Ffile2fix
Sign in Get started

Fix Composer: zip extension and unzip/7z commands are both missing

Failed to download laravel/framework from dist: The zip extension and unzip/7z commands are both missing, skipping.
The php.ini used by your command-line PHP is: /etc/php/8.3/cli/php.ini
    Now trying to download from source

Composer downloads packages as ZIP files and needs either the PHP zip extension or a system unzip/7z command to unpack them. With neither available it falls back to cloning every package from source with git, which is slow and fails if git is missing or the repository needs credentials.

Also appears as: As there is no 'unzip' nor '7z' command installed zip files are being unpacked using the PHP zip extension. · The zip extension and unzip/7z commands are both missing, skipping. · Failed to clone the https://github.com/vendor/package.git repository, try running in interactive mode so that you can enter your GitHub credentials · git was not found in your PATH, skipping source download

Common causes

  • A fresh VPS, container or CI image without the unzip package installed
  • The PHP zip extension is not installed for the CLI PHP (php-zip is per version, e.g. php8.3-zip)
  • The extension is enabled for the web server's php.ini but not the CLI php.ini shown in the message
  • Minimal Docker images (php:*-cli, alpine) that do not include libzip or unzip by default
  • A Windows PHP install with extension=zip still commented out

How to fix it

  1. Install the unzip command. This is the preferred fix because it is faster than the PHP extension: sudo apt install unzip on Debian/Ubuntu, sudo dnf install unzip on RHEL/AlmaLinux, apk add unzip on Alpine.
  2. Install the PHP zip extension too. Install the package for your CLI version, e.g. sudo apt install php8.3-zip, and confirm with php -m | grep zip.
  3. Check the php.ini Composer reports. The message prints the CLI php.ini path. If you enable zip by editing php.ini (Windows), edit that exact file, not the one for Apache or FPM.
  4. Fix it in Docker or CI. Add unzip and the zip extension to your image (see the snippet) so CI does not fall back to source downloads and hit GitHub rate limits.
  5. Clear the cache and retry. Run composer clear-cache, delete the partially installed vendor/ folder and run composer install again. Packages should now show 'Extracting archive'.

Dockerfile (php:8.3-cli)

FROM php:8.3-cli
RUN apt-get update \
 && apt-get install -y --no-install-recommends git unzip libzip-dev \
 && docker-php-ext-install zip \
 && rm -rf /var/lib/apt/lists/*
COPY --from=composer:2 /usr/bin/composer /usr/bin/composer

How to stop it happening again

  • Include unzip, git and php-zip in every server provisioning script and Docker base image
  • Run composer diagnose on new environments before the first deploy
  • Cache Composer's download cache in CI to reduce repeated downloads

Frequently asked questions

Is the warning about using the PHP zip extension a problem?

No. 'As there is no unzip nor 7z command installed zip files are being unpacked using the PHP zip extension' is just advice; installs work, but installing unzip is faster and preserves file permissions better.

Why does Composer then ask for GitHub credentials?

Falling back to source means git cloning each package, which can hit GitHub's anonymous rate limits or private repositories. Installing unzip lets Composer use dist archives and avoids this.

I am on shared hosting without root. What can I do?

Enable the zip extension in the panel's PHP extension selector, which usually applies to the CLI too, or run composer install locally and upload vendor/ as a single archive.