Harbor
Open-source container image registry with built-in security, signing, and vulnerability scanning for cloud-native environments
- Also known as
- harbor
What is Harbor?
A self-hosted Docker Distribution extension that provides centralized storage for container images and Helm charts with integrated security features including image signing, vulnerability scanning, user authentication, access control, and cross-registry replication.
Harbor pricing
We don't have Harbor's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.
What Harbor does
The capabilities that matter for container registries, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- Hosting
- Self-hosted only
- OCI Distribution Spec compliant
- ✓
- Artifact types
- Images + Helm/OCI artifacts
- Built-in vulnerability scanning
- ✓
- Image signing (Cosign/Notation)
- ✓
- SBOM generation / storage
- -
- Fine-grained RBAC / robot accounts
- ✓
- Private repositories
- ✓
- Geo-replication / mirroring
- ✓
- Pull-through cache / proxy
- ✓
- Native cloud IAM integration
- -
- Pull-rate limits
- -
- Web UI / console
- ✓
- High-availability deployment
- ✓
Platform & deployment
Independently observed- CLI
- Web
- Self-hosted
Integrations (8)
Independently observed- LDAP←•
- Active Directory←•
- Trivy
- Cosign
- Redis
- Valkey
- Docker→•
- Helm→•
Security & compliance
Known vulnerabilities: 1 (0 in the last 12 months), max severity HIGH sourcea count reflects scale & disclosure, not quality
Harbor FAQ
Common questions about Harbor, answered from independent, dated evidence.
What is Harbor?
Harbor is an open source registry that secures artifacts with policies and role-based access control, ensures images are scanned and free from vulnerabilities, and signs images as trusted. It is indexed under Container Registries.
Source: https://goharbor.io
Is Harbor free to use?
Harbor is open source, so it can be self-hosted and used at no licence cost. It is released under the Apache-2.0 licence. Pricing changes often, so verify at source before relying on it.
Source: https://goharbor.io
What platforms does Harbor support?
Harbor supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.
Source: https://goharbor.io
Can Harbor be self-hosted?
Yes. Harbor can be deployed self-hosted, so it does not have to run on the vendor's infrastructure.
Source: https://goharbor.io
What does Harbor integrate with?
We have confirmed 4 integrations for Harbor, including Trivy, Cosign, Redis and Valkey. This is what we could verify from public sources, so the vendor may support others we have not indexed.
Source: https://goharbor.io
Is Harbor open source?
Yes. Harbor is published under the Apache-2.0 licence, a permissive licence that generally allows commercial use and modification. Licence terms can change between releases, so verify against the repository for the version you intend to use.
Harbor alternatives
Other container registries we track, ranked by the same independent score.
- Google Artifact RegistryA hosted repository service for organizing and managing build artifacts and package dependencies across multiple formatsmedium · 54%
- Docker HubA central registry for storing, managing, and sharing container images with your team and the broader developer communityhigh · 75%
- CloudsmithUniversal registry platform with integrated security scanning for managing artifacts across your software supply chainmedium · 52%
- Azure Container RegistryHosted storage for containerized application imagesmedium · 53%
- CNCF DistributionA cloud-hosted registry for discovering, publishing, and managing containerized applicationsmedium · 67%
- Chainguard RegistryContainer images and open source packages maintained without known vulnerabilitiesmedium · 73%
Compare Harbor
Side by side against other container registries, attribute by attribute, with a source on every value.
The vioscaleAI score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Harbor, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Capabilities | 96 | 0.09 | 8.4 | ✓ |
| Release cadence | 99 | 0.07 | 6.7 | ✓ |
| Security score | 81 | 0.08 | 6.6 | ✓ |
| Development activity | 55 | 0.11 | 5.9 | ✓ |
| Stars | 84 | 0.03 | 2.3 | ✓ |
| Dependent projects | 25 | 0.07 | 1.7 | ✓ |
| Integrations | 24 | 0.05 | 1.3 | ✓ |
| Security posture | 0 | 0.18 | 0.0 | - |
| Package downloads | 0 | 0.15 | 0.0 | - |
| Developer Q&A activity | 0 | 0.05 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Activity
| Attribute | Value | Evidence |
|---|---|---|
| Commits last 30d | 53 | mediumsource · 2026-09-10 · 65% |
Adoption
Content
| Attribute | Value | Evidence |
|---|---|---|
| Faq | 6 items | mediumsource · 2026-09-10 · 66% |
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | Rbac: Yes · Web ui: Yes · Hosting: self · Image signing: Yes · Oci compliant: Yes · Private repos: Yes | mediumsource · 2026-09-10 · 60% |
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 6 | mediumsource · 2026-09-10 · 60% |
Language
| Attribute | Value | Evidence |
|---|---|---|
| Primary | Go | highsource · 2026-09-10 · 90% |
License
| Attribute | Value | Evidence |
|---|---|---|
| Spdx | Apache-2.0 | highsource · 2026-09-10 · 95% |
Pricing
Release
Reliability
| Attribute | Value | Evidence |
|---|---|---|
| Status page | Yes | mediumsource · 2026-08-05 · 60% |
Security
Is Harbor the right choice for you?
Tell us the job, the constraints and what you weigh most, and we will rank Harbor against the rest of the container registries we index, using the same dated evidence weighted your way.
Free to run, no account needed to start. How the evaluation works
Is this your product?
This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves Harbor up or down: nobody can buy rank here, including you.
Take the badge
Live, always current, and free to use on your own site. It shows Harbor's independent score and links back to this profile.
<a href="https://www.vioscale.ai/software/harbor" target="_blank" rel="noopener">
<img src="https://www.vioscale.ai/badge/software/harbor.svg" alt="Harbor, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>Markdown, for a README →
[](https://www.vioscale.ai/software/harbor)Claim the profile
Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing Harbor. Free, and it does not change the score.
- Correct anything wrong, with evidence
- Point our crawler at the pages that matter
- See which AI systems are reading this profile
Not the owner? How vendor profiles work