# Amazon ECR vs CNCF Distribution

**Leader by Vioscale score:** CNCF Distribution

| Attribute | Amazon ECR | CNCF Distribution |
|---|---|---|
| **Vioscale score** | 48.8 (73% (medium)) | 57.6 (66% (medium)) |
| activity.commits_last_30d | - | 8 |
| adoption.dependent_repos | - | 2,403 |
| adoption.github_stars | - | 10,582 |
| deployment.options | `{"cloud":true}` | `{"on_prem":true,"self_hosted":true}` |
| description.long | Amazon ECR is a managed service that stores Docker container images and OCI artifacts with high availability. It integrates with AWS compute services, offers both private and public repositories, and includes built-in encryption, access controls via IAM, and vulnerability scanning through Amazon Inspector. | Open-source implementation of the OCI Distribution Specification for storing and distributing container images. Enables organizations to tightly control their image storage and distribution pipeline with full ownership of their distribution infrastructure. |
| features.capabilities | `{"rbac":true,"web_ui":true,"hosting":"cloud","image_signing":true,"oci_compliant":true,"private_repos":true,"artifact_types":"images_helm","cloud_iam_native":true,"pull_rate_limits":"tiered","high_availability":true,"pull_through_cache":true,"replication_mirroring":true,"vulnerability_scanning":true}` | `{"hosting":"self","image_signing":true,"oci_compliant":true,"private_repos":true,"artifact_types":"images"}` |
| integrations.count | 10 | - |
| integrations.list | `[{"name":"Amazon ECS"},{"name":"Amazon EKS"},{"name":"Amazon EC2"},{"name":"AWS Lambda"},{"name":"AWS Fargate"},{"name":"AWS App Runner"},{"name":"Amazon Inspector"},{"name":"AWS Marketplace"},{"name":"Docker CLI"},{"name":"Helm"}]` | - |
| language.primary | - | Go |
| license.spdx | - | Apache-2.0 |
| market.availability | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | - |
| platform.support | `{"cli":true,"web":true}` | - |
| pricing | `{"type":"usage","plans":[{"free":false,"name":"Private Repository Storage","summary":"$0.10 per GB per month","features":["Private repository storage"],"components":[{"per":{"qty":1,"unit":"gb"},"kind":"metered","amount":0.1,"period":"month","currency":"USD"}],"description":"Storage for private container repositories","contactSales":false},{"free":true,"name":"Public Repository (Always Free)","summary":"Always free","features":["50 GB/month storage included","500 GB/month anonymous data transfer","5 TB/month data transfer with AWS account"],"description":"Always-free storage and transfer for public repositories","contactSales":false,"includedLimits":{"storage":"50 GB/month","anonymous_transfer":"500 GB/month","authenticated_transfer":"5 TB/month"}},{"free":false,"name":"Data Transfer (Beyond Free Limits)","summary":"Tiered starting at $0.09 per GB","features":["Tiered outbound data transfer pricing"],"components":[{"per":{"qty":1,"unit":"gb"},"kind":"metered","amount":0.09,"period":"month","currency":"USD"}],"description":"Pay for outbound data transfer beyond free tier limits","contactSales":false}],"summary":"Free: 50 GB/month public storage always-free, 500 MB/month private for 1 year. Paid: $0.10/GB for private storage, tiered data transfer charges.","currency":"USD","freeTier":true,"sourceUrl":"https://aws.amazon.com/ecr/pricing/","retrievedAt":"2026-08-14T11:06:02.938Z","startingPrice":{"amount":0.09,"period":"month","currency":"USD"},"billingPeriods":["month"]}` | `{"type":"open_source","sourceUrl":"https://distribution.github.io/distribution/","retrievedAt":"2026-08-13T18:17:59.377Z"}` |
| pricing.free_tier | yes | - |
| pricing.model | freemium | open_source |
| pricing.price_level | low | free |
| pricing.transparent | yes | - |
| release.cadence_days | - | 55 |
| release.history | - | `[{"url":"https://github.com/distribution/distribution/releases/tag/v3.1.1","date":"2026-05-01T15:51:50Z","type":"stable","version":"v3.1.1"},{"url":"https://github.com/distribution/distribution/releases/tag/v3.1.0","date":"2026-04-06T17:09:31Z","type":"stable","version":"v3.1.0"},{"url":"https://github.com/distribution/distribution/releases/tag/v3.0.0","date":"2025-04-03T06:25:36Z","type":"stable","version":"v3.0.0"},{"url":"https://github.com/distribution/distribution/releases/tag/v3.0.0-rc.4","date":"2025-03-22T14:59:29Z","type":"prerelease","version":"v3.0.0-rc.4"},{"url":"https://github.com/distribution/distribution/releases/tag/v3.0.0-rc.3","date":"2025-02-11T16:21:07Z","type":"prerelease","version":"v3.0.0-rc.3"},{"url":"https://github.com/distribution/distribution/releases/tag/v3.0.0-rc.2","date":"2024-12-18T15:23:19Z","type":"prerelease","version":"v3.0.0-rc.2"},{"url":"https://github.com/distribution/distribution/releases/tag/v3.0.0-rc.1","date":"2024-11-07T21:04:41Z","type":"prerelease","version":"v3.0.0-rc.1"},{"url":"https://github.com/distribution/distribution/releases/tag/v3.0.0-beta.1","date":"2024-07-10T13:22:40Z","type":"prerelease","version":"v3.0.0-beta.1"},{"url":"https://github.com/distribution/distribution/releases/tag/v3.0.0-alpha.1","date":"2023-12-19T16:03:36Z","type":"prerelease","version":"v3.0.0-alpha.1"},{"url":"https://github.com/distribution/distribution/releases/tag/v2.8.3","date":"2023-10-02T18:23:54Z","type":"stable","version":"v2.8.3"},{"url":"https://github.com/distribution/distribution/releases/tag/v2.8.2","date":"2023-05-11T10:47:43Z","type":"stable","version":"v2.8.2"},{"url":"https://github.com/distribution/distribution/releases/tag/v2.8.2-beta.2","date":"2023-05-09T23:32:56Z","type":"prerelease","version":"v2.8.2-beta.2"},{"url":"https://github.com/distribution/distribution/releases/tag/v2.8.2-beta.1","date":"2023-05-09T22:42:12Z","type":"prerelease","version":"v2.8.2-beta.1"},{"url":"https://github.com/distribution/distribution/releases/tag/v2.8.1","date":"2022-03-08T18:19:10Z","type":"stable","version":"v2.8.1"},{"url":"https://github.com/distribution/distribution/releases/tag/v2.8.0","date":"2022-02-07T15:53:07Z","type":"stable","version":"v2.8.0"},{"url":"https://github.com/distribution/distribution/releases/tag/v2.8.0-beta.1","date":"2022-01-21T16:49:13Z","type":"prerelease","version":"v2.8.0-beta.1"},{"url":"https://github.com/distribution/distribution/releases/tag/v2.7.1","date":"2019-01-17T23:22:32Z","type":"stable","version":"v2.7.1"},{"url":"https://github.com/distribution/distribution/releases/tag/v2.7.0","date":"2018-12-04T00:20:01Z","type":"stable","version":"v2.7.0"},{"url":"https://github.com/distribution/distribution/releases/tag/v2.7.0-rc.0","date":"2018-09-28T23:23:36Z","type":"prerelease","version":"v2.7.0-rc.0"},{"url":"https://github.com/distribution/distribution/releases/tag/v2.6.2","date":"2017-07-20T21:20:00Z","type":"stable","version":"v2.6.2"}]` |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | - |
| security.gdpr | yes | - |
| security.pci | yes | - |
| security.scorecard | - | 7.9 |
| security.vulnerabilities | - | `{"count":4,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fdistribution%2Fdistribution%2Fv3&per_page=100","last_12m":3,"max_severity":"HIGH"}` |

## Capabilities (Container Registries)

| Capability | Amazon ECR | CNCF Distribution |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud only | Self-hosted only |
| **Standards** |  |  |
| OCI Distribution Spec compliant | ✓ | ✓ |
| **Scope** |  |  |
| Artifact types | Images + Helm/OCI artifacts | Container images only |
| **Security** |  |  |
| Built-in vulnerability scanning | ✓ | - |
| Image signing (Cosign/Notation) | ✓ | ✓ |
| SBOM generation / storage | - | - |
| **Access** |  |  |
| Fine-grained RBAC / robot accounts | ✓ | - |
| Private repositories | ✓ | ✓ |
| **Distribution** |  |  |
| Geo-replication / mirroring | ✓ | - |
| Pull-through cache / proxy | ✓ | - |
| **Integration** |  |  |
| Native cloud IAM integration | ✓ | - |
| **Pricing** |  |  |
| Pull-rate limits | Tiered by plan | - |
| **UX** |  |  |
| Web UI / console | ✓ | - |
| **Ops** |  |  |
| High-availability deployment | ✓ | - |

*Source: Vioscale. Generated 2026-09-01T14:44:58.604Z. "-" = undocumented, not absent.*
