What is Zot?
A lightweight, self-contained registry for managing container images that fully implements OCI standards. It runs as a single binary without elevated privileges and includes built-in security scanning, access control, garbage collection, and image deduplication.
Zot pricing
We don't have Zot's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.
What Zot does
The capabilities that matter for container registries, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- Hosting
- Cloud + self-hosted
- OCI Distribution Spec compliant
- ✓
- Artifact types
- Container images only
- Built-in vulnerability scanning
- ✓
- Image signing (Cosign/Notation)
- -
- SBOM generation / storage
- -
- Fine-grained RBAC / robot accounts
- ✓
- Private repositories
- ✓
- Geo-replication / mirroring
- -
- Pull-through cache / proxy
- -
- Native cloud IAM integration
- -
- Pull-rate limits
- -
- Web UI / console
- -
- High-availability deployment
- -
Platform & deployment
Independently observed- CLI
- macOS
- Linux
- Cloud / SaaS
- Self-hosted
Integrations (1)
Independently observed- Stacker
Security & compliance
Known vulnerabilities: 1 (1 in the last 12 months), max severity HIGH sourcea count reflects scale & disclosure, not quality
Zot alternatives
Other container registries we track, ranked by the same independent score.
- Google Artifact RegistryA hosted repository service for organizing and managing build artifacts and package dependencies across multiple formatsmedium · 54%
- Cloudsmithmedium · 52%
- Azure Container RegistryA service for storing and managing Docker and OCI-compliant container imagesmedium · 53%
- Harborhigh · 77%
- Docker HubA hosted repository for storing and sharing containerized applicationsmedium · 74%
- Distributionmedium · 67%
The Vioscale score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Zot, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Security score | 82 | 0.08 | 6.6 | ✓ |
| Capabilities | 67 | 0.09 | 5.9 | ✓ |
| Development activity | 55 | 0.11 | 5.9 | ✓ |
| Release cadence | 84 | 0.07 | 5.7 | ✓ |
| Stars | 65 | 0.03 | 1.7 | ✓ |
| Integrations | 9 | 0.05 | 0.5 | ✓ |
| Dependent projects | 0 | 0.07 | 0.0 | ✓ |
| Security posture | 0 | 0.18 | 0.0 | - |
| Package downloads | 0 | 0.15 | 0.0 | - |
| Developer Q&A activity | 0 | 0.05 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Activity
| Attribute | Value | Evidence |
|---|---|---|
| Commits last 30d | 54 | mediumsource · 2026-08-26 · 65% |
Adoption
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | Rbac: Yes · Hosting: both · Oci compliant: Yes · Private repos: Yes · Artifact types: images · Vulnerability scanning: Yes | mediumsource · 2026-08-16 · 60% |
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 1 | mediumsource · 2026-08-16 · 60% |
Language
| Attribute | Value | Evidence |
|---|---|---|
| Primary | Go | highsource · 2026-08-26 · 90% |
License
| Attribute | Value | Evidence |
|---|---|---|
| Spdx | Apache-2.0 | highsource · 2026-08-26 · 95% |