# Amazon ECR vs Zot

| Attribute | Amazon ECR | Zot |
|---|---|---|
| **Vioscale score** | 48.8 (73% (medium)) | 53.4 (78% (high)) |
| activity.commits_last_30d | - | 54 |
| adoption.dependent_repos | - | 0 |
| adoption.github_stars | - | 2,659 |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"self_hosted":true}` |
| description.long | Amazon ECR is a managed service that stores Docker container images and OCI artifacts with high availability. It integrates with AWS compute services, offers both private and public repositories, and includes built-in encryption, access controls via IAM, and vulnerability scanning through Amazon Inspector. | A lightweight, self-contained registry for managing container images that fully implements OCI standards. It runs as a single binary without elevated privileges and includes built-in security scanning, access control, garbage collection, and image deduplication. |
| features.capabilities | `{"rbac":true,"web_ui":true,"hosting":"cloud","image_signing":true,"oci_compliant":true,"private_repos":true,"artifact_types":"images_helm","cloud_iam_native":true,"pull_rate_limits":"tiered","high_availability":true,"pull_through_cache":true,"replication_mirroring":true,"vulnerability_scanning":true}` | `{"rbac":true,"hosting":"both","oci_compliant":true,"private_repos":true,"artifact_types":"images","vulnerability_scanning":true}` |
| integrations.count | 10 | 1 |
| integrations.list | `[{"name":"Amazon ECS"},{"name":"Amazon EKS"},{"name":"Amazon EC2"},{"name":"AWS Lambda"},{"name":"AWS Fargate"},{"name":"AWS App Runner"},{"name":"Amazon Inspector"},{"name":"AWS Marketplace"},{"name":"Docker CLI"},{"name":"Helm"}]` | `[{"name":"Stacker"}]` |
| language.primary | - | Go |
| license.spdx | - | Apache-2.0 |
| market.availability | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | - |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"mac":true,"linux":true}` |
| pricing | `{"type":"usage","plans":[{"free":false,"name":"Private Repository Storage","summary":"$0.10 per GB per month","features":["Private repository storage"],"components":[{"per":{"qty":1,"unit":"gb"},"kind":"metered","amount":0.1,"period":"month","currency":"USD"}],"description":"Storage for private container repositories","contactSales":false},{"free":true,"name":"Public Repository (Always Free)","summary":"Always free","features":["50 GB/month storage included","500 GB/month anonymous data transfer","5 TB/month data transfer with AWS account"],"description":"Always-free storage and transfer for public repositories","contactSales":false,"includedLimits":{"storage":"50 GB/month","anonymous_transfer":"500 GB/month","authenticated_transfer":"5 TB/month"}},{"free":false,"name":"Data Transfer (Beyond Free Limits)","summary":"Tiered starting at $0.09 per GB","features":["Tiered outbound data transfer pricing"],"components":[{"per":{"qty":1,"unit":"gb"},"kind":"metered","amount":0.09,"period":"month","currency":"USD"}],"description":"Pay for outbound data transfer beyond free tier limits","contactSales":false}],"summary":"Free: 50 GB/month public storage always-free, 500 MB/month private for 1 year. Paid: $0.10/GB for private storage, tiered data transfer charges.","currency":"USD","freeTier":true,"sourceUrl":"https://aws.amazon.com/ecr/pricing/","retrievedAt":"2026-08-14T11:06:02.938Z","startingPrice":{"amount":0.09,"period":"month","currency":"USD"},"billingPeriods":["month"]}` | `{"type":"open_source","freeTier":true,"sourceUrl":"https://zotregistry.dev","retrievedAt":"2026-08-03T13:02:43.251Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | open_source |
| pricing.price_level | low | free |
| pricing.transparent | yes | yes |
| release.cadence_days | - | 29 |
| release.history | - | `[{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.20","date":"2026-08-04T17:51:30Z","type":"stable","version":"v2.1.20"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.19","date":"2026-08-04T06:46:22Z","type":"stable","version":"v2.1.19"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.18","date":"2026-06-24T15:30:19Z","type":"stable","version":"v2.1.18"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.17","date":"2026-05-18T05:44:37Z","type":"stable","version":"v2.1.17"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.16","date":"2026-04-19T06:26:29Z","type":"stable","version":"v2.1.16"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.15","date":"2026-03-08T22:31:57Z","type":"stable","version":"v2.1.15"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.14","date":"2026-01-25T17:14:38Z","type":"stable","version":"v2.1.14"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.13","date":"2025-12-23T10:14:48Z","type":"stable","version":"v2.1.13"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.12","date":"2025-12-21T20:45:14Z","type":"stable","version":"v2.1.12"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.11","date":"2025-11-20T20:14:44Z","type":"stable","version":"v2.1.11"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.10","date":"2025-10-18T18:46:36Z","type":"stable","version":"v2.1.10"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.9","date":"2025-10-14T16:18:49Z","type":"stable","version":"v2.1.9"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.8","date":"2025-09-01T19:20:42Z","type":"stable","version":"v2.1.8"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.7","date":"2025-08-03T16:35:59Z","type":"stable","version":"v2.1.7"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.6","date":"2025-07-27T01:14:14Z","type":"stable","version":"v2.1.6"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.5","date":"2025-06-17T18:04:11Z","type":"stable","version":"v2.1.5"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.4","date":"2025-06-06T02:31:04Z","type":"stable","version":"v2.1.4"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.3","date":"2025-05-22T17:04:49Z","type":"stable","version":"v2.1.3"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.3-rc6","date":"2025-05-02T19:50:48Z","type":"prerelease","version":"v2.1.3-rc6"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.3-rc5","date":"2025-04-17T17:00:51Z","type":"prerelease","version":"v2.1.3-rc5"}]` |
| reliability.status_page | yes | - |
| security.disclosure_policy | yes | - |
| security.gdpr | yes | - |
| security.pci | yes | - |
| security.scorecard | - | 8.2 |
| security.vulnerabilities | - | `{"count":1,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=zotregistry.dev%2Fzot%2Fv2&per_page=100","last_12m":1,"max_severity":"HIGH"}` |

## Capabilities (Container Registries)

| Capability | Amazon ECR | Zot |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Standards** |  |  |
| OCI Distribution Spec compliant | ✓ | ✓ |
| **Scope** |  |  |
| Artifact types | Images + Helm/OCI artifacts | Container images only |
| **Security** |  |  |
| Built-in vulnerability scanning | ✓ | ✓ |
| Image signing (Cosign/Notation) | ✓ | - |
| SBOM generation / storage | - | - |
| **Access** |  |  |
| Fine-grained RBAC / robot accounts | ✓ | ✓ |
| Private repositories | ✓ | ✓ |
| **Distribution** |  |  |
| Geo-replication / mirroring | ✓ | - |
| Pull-through cache / proxy | ✓ | - |
| **Integration** |  |  |
| Native cloud IAM integration | ✓ | - |
| **Pricing** |  |  |
| Pull-rate limits | Tiered by plan | - |
| **UX** |  |  |
| Web UI / console | ✓ | - |
| **Ops** |  |  |
| High-availability deployment | ✓ | - |

*Source: Vioscale. Generated 2026-09-01T17:31:00.422Z. "-" = undocumented, not absent.*
