes, plus forms checked to still submit.
Asks firstA pull request and a Slack note with everything needed to approve. Production is never touched automatically.
Keeps a recordA complete audit trail of what was updated, when, and who approved it.

Why we built it

Patching a dozen client sites by hand is slow, and slow patching is a security risk. We wanted the routine part done by the time a person looks at it.

CMS Patch Pilot was made at Matters and is deployed at Savas Labs, which uses it to keep client sites patched.

Savas Labs