# Pulp vs Zot

**Leader by Vioscale score:** Zot

| Attribute | Pulp | Zot |
|---|---|---|
| **Vioscale score** | 43.7 (60% (medium)) | 53.4 (78% (high)) |
| activity.commits_last_30d | 49 | 54 |
| adoption.dependent_repos | 65 | 0 |
| adoption.github_stars | 586 | 2,659 |
| deployment.options | `{"cloud":true,"on_prem":true,"self_hosted":true}` | `{"cloud":true,"self_hosted":true}` |
| description.long | Pulp enables developers and operators to fetch, upload, organize, and distribute software packages across on-premises infrastructure or cloud environments. It supports multiple content types through a plugin architecture and provides tools for repository management at scale. | A lightweight, self-contained registry for managing container images that fully implements OCI standards. It runs as a single binary without elevated privileges and includes built-in security scanning, access control, garbage collection, and image deduplication. |
| features.capabilities | `{"rbac":false,"web_ui":true,"hosting":"both","sbom_support":false,"image_signing":false,"oci_compliant":true,"private_repos":true,"artifact_types":"universal","cloud_iam_native":false,"pull_rate_limits":"none","high_availability":false,"pull_through_cache":false,"replication_mirroring":false,"vulnerability_scanning":false}` | `{"rbac":true,"hosting":"both","oci_compliant":true,"private_repos":true,"artifact_types":"images","vulnerability_scanning":true}` |
| integrations.count | 2 | 1 |
| integrations.list | `[{"name":"OpenAI API"},{"name":"GitHub"}]` | `[{"name":"Stacker"}]` |
| language.primary | Python | Go |
| license.spdx | GPL-2.0 | Apache-2.0 |
| market.availability | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | - |
| platform.support | `{"cli":true}` | `{"cli":true,"mac":true,"linux":true}` |
| pricing | `{"type":"open_source","freeTier":true,"sourceUrl":"https://pulpproject.org","retrievedAt":"2026-08-16T21:32:46.974Z"}` | `{"type":"open_source","freeTier":true,"sourceUrl":"https://zotregistry.dev","retrievedAt":"2026-08-03T13:02:43.251Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | open_source | open_source |
| pricing.price_level | free | free |
| pricing.transparent | yes | yes |
| release.cadence_days | - | 29 |
| release.history | `[{"url":"https://github.com/pulp/pulpcore/releases/tag/3.116.0","date":"2026-08-12T18:28:59Z","type":"stable","version":"3.116.0"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.16","date":"2026-08-12T16:55:30Z","type":"stable","version":"3.105.16"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.85.28","date":"2026-07-29T15:10:38Z","type":"stable","version":"3.85.28"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.63.45","date":"2026-07-29T15:11:51Z","type":"stable","version":"3.63.45"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.49.68","date":"2026-07-29T15:11:41Z","type":"stable","version":"3.49.68"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.3","date":"2026-07-28T20:41:04Z","type":"stable","version":"3.115.3"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.15","date":"2026-07-28T20:40:51Z","type":"stable","version":"3.105.15"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.14","date":"2026-07-28T08:02:29Z","type":"stable","version":"3.105.14"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.85.27","date":"2026-07-28T20:40:30Z","type":"stable","version":"3.85.27"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.73.41","date":"2026-07-28T20:40:26Z","type":"stable","version":"3.73.41"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.63.44","date":"2026-07-28T20:39:47Z","type":"stable","version":"3.63.44"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.49.67","date":"2026-07-28T20:39:20Z","type":"stable","version":"3.49.67"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.13","date":"2026-07-27T14:15:34Z","type":"stable","version":"3.105.13"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.2","date":"2026-07-22T12:50:08Z","type":"stable","version":"3.115.2"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.1","date":"2026-07-21T17:06:56Z","type":"stable","version":"3.115.1"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.0","date":"2026-07-21T15:16:40Z","type":"stable","version":"3.115.0"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.114.2","date":"2026-07-20T17:19:08Z","type":"stable","version":"3.114.2"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.12","date":"2026-07-20T17:20:16Z","type":"stable","version":"3.105.12"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.85.26","date":"2026-07-20T17:20:28Z","type":"stable","version":"3.85.26"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.73.40","date":"2026-07-20T17:21:51Z","type":"stable","version":"3.73.40"}]` | `[{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.20","date":"2026-08-04T17:51:30Z","type":"stable","version":"v2.1.20"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.19","date":"2026-08-04T06:46:22Z","type":"stable","version":"v2.1.19"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.18","date":"2026-06-24T15:30:19Z","type":"stable","version":"v2.1.18"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.17","date":"2026-05-18T05:44:37Z","type":"stable","version":"v2.1.17"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.16","date":"2026-04-19T06:26:29Z","type":"stable","version":"v2.1.16"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.15","date":"2026-03-08T22:31:57Z","type":"stable","version":"v2.1.15"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.14","date":"2026-01-25T17:14:38Z","type":"stable","version":"v2.1.14"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.13","date":"2025-12-23T10:14:48Z","type":"stable","version":"v2.1.13"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.12","date":"2025-12-21T20:45:14Z","type":"stable","version":"v2.1.12"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.11","date":"2025-11-20T20:14:44Z","type":"stable","version":"v2.1.11"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.10","date":"2025-10-18T18:46:36Z","type":"stable","version":"v2.1.10"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.9","date":"2025-10-14T16:18:49Z","type":"stable","version":"v2.1.9"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.8","date":"2025-09-01T19:20:42Z","type":"stable","version":"v2.1.8"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.7","date":"2025-08-03T16:35:59Z","type":"stable","version":"v2.1.7"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.6","date":"2025-07-27T01:14:14Z","type":"stable","version":"v2.1.6"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.5","date":"2025-06-17T18:04:11Z","type":"stable","version":"v2.1.5"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.4","date":"2025-06-06T02:31:04Z","type":"stable","version":"v2.1.4"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.3","date":"2025-05-22T17:04:49Z","type":"stable","version":"v2.1.3"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.3-rc6","date":"2025-05-02T19:50:48Z","type":"prerelease","version":"v2.1.3-rc6"},{"url":"https://github.com/project-zot/zot/releases/tag/v2.1.3-rc5","date":"2025-04-17T17:00:51Z","type":"prerelease","version":"v2.1.3-rc5"}]` |
| security.gdpr | yes | - |
| security.scorecard | - | 8.2 |
| security.vulnerabilities | `{"count":2,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=pulpcore&per_page=100","last_12m":0,"max_severity":"HIGH"}` | `{"count":1,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=zotregistry.dev%2Fzot%2Fv2&per_page=100","last_12m":1,"max_severity":"HIGH"}` |

## Capabilities (Container Registries)

| Capability | Pulp | Zot |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud + self-hosted | Cloud + self-hosted |
| **Standards** |  |  |
| OCI Distribution Spec compliant | ✓ | ✓ |
| **Scope** |  |  |
| Artifact types | Universal (images + language packages) | Container images only |
| **Security** |  |  |
| Built-in vulnerability scanning | ✗ | ✓ |
| Image signing (Cosign/Notation) | ✗ | - |
| SBOM generation / storage | ✗ | - |
| **Access** |  |  |
| Fine-grained RBAC / robot accounts | ✗ | ✓ |
| Private repositories | ✓ | ✓ |
| **Distribution** |  |  |
| Geo-replication / mirroring | ✗ | - |
| Pull-through cache / proxy | ✗ | - |
| **Integration** |  |  |
| Native cloud IAM integration | ✗ | - |
| **Pricing** |  |  |
| Pull-rate limits | None | - |
| **UX** |  |  |
| Web UI / console | ✓ | - |
| **Ops** |  |  |
| High-availability deployment | ✗ | - |

*Source: Vioscale. Generated 2026-09-01T15:02:03.944Z. "-" = undocumented, not absent.*
