# ZF1: community-maintained official fork

**URL:** <https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419>\
**Category:** Contributors\
**Tags:** zf1\
**Created:** [January 9, 2018, 10:37am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419 "2018-01-09T10:37:21Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Slamdunk](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/slamdunk/32/115_2.png) [@Slamdunk](https://discourse.laminas.dev/u/Slamdunk)\
**Post date:** [January 9, 2018, 10:37am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/1 "2018-01-09T10:37:21Z")

</div>

Hi, we all know ZF1 [reached EOL](https://framework.zend.com/blog/2016-06-28-zf1-eol.html) long time ago.

The really bad thing of ZF1 is that it still is a **rock-solid** framework: I have many legacy apps in production, all with 100% code-coverage that happily run without bugs nor (known) security holes; all of them must keep running due to legal constraints but none of them have the money for an upgrade.

What I would like is:

1. Respect ZF1 [LICENSE.txt](https://github.com/zendframework/zf1/blob/master/LICENSE.txt), a _BSD-3-Clause_
2. Fork the latest release - or something similar, like getting in charge for the purpose
3. Clearly state the purpose of the fork:
  1. Keep ZF1 running without blocking errors on newest PHP versions
  2. Drop support for previous/old/unsupported PHP versions when above point can’t be satisfied
  3. If above points are satisfied, accept trivial-and-tested bug fixes
  4. Reject any API changes, extensions, new features, optimizations etc

4. Discourage, like now, any usage of the fork beside updating PHP version for legacy apps

Issues for the goal:

1. Old PR with `[no signed CLA]` tag: have no idea how to handle this
2. `Zend_Version` executes an external call to `http://framework.zend.com/api/zf-version`: I would like to deprecate this class as I do not want to alter anything outside the fork, like the [zend.com](http://zend.com) website

Reference: [https://github.com/zendframework/zf1/pull/748](https://github.com/zendframework/zf1/pull/748)

Any suggestions are welcome.

---

<div class="post-metadata">

**Author:** ![froschdesign](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/froschdesign/32/38_2.png) [@froschdesign](https://discourse.laminas.dev/u/froschdesign)\
**Post date:** [January 9, 2018, 3:32pm UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/2 "2018-01-09T15:32:15Z")

</div>

Some thoughts:

- The naming “official fork” suggests a wrong impression, it should not be used.
- I think the name “Zend” can not be used and should not be used.
- There is no way to port the open PR’s to another repository. All open PR’s are send to the official ZF1 repository and no one is allowed to port this code. You can ask every contributor to send a new PR to your fork.
- You can fork the project as long as you honour the current license terms.
- You can create a community around your fork.
- My suggestion for naming: “zf1-legacy” 😉
- My suggestion for the fork: do not add new features, only fixes bugs and problems.
- And don’t forget: you’re still riding a dead horse!

Another and my most important suggestion: **Don’t do this!**  
Create no fork and invest no work or energy in a dead project. And if there is no money for upgrades, why would you update or add new features to the underlying framework?!  
Use PHP 5.6 and ZF 1.12.20 and everything stays as it was!

(Please keep in mind: I’m not a lawyer or jurist and it’s only my own view and my opinion!)

---

<div class="post-metadata">

**Author:** ![Slamdunk](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/slamdunk/32/115_2.png) [@Slamdunk](https://discourse.laminas.dev/u/Slamdunk)\
**Post date:** [January 9, 2018, 4:16pm UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/3 "2018-01-09T16:16:34Z")

</div>

> [@froschdesign](#):
>
> - The naming “official fork” suggests a wrong impression, it should not be used.

Agree

> [@froschdesign](#):
>
> - I think the name “Zend” can not be used and should not be used.
> - You can fork the project as long as you honour the current license terms.

I have no experience in licenses management, I fear to make mistakes. I do **not** want to use the Zend name, but the licence must stay still and same, so the name would be different, but the files containted and the licence would refer to Zend. Would this be correct?

> [@froschdesign](#):
>
> - There is no way to port the open PR’s to another repository. All open PR’s are send to the official ZF1 repository and no one is allowed to port this code. You can ask every contributor to send a new PR to your fork.

I’m ok with this

> [@froschdesign](#):
>
> - My suggestion for naming: “zf1-legacy” 😉

Nice name

> [@froschdesign](#):
>
> Another and my most important suggestion: **Don’t do this!**

I totally agree, but:

> [@froschdesign](#):
>
> And if there is no money for upgrades, why would you update or add new features to the underlying framework?!
> 
> Use PHP 5.6 and ZF 1.12.20 and everything stays as it was!

I fear security issues like [CVE-2016-5771](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5771) and [CVE-2016-5773](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5773).  
Upgrading the environment is easy and cheap, I do not want unmaintained infrastructures nor systems nor softwares in my production.  
Upgrading the framework is tricky and costly, that’s what tests are for: we spent a lot of effort to ensure happy&sad&bad paths are all covered, so we can safely face the environment upgrade.

Keeping the old framework up to date to the newest PHP versions is cheap (at least now), so the overall cost of committing my time into it plus upgrading the environment ensures my client the best compromise between money and issue-prevention.

---

<div class="post-metadata">

**Author:** ![matthew](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/matthew/32/14_2.png) [@matthew](https://discourse.laminas.dev/u/matthew)\
**Post date:** [January 9, 2018, 4:25pm UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/4 "2018-01-09T16:25:31Z")

</div>

> [@Slamdunk](#):
>
> Keeping the old framework up to date to the newest PHP versions is cheap (at least now)

I beg to differ.

RogueWave has provided ZF1 patches to customers with service license agreements since the EOL date. All of these have involved fixing issues arising due to running the framework on newer versions of PHP than it was originally tested against. Many of these have proved non-trivial to update, taking many hours of developer time. It’s nowhere near cheap… which is why we only do it for paying customers with SLAs in place.

My point is: do not underestimate the amount of time, energy, and money it will take to keep ZF1 running under newer PHP versions. It’s not as trivial as you might think.

---

<div class="post-metadata">

**Author:** ![froschdesign](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/froschdesign/32/38_2.png) [@froschdesign](https://discourse.laminas.dev/u/froschdesign)\
**Post date:** [January 10, 2018, 9:24am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/5 "2018-01-10T09:24:42Z")

</div>

> [@Slamdunk](#):
>
> Drop support for previous/old/unsupported PHP versions

Where does that help? Extra and unneeded work!

> [@Slamdunk](#):
>
> …I do not want unmaintained infrastructures nor systems nor softwares in my production.

And here is the problem: ZF1 is unmaintained!

* * *

Please do not get me wrong, I understand your situation! I also support some ZF1 applications.

But the update of the framework is not trivial; I have the same experience. Some examples from my work on ZF1 und many applications which based on ZF1: (the list is not complete!)

- `Zend_Date` is a big fat monster with ugly bugs; should removed
- `Zend_Locale` is outdated and gives wrong results; no update without rewrite
- `Zend_Currency` is outdated because it based on `Zend_Locale`
- `Zend_Captcha` only supports version 1 of ReCaptcha
- `Zend_Form` doesn’t support HTML5 and mixes different layers
- `Zend_Validate_CreditCard`, `Zend_Validate_Hostname` and `Zend_Validate_PostCode` are outdated
- `Zend_Dojo` and `ZendX_JQuery` are completely outdated
- `Zend_Pdf` is incomplete
- results from `Zend_Markup` are wrong
- `Zend_Registry` is a mess
- `Zend_View` is inflexible
- `Zend_Application` is not helpful
- the module system not existent
- many service and cloud components / classes uses an old API version of the related service
- dependency injection where are you?
- absolutely no PSR support
- version 7.1 and 7.2 of PHP were never tested; 7.0 with allowed failures
- PHPUnit with version 3.7 is used

The last point is a KO criteria for further maintenance of the framework!

I advise and strongly recommend a migration for your applications! A migration in several steps:

- decoupling the layer with controller from the rest of the application; can be done without changes on the framework or without other external components
- replace `Zend_Date`, `Zend_Locale` etc. with e.g. PHP’s `DateTime` and so on
- replace `Zend_Validate`
- replace `Zend_Db`
- …

I call this a “soft migration”. 😉 Yes, this takes some time – sometimes years! But you will not be riding a dead horse in the future.  
Positive side-effect: you create a solid and robust application structure for all upcoming frameworks or framework versions.

If you can change absolutely nothing, then use PHP 5.6 and ZF 1.12.20. Everything else is the same as paying for the Windows XP support.

---

<div class="post-metadata">

**Author:** ![eldt](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/eldt/32/501_2.png) [@eldt](https://discourse.laminas.dev/u/eldt)\
**Post date:** [January 17, 2018, 11:59am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/6 "2018-01-17T11:59:25Z")

</div>

ZendFramework (as its [repo](https://github.com/zendframework/zendframework/tree/master) says) its pretty much dead. To be honest Im not surprised.

---

<div class="post-metadata">

**Author:** ![ocramius](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/ocramius/32/23_2.png) [@ocramius](https://discourse.laminas.dev/u/ocramius)\
**Post date:** [January 17, 2018, 12:12pm UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/7 "2018-01-17T12:12:55Z")

</div>

The main repo only contains headers referencing the single components:  
check [https://github.com/zendframework](https://github.com/zendframework) for current activity (which is a  
damn lot) 😉

Marco Pivetta

[http://twitter.com/Ocramius](http://twitter.com/Ocramius)

[http://ocramius.github.com/](http://ocramius.github.com/)

---

<div class="post-metadata">

**Author:** ![froschdesign](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/froschdesign/32/38_2.png) [@froschdesign](https://discourse.laminas.dev/u/froschdesign)\
**Post date:** [January 17, 2018, 12:56pm UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/8 "2018-01-17T12:56:34Z")

</div>

> [@eldt](#):
>
> ZendFramework (as its repo says) its pretty much dead.

Please note: This discussion is related to version 1 of ZF!

---

<div class="post-metadata">

**Author:** ![matthew](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/matthew/32/14_2.png) [@matthew](https://discourse.laminas.dev/u/matthew)\
**Post date:** [January 17, 2018, 2:32pm UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/9 "2018-01-17T14:32:55Z")

</div>

@eldt Zend Framework is far from dead. We shipped more than 100 million packages from March until December alone.

Version 1 has reached its end of life, however, which is what this particular topic is about.

ZF2 and later (ZF3 was announced over 18 months ago), which is the repository you referenced, is quite alive. However, it’s no longer being developed in a monolithic repository, but rather as individual components, which you can put together into a full-stack MVC framework (via zend-mvc and the ZendSkeletonApplication), a middleware framework (Expressive), or as a custom runtime (by including only what you want/need).

---

<div class="post-metadata">

**Author:** ![Thiouzz](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thiouzz](https://discourse.laminas.dev/u/Thiouzz)\
**Post date:** [January 26, 2018, 9:59am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/10 "2018-01-26T09:59:54Z")

</div>

ZF1 is one of my best PHP Framework and i really like how can we extend it as much as we like and its not a black box like Symfony … I keep choosing it for my projects and i really want we continue to maintain it even if its not official.

Totally agree !!

---

<div class="post-metadata">

**Author:** ![Slamdunk](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/slamdunk/32/115_2.png) [@Slamdunk](https://discourse.laminas.dev/u/Slamdunk)\
**Post date:** [January 26, 2018, 10:19am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/11 "2018-01-26T10:19:33Z")

</div>

> [@Thiouzz](#):
>
> […] I keep choosing it for my projects […]

This is not the purpose of my idea. You shouldn’t adopt it for any project anymore.

---

<div class="post-metadata">

**Author:** ![David\_Ballerini](https://avatars.discourse-cdn.com/v4/letter/d/c5a1d2/32.png) [@David\_Ballerini](https://discourse.laminas.dev/u/David_Ballerini)\
**Post date:** [January 26, 2018, 10:55am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/12 "2018-01-26T10:55:35Z")

</div>

What about third-party plugins / modules that have been developed for ZF1 ? Would they be compatible (wide and large) with ZF3 ?

---

<div class="post-metadata">

**Author:** ![Thiouzz](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thiouzz](https://discourse.laminas.dev/u/Thiouzz)\
**Post date:** [January 26, 2018, 10:56am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/13 "2018-01-26T10:56:44Z")

</div>

Sure i got your point but why we souldn’t adopt it for any project ?

---

<div class="post-metadata">

**Author:** ![froschdesign](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/froschdesign/32/38_2.png) [@froschdesign](https://discourse.laminas.dev/u/froschdesign)\
**Post date:** [January 26, 2018, 11:10am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/14 "2018-01-26T11:10:49Z")

</div>

> [@Thiouzz](#):
>
> …why we souldn’t adopt it for any project ?

**No more updates, bug fixes or security fixes!** (The last release was on 8 Sep 2016.)

---

<div class="post-metadata">

**Author:** ![froschdesign](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/froschdesign/32/38_2.png) [@froschdesign](https://discourse.laminas.dev/u/froschdesign)\
**Post date:** [January 26, 2018, 11:13am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/15 "2018-01-26T11:13:15Z")

</div>

> [@David\_Ballerini](#):
>
> Would they be compatible (wide and large) with ZF3 ?

Maybe or maybe not. If a plugin based directly on an older class like `Zend_Controller_Action_Helper_Abstract`, then an update is needed.

---

<div class="post-metadata">

**Author:** ![froschdesign](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/froschdesign/32/38_2.png) [@froschdesign](https://discourse.laminas.dev/u/froschdesign)\
**Post date:** [January 26, 2018, 11:17am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/16 "2018-01-26T11:17:25Z")

</div>

> [@Thiouzz](#):
>
> ZF1 is one of my best PHP Framework…

Sure? Please look at the problems which I listed above.

---

<div class="post-metadata">

**Author:** ![tux-rampage](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/tux-rampage/32/237_2.png) [@tux-rampage](https://discourse.laminas.dev/u/tux-rampage)\
**Post date:** [January 26, 2018, 11:25am UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/17 "2018-01-26T11:25:33Z")

</div>

> Sure i got your point but why we souldn’t adopt it for any project ?

😱 You really should **not** do this. It’s like “I’m still using Windows 98 for my new Computers”.

---

<div class="post-metadata">

**Author:** ![Thiouzz](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thiouzz](https://discourse.laminas.dev/u/Thiouzz)\
**Post date:** [January 26, 2018, 12:30pm UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/18 "2018-01-26T12:30:56Z")

</div>

Its a bit exagerated i guess … I like Zend 1 because the aspect of tool box, then if you are a good programmer you can manage all the other aspect of security, etc.

Its just recentry that the others framework are more modular by extracting the components seperatly.

Also its just the fact that i am too dependent to the framework and i am just configuring it with anotation and yaml files that i can’t stand and its my point of view !!!

Also have in mind that a framework have to be just implementation of the desgn patterns and with ZF1 you can still implement whatever design pattern your WAY !!! what is not with the new framework because you are using the design patterns implemented their way.

I guess its a long debate but here are my arguments why i still use ZF1

---

<div class="post-metadata">

**Author:** ![froschdesign](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/froschdesign/32/38_2.png) [@froschdesign](https://discourse.laminas.dev/u/froschdesign)\
**Post date:** [January 26, 2018, 4:04pm UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/19 "2018-01-26T16:04:34Z")

</div>

> [@Thiouzz](#):
>
> Also its just the fact that i am too dependent to the framework and i am just configuring it with anotation and yaml files that i can’t stand and its my point of view !!!

Wrong fact! There are no annotations or YAML configuration in ZF. And with version 1 you have a hard dependency to framework. Loose coupling come with version 2.

> [@Thiouzz](#):
>
> …with ZF1 you can still implement whatever design pattern your WAY…

The opposite is the case, ZF1 uses some bad practices and has poor limitations.

---

<div class="post-metadata">

**Author:** ![Thiouzz](https://avatars.discourse-cdn.com/v4/letter/t/7ab992/32.png) [@Thiouzz](https://discourse.laminas.dev/u/Thiouzz)\
**Post date:** [January 26, 2018, 4:12pm UTC](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419/20 "2018-01-26T16:12:15Z")

</div>

I got it … just is the fact that i always get what i needed with ZF1 and i really gone far in modules and plugins that helps me every day in my work.

I should give ZF2 a try then. But the Yaml and Anotation i am talking about Symfony that till now i still don’t manage to accept it.

Good conversation and happy phping !!

[Next page](https://discourse.laminas.dev/t/zf1-community-maintained-official-fork/419.md?page=2)
