What is Harbor?
Harbor is an open source registry that secures artifacts with policies and role-based access control, ensures images are scanned and free from vulnerabilities, and signs images as trusted.
Harbor pricing
We don't have Harbor's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.
What Harbor does
The capabilities that matter for container registries, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- Hosting
- Self-hosted only
- OCI Distribution Spec compliant
- -
- Artifact types
- Container images only
- Built-in vulnerability scanning
- ✓
- Image signing (Cosign/Notation)
- ✓
- SBOM generation / storage
- -
- Fine-grained RBAC / robot accounts
- ✓
- Private repositories
- ✓
- Geo-replication / mirroring
- ✓
- Pull-through cache / proxy
- -
- Native cloud IAM integration
- -
- Pull-rate limits
- -
- Web UI / console
- ✓
- High-availability deployment
- -
Platform & deployment
Independently observed- CLI
- Web
- On-premise
- Self-hosted
Harbor alternatives
Other container registries we track, ranked by the same independent score.
- Docker HubFind and share container images with your teamlow · 28%
- CloudsmithCloud-Native Artifact Management Platformlow · 39%
- DistributionStateless, highly scalable open-source container image registry serverlow · 3%
- Google Artifact Registrylow · 21%
- Chainguard RegistryThe trusted source for open sourcemedium · 50%
- DigitalOcean Container RegistryStore and manage your private container images in a registry co-located with DigitalOcean Kubernetes clusterslow · 21%
The Vioscale score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Harbor, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Capabilities | 81 | 0.11 | 9.0 | ✓ |
| Release Cadence | 98 | 0.08 | 7.8 | ✓ |
| Github Activity | 49 | 0.13 | 6.2 | ✓ |
| Github Stars | 84 | 0.03 | 2.7 | ✓ |
| Integrations | 0 | 0.06 | 0.0 | - |
| Security Posture | 0 | 0.21 | 0.0 | - |
| Package Downloads | 0 | 0.17 | 0.0 | - |
| Stackoverflow Activity | 0 | 0.06 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Activity
| Attribute | Value | Evidence |
|---|---|---|
| Commits last 30d | 35 | mediumsource · 2026-08-01 · 65% |
Adoption
| Attribute | Value | Evidence |
|---|---|---|
| Github stars | 29,065 | highsource · 2026-08-01 · 90% |
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | {"rbac":true,"web_ui":true,"hosting":"self","image_signing":true,"private_repos":true,"artifact_types":"images","replication_mirroring":true,"vulnerability_scanning":true} | mediumsource · 2026-08-05 · 60% |
Language
| Attribute | Value | Evidence |
|---|---|---|
| Primary | Go | highsource · 2026-08-01 · 90% |
License
| Attribute | Value | Evidence |
|---|---|---|
| Spdx | Apache-2.0 | highsource · 2026-08-01 · 95% |
Pricing
Release
| Attribute | Value | Evidence |
|---|---|---|
| Cadence days | 3 | mediumsource · 2026-08-01 · 70% |
Reliability
| Attribute | Value | Evidence |
|---|---|---|
| Status page | Yes | mediumsource · 2026-08-05 · 60% |