# Chainguard Registry vs Pulp

**Leader by Vioscale score:** Chainguard Registry

| Attribute | Chainguard Registry | Pulp |
|---|---|---|
| **Vioscale score** | 57.9 (72% (medium)) | 43.7 (60% (medium)) |
| activity.commits_last_30d | - | 49 |
| adoption.dependent_repos | - | 65 |
| adoption.github_stars | - | 586 |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"on_prem":true,"self_hosted":true}` |
| description.long | Secure-by-default container images and open source libraries built from source with SLSA L3 compliance, designed to prevent AI attacks and minimize vulnerability surface in production environments. | Pulp enables developers and operators to fetch, upload, organize, and distribute software packages across on-premises infrastructure or cloud environments. It supports multiple content types through a plugin architecture and provides tools for repository management at scale. |
| features.capabilities | `{"web_ui":true,"hosting":"cloud","sbom_support":true,"private_repos":true,"artifact_types":"universal","vulnerability_scanning":true}` | `{"rbac":false,"web_ui":true,"hosting":"both","sbom_support":false,"image_signing":false,"oci_compliant":true,"private_repos":true,"artifact_types":"universal","cloud_iam_native":false,"pull_rate_limits":"none","high_availability":false,"pull_through_cache":false,"replication_mirroring":false,"vulnerability_scanning":false}` |
| integrations.count | 8 | 2 |
| integrations.list | `[{"name":"Cursor"},{"name":"AWS Security Hub"},{"name":"Wiz"},{"name":"GitHub"},{"name":"GitHub Actions"},{"name":"npm"},{"name":"SAP Cloud Application Programming Model"},{"name":"Kubernetes"}]` | `[{"name":"OpenAI API"},{"name":"GitHub"}]` |
| language.primary | - | Python |
| license.spdx | - | GPL-2.0 |
| market.availability | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true}` |
| pricing | `{"type":"hybrid","plans":[{"free":false,"name":"Catalog Pricing","features":["Unlimited image catalog access","All 10,000+ underlying packages","Custom Assembly for image customization","Private APK Repositories","EOL Grace Period (6 months extended support)"],"description":"Unlimited access to entire image catalog of 1,400+ images and 10,000+ packages with 50-100 new images built monthly. Scales based on containerized engineering organization size.","contactSales":true},{"free":false,"name":"Per-Image Pricing","features":["Specific image selection","Custom Assembly","Private APK Repositories"],"description":"Targeted pricing model for organizations with fixed application stacks or focused adoption","contactSales":true}],"summary":"Contact sales for quote. Free tier available with limited catalog access.","currency":"USD","freeTier":true,"sourceUrl":"https://www.chainguard.dev/unchained/unlock-the-full-chainguard-containers-catalog-now-with-a-catalog-pricing-option","retrievedAt":"2026-08-13T18:17:50.440Z"}` | `{"type":"open_source","freeTier":true,"sourceUrl":"https://pulpproject.org","retrievedAt":"2026-08-16T21:32:46.974Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | quote | open_source |
| pricing.price_level | low | free |
| pricing.transparent | no | yes |
| release.history | - | `[{"url":"https://github.com/pulp/pulpcore/releases/tag/3.116.0","date":"2026-08-12T18:28:59Z","type":"stable","version":"3.116.0"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.16","date":"2026-08-12T16:55:30Z","type":"stable","version":"3.105.16"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.85.28","date":"2026-07-29T15:10:38Z","type":"stable","version":"3.85.28"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.63.45","date":"2026-07-29T15:11:51Z","type":"stable","version":"3.63.45"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.49.68","date":"2026-07-29T15:11:41Z","type":"stable","version":"3.49.68"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.3","date":"2026-07-28T20:41:04Z","type":"stable","version":"3.115.3"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.15","date":"2026-07-28T20:40:51Z","type":"stable","version":"3.105.15"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.14","date":"2026-07-28T08:02:29Z","type":"stable","version":"3.105.14"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.85.27","date":"2026-07-28T20:40:30Z","type":"stable","version":"3.85.27"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.73.41","date":"2026-07-28T20:40:26Z","type":"stable","version":"3.73.41"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.63.44","date":"2026-07-28T20:39:47Z","type":"stable","version":"3.63.44"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.49.67","date":"2026-07-28T20:39:20Z","type":"stable","version":"3.49.67"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.13","date":"2026-07-27T14:15:34Z","type":"stable","version":"3.105.13"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.2","date":"2026-07-22T12:50:08Z","type":"stable","version":"3.115.2"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.1","date":"2026-07-21T17:06:56Z","type":"stable","version":"3.115.1"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.0","date":"2026-07-21T15:16:40Z","type":"stable","version":"3.115.0"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.114.2","date":"2026-07-20T17:19:08Z","type":"stable","version":"3.114.2"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.12","date":"2026-07-20T17:20:16Z","type":"stable","version":"3.105.12"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.85.26","date":"2026-07-20T17:20:28Z","type":"stable","version":"3.85.26"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.73.40","date":"2026-07-20T17:21:51Z","type":"stable","version":"3.73.40"}]` |
| reliability.status_page | yes | - |
| security.fedramp | yes | - |
| security.gdpr | yes | yes |
| security.hipaa | yes | - |
| security.pci | yes | - |
| security.soc2 | yes | - |
| security.vulnerabilities | - | `{"count":2,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=pulpcore&per_page=100","last_12m":0,"max_severity":"HIGH"}` |

## Capabilities (Container Registries)

| Capability | Chainguard Registry | Pulp |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Standards** |  |  |
| OCI Distribution Spec compliant | - | ✓ |
| **Scope** |  |  |
| Artifact types | Universal (images + language packages) | Universal (images + language packages) |
| **Security** |  |  |
| Built-in vulnerability scanning | ✓ | ✗ |
| Image signing (Cosign/Notation) | - | ✗ |
| SBOM generation / storage | ✓ | ✗ |
| **Access** |  |  |
| Fine-grained RBAC / robot accounts | - | ✗ |
| Private repositories | ✓ | ✓ |
| **Distribution** |  |  |
| Geo-replication / mirroring | - | ✗ |
| Pull-through cache / proxy | - | ✗ |
| **Integration** |  |  |
| Native cloud IAM integration | - | ✗ |
| **Pricing** |  |  |
| Pull-rate limits | - | None |
| **UX** |  |  |
| Web UI / console | ✓ | ✓ |
| **Ops** |  |  |
| High-availability deployment | - | ✗ |

*Source: Vioscale. Generated 2026-09-01T16:45:42.798Z. "-" = undocumented, not absent.*
