PHP Lifecycle and PHP Upgrade Challenges

Опубликовано: 23 Май 2026
на канале: Perforce OpenLogic
51
1

Matthew Weier O’Phinney (Senior Product Manager, Zend by Perforce) explains the PHP lifecycle and release cadence, as well as some of the upgrade challenges PHP teams may face when their version becomes end-of-life.

This video is from the webinar, “How to Ace OSS Lifecycle Management: Upgrades, Patches, and LTS” that took place on July 20, 2023. It was moderated by Javier Perez, Chief OSS Evangelist and Senior Director of Product Management at Perforce Software, and featured speakers Tim Carroll, Director of Product Development for OpenLogic, and Matthew Weier O’Phinney, Senior Product Manager for Zend.

To watch the full webinar, click here: https://ter.li/l2yf7l

- -

About OpenLogic by Perforce:
OpenLogic offers end-to-end enterprise support for organizations using open source software in their infrastructure. With support for over 400 open source packages, guaranteed SLAs, and direct access to highly experienced Enterprise Architects, OpenLogic customers benefit from 24x7 ticket-based technical support, professional services, and training.
Follow OpenLogic on LinkedIn, Twitter, and don’t forget to subscribe to our YouTube channel for more videos on all things open source!

- -

Transcript (lightly edited for clarity):

Javier: So, how about we start with PHP, Matthew? You can give us a little bit of information here on how PHP works in terms of that life cycle, the LTS. If you can mention some of the end of life versions, that would be good. Let's use that as the first example.

Matthew: Sure. So, PHP for a long time didn't have any formal policy around it. It was just whatever they would patch, but then around eight or nine years ago, they adopted an RFC process. With that process, they said, "Hey, we're not going to introduce new features unless they've been vetted by the community. But on the top of that, we're going to adopt an actual formal life cycle for the project." The way it works is that a version gets released. When I say a version, it's a minor version that includes new major versions. So, 8.0 is a major version and a new minor version at the same time, but those minor versions have a release cycle of three years.
Customers get two years of active support where they're getting bug fixes and security patches, and then an additional year after that where they get only security patches. So, that means that if a new release is done in November of 2016, then in November of 2019, it has reached end of life within the PHP community and it will no longer receive patches. So, it's very nice, it's very predictable. We know that every year, there's a new minor release, whether it's a minor or a major, but there's a new minor release that happens every year right around November or December, depending on how the release schedule pans out in the end. That release will get three years of support, which is fantastic.

Now, a lot of our customers and a lot of people on this call, probably hear three years and go, "That's not very long." It's not. So, what we find is a lot of people are on applications that they can't actually update on that regular cadence of one to three years. So, what happens is, at a certain point, the PHP version that they pinned against goes end of life. Now they're stuck and they're like, "What do we do here? Because what if security packages are released for those new current versions? How do we make sure that we're secure here?" So that's when you have to go to other sources. Most operating systems, Linux Operating Systems in particular, part of their LTS commitment for the operating system is that all of the packages that they have in there, they will do backported security patches.

That said, on Linux Operating Systems, you usually have exactly one PHP version. So, that means whatever version that is, that's what you're stuck on. An example of that is 20.04, if I remember correctly, it has PHP 7.4. What's great about that is you can just keep using 20.04 until it goes end of life, but the problem is then when it does and you want to upgrade to that next version of the operating system, you're also stuck upgrading to a new version of PHP and it's likely many different versions. So, now you have a problem where you have to go not only upgrade the operating system, you have the additional risk of updating your application.
Each time there's a new release, there's deprecation for whatever the next major is going to be. Then if there's another major, then those deprecations are just removed. So, there's lots of little pieces that can cause problems and risk as you do those upgrades. So, that's what we look at, and that's part of the reason Zend exists, is that we do LTS that gives you additional lives of time beyond what the community provides.