Continuous integration for Drupal

Every change to a website carries some risk. Continuous integration reduces it: developers merge code often, and automated tests check each change before it goes near your live site.

The tests don't promise zero errors. They find errors sooner, ideally before they reach production, and free developers from running the same checks by hand.

Release changes with confidence

For a government site that handles sensitive information or high traffic, an undetected fault costs far more than it would on a typical commercial site. Automated testing catches bugs, security issues, and accessibility problems before they reach the people who rely on your site.

It also means improvements arrive in small, regular steps instead of large, risky releases.

What you get:

  • Problems found before launch. Coding standards, unit tests, and behavioural tests run on every change.
  • Safer editorial workflows. Automated tests confirm that approval and publishing steps keep working.
  • Quality that scales. A support arrangement that doesn't depend on manual checking alone.

Our approach to continuous integration

Build the pipeline

We set up a pipeline that uses external services to manage the testing and release of code. Every change goes through the same steps.

Test what matters

Automated checks cover coding standards, unit tests, and behavioural tests. We add functional tests of content types and components, accessibility checks, and regression tests for critical user journeys.

Catch visual changes

Visual regression tools such as BackstopJS compare a page before and after a change, so unintended design changes are caught before deployment.

Keep checking after release

Our pipeline also runs nightly. It caught a vulnerability in Drupal core, which led to the problem being fixed promptly.

Frequently asked questions

We build quality into development with continuous integration pipelines that automate testing and code quality checks at each deployment. Automated testing covers accessibility, functional testing of content types and components, and regression testing of critical user journeys. Before launch, we also run manual accessibility audits, cross-browser testing, and performance profiling. For GovCMS clients, our security hardening checklist covers government security requirements.

Continuous integration and deployment pipelines catch bugs, security issues, and accessibility regressions before they reach a live, public-facing site. They also let content and functionality updates ship faster and more safely than manual deployment. For a government site with sensitive information or high traffic, an undetected regression costs far more than on a typical commercial site.

A proper CI pipeline runs tests on every code change, including visual regression tools such as BackstopJS, so problems are caught before deployment rather than through manual quality assurance alone. That matters when you compare support providers, because manual-only checking scales poorly as a site grows.

It should be standard practice for any PaaS build with custom code. PaaS gives you flexibility and responsibility that SaaS doesn't, and that flexibility is only safe to use with automated testing and disciplined deployment behind it.

Yes. Drupal's content moderation has configurable states such as draft, needs review, and published, plus role-based permissions. We test these workflows with Cypress, so approval chains keep working after each release.

Latest insights

Beer poured from clean pipelines
Article

The Morpht CI pipeline caught a recent vulnerability in Drupal core which led to the problem promptly being fixed.