# Google Artifact Registry vs Zot

**Leader by Vioscale score:** Google Artifact Registry

| Attribute | Google Artifact Registry | Zot |
|---|---|---|
| **Vioscale score** | 70.2 (54% (medium)) | 53.4 (78% (high)) |
| activity.commits_last_30d | - | 54 |
| adoption.dependent_repos | - | 0 |
| adoption.github_stars | - | 2,659 |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"self_hosted":true}` |
| description.long | A cloud-based package manager that stores, secures, and distributes various types of build artifacts, including container images and language-specific packages, with support for multiple package formats and registries. | A lightweight, self-contained registry for managing container images that fully implements OCI standards. It runs as a single binary without elevated privileges and includes built-in security scanning, access control, garbage collection, and image deduplication. |
| features.capabilities | `{"rbac":true,"web_ui":true,"hosting":"cloud","private_repos":true,"artifact_types":"universal","cloud_iam_native":true}` | `{"rbac":true,"hosting":"both","oci_compliant":true,"private_repos":true,"artifact_types":"images","vulnerability_scanning":true}` |
| integrations.count | - | 1 |
| integrations.list | - | `[{"name":"Stacker"}]` |
| language.primary | - | Go |
| license.spdx | - | Apache-2.0 |
| market.availability | `{"hqCountry":"US","primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | - |
| platform.support | `{"web":true}` | `{"cli":true,"mac":true,"linux":true}` |
| pricing | `{"type":"usage","plans":[{"free":true,"name":"Storage","summary":"Free 0–0.5 GiB/mo; $0.000136986/GiB/hr above","features":["Regional repositories","Multi-regional repositories","Standard and remote repositories"],"commitment":"monthly","components":[{"per":{"qty":1,"unit":"gibibyte"},"kind":"metered","amount":0.000136986,"currency":"USD"}],"description":"At-rest artifact storage","contactSales":false,"includedLimits":{"storage":"0.5 GiB/month free"}},{"free":true,"name":"Data Transfer","summary":"$0–$0.15/GiB depending on region; free within same location/continent","features":["Free same-location transfers","Free same-continent transfers","Metered cross-region pricing"],"commitment":"monthly","components":[{"per":{"qty":1,"unit":"gibibyte"},"kind":"metered","note":"US/Canada inter-region","amount":0.01,"currency":"USD"},{"per":{"qty":1,"unit":"gibibyte"},"kind":"metered","note":"Europe inter-region","amount":0.02,"currency":"USD"},{"per":{"qty":1,"unit":"gibibyte"},"kind":"metered","note":"Asia inter-region","amount":0.05,"currency":"USD"},{"per":{"qty":1,"unit":"gibibyte"},"kind":"metered","note":"Cross-continent","amount":0.08,"currency":"USD"},{"per":{"qty":1,"unit":"gibibyte"},"kind":"metered","note":"Oceania","amount":0.15,"currency":"USD"}],"description":"Outbound traffic from repositories","contactSales":false,"includedLimits":{"data_transfer_free":"Same location, same continent"}},{"free":false,"name":"Vulnerability Scanning","summary":"See Artifact Analysis pricing documentation","features":["Automatic vulnerability scanning","On-Demand Scanning"],"commitment":"monthly","description":"Automatic and on-demand container scanning","contactSales":false}],"summary":"Usage-based. Free tier: 0.5 GiB storage/month. Metered storage $0.000136986/GiB/hr, data transfer $0–$0.15/GiB, vulnerability scanning per Artifact Analysis docs.","currency":"USD","freeTier":true,"sourceUrl":"https://cloud.google.com/artifact-registry","retrievedAt":"2026-08-05T13:22:08.459Z","billingPeriods":["month"]}` | `{"type":"open_source","freeTier":true,"sourceUrl":"https://zotregistry.dev","retrievedAt":"2026-08-03T13:02:43.251Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | free | open_source |
| pricing.price_level | free | free |
| pricing.transparent | yes | yes |
| release.cadence_days | - | 29 |
| release.history | - | `[{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.20","date":"2026-08-04T17:51:30Z","type":"stable","version":"v2.1.20"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.19","date":"2026-08-04T06:46:22Z","type":"stable","version":"v2.1.19"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.18","date":"2026-06-24T15:30:19Z","type":"stable","version":"v2.1.18"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.17","date":"2026-05-18T05:44:37Z","type":"stable","version":"v2.1.17"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.16","date":"2026-04-19T06:26:29Z","type":"stable","version":"v2.1.16"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.15","date":"2026-03-08T22:31:57Z","type":"stable","version":"v2.1.15"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.14","date":"2026-01-25T17:14:38Z","type":"stable","version":"v2.1.14"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.13","date":"2025-12-23T10:14:48Z","type":"stable","version":"v2.1.13"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.12","date":"2025-12-21T20:45:14Z","type":"stable","version":"v2.1.12"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.11","date":"2025-11-20T20:14:44Z","type":"stable","version":"v2.1.11"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.10","date":"2025-10-18T18:46:36Z","type":"stable","version":"v2.1.10"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.9","date":"2025-10-14T16:18:49Z","type":"stable","version":"v2.1.9"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.8","date":"2025-09-01T19:20:42Z","type":"stable","version":"v2.1.8"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.7","date":"2025-08-03T16:35:59Z","type":"stable","version":"v2.1.7"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.6","date":"2025-07-27T01:14:14Z","type":"stable","version":"v2.1.6"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.5","date":"2025-06-17T18:04:11Z","type":"stable","version":"v2.1.5"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.4","date":"2025-06-06T02:31:04Z","type":"stable","version":"v2.1.4"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.3","date":"2025-05-22T17:04:49Z","type":"stable","version":"v2.1.3"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.3-rc6","date":"2025-05-02T19:50:48Z","type":"prerelease","version":"v2.1.3-rc6"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.3-rc5","date":"2025-04-17T17:00:51Z","type":"prerelease","version":"v2.1.3-rc5"}]` |
| reliability.status_page | yes | - |
| security.scorecard | - | 8.2 |
| security.vulnerabilities | - | `{"count":1,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=zotregistry.dev%2Fzot%2Fv2&per_page=100","last_12m":1,"max_severity":"HIGH"}` |

## Capabilities (Container Registries)

| Capability | Google Artifact Registry | Zot |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Standards** |  |  |
| OCI Distribution Spec compliant | - | ✓ |
| **Scope** |  |  |
| Artifact types | Universal (images + language packages) | Container images only |
| **Security** |  |  |
| Built-in vulnerability scanning | - | ✓ |
| Image signing (Cosign/Notation) | - | - |
| SBOM generation / storage | - | - |
| **Access** |  |  |
| Fine-grained RBAC / robot accounts | ✓ | ✓ |
| Private repositories | ✓ | ✓ |
| **Distribution** |  |  |
| Geo-replication / mirroring | - | - |
| Pull-through cache / proxy | - | - |
| **Integration** |  |  |
| Native cloud IAM integration | ✓ | - |
| **Pricing** |  |  |
| Pull-rate limits | - | - |
| **UX** |  |  |
| Web UI / console | ✓ | - |
| **Ops** |  |  |
| High-availability deployment | - | - |

*Source: Vioscale. Generated 2026-09-01T17:10:36.765Z. "-" = undocumented, not absent.*
