What is Zot?

A lightweight, self-contained registry for managing container images that fully implements OCI standards. It runs as a single binary without elevated privileges and includes built-in security scanning, access control, garbage collection, and image deduplication.

Independently observed

Zot pricing

We don't have Zot's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

What Zot does

The capabilities that matter for container registries, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Deployment
Hosting
Cloud + self-hosted
Standards
OCI Distribution Spec compliant
Scope
Artifact types
Container images only
Security
Built-in vulnerability scanning
Image signing (Cosign/Notation)
-
SBOM generation / storage
-
Access
Fine-grained RBAC / robot accounts
Private repositories
Distribution
Geo-replication / mirroring
-
Pull-through cache / proxy
-
Integration
Native cloud IAM integration
-
Pricing
Pull-rate limits
-
UX
Web UI / console
-
Ops
High-availability deployment
-
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
  • macOS
  • Linux
Deployment
  • Cloud / SaaS
  • Self-hosted

Integrations (1)

Independently observed
  • Stacker

Security & compliance

Known vulnerabilities: 1 (1 in the last 12 months), max severity HIGH sourcea count reflects scale & disclosure, not quality

Zot alternatives

Other container registries we track, ranked by the same independent score.

All Zot alternatives, ranked →

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Zot, not the verdict.

Balanced composite 53 / 100
high · 78%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Security score820.086.6
Capabilities670.095.9
Development activity550.115.9
Release cadence840.075.7
Stars650.031.7
Integrations90.050.5
Dependent projects00.070.0
Security posture00.180.0-
Package downloads00.150.0-
Developer Q&A activity00.050.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d54mediumsource · 2026-08-26 · 65%

Adoption

AttributeValueEvidence
Github stars2,659highsource · 2026-08-26 · 90%
Dependent repos0highsource · 2026-08-26 · 85%

Features

AttributeValueEvidence
CapabilitiesRbac: Yes · Hosting: both · Oci compliant: Yes · Private repos: Yes · Artifact types: images · Vulnerability scanning: Yesmediumsource · 2026-08-16 · 60%

Integrations

AttributeValueEvidence
Count1mediumsource · 2026-08-16 · 60%

Language

AttributeValueEvidence
PrimaryGohighsource · 2026-08-26 · 90%

License

AttributeValueEvidence
SpdxApache-2.0highsource · 2026-08-26 · 95%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-08-03 · 60%
Modelopen_sourcemediumsource · 2026-08-03 · 60%
Price levelfreemediumsource · 2026-08-03 · 60%
TransparentYesmediumsource · 2026-08-03 · 60%

Release

AttributeValueEvidence
Cadence days29mediumsource · 2026-08-26 · 70%
History20 itemsmediumsource · 2026-08-26 · 70%

Security

AttributeValueEvidence
Scorecard8.2highsource · 2026-08-26 · 90%
VulnerabilitiesCount: 1 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=zotregistry.dev%2Fzot%2Fv2&per_page=100 · Last 12m: 1 · Max severity: HIGHhighsource · 2026-08-26 · 90%