# Zot

- **Canonical URI:** https://www.vioscale.ai/software/zot
- **Category:** Container Registries
- **Homepage:** https://zotregistry.dev
- **Also known as:** zot
- **Profile claimed by vendor:** no
- **Last updated:** 2026-08-26T19:02:38.628Z

## Vioscale score

**53.4 / 100**, confidence 78% (high). Computed 2026-09-01.

Composite of weighted, independently-sourced signals (no user reviews, no vendor payment).

| Signal | Score | Weight | Contribution | Evidence present |
|---|--:|--:|--:|:--:|
| capabilities | 67.1 | 0.08722222222222224 | 5.9 | ✓ |
| repo_stars | 64.6 | 0.027 | 1.7 | ✓ |
| integrations | 8.7 | 0.054 | 0.5 | ✓ |
| dependent_projects | 0 | 0.068 | 0 | ✓ |
| dev_activity | 54.8 | 0.108 | 5.9 | ✓ |
| release_cadence | 83.9 | 0.068 | 5.7 | ✓ |
| security_posture | 0 | 0.176 | 0 | - |
| package_downloads | 0 | 0.149 | 0 | - |
| security_score | 82 | 0.081 | 6.6 | ✓ |
| community_qa_activity | 0 | 0.054 | 0 | - |

## Pricing

_As of 2026-08-03, [verify at source](https://zotregistry.dev). Independently observed._

Open source · Free tier

## About

A lightweight, self-contained registry for managing container images that fully implements OCI standards. It runs as a single binary without elevated privileges and includes built-in security scanning, access control, garbage collection, and image deduplication.

_Independently observed._

## Platform & deployment

- **Platforms:** CLI, macOS, Linux
- **Deployment:** Cloud / SaaS, Self-hosted

## Integrations (1)

_Independently observed._

- Stacker

## Capabilities

_The capabilities that matter for Container Registries. "-" = undocumented, not absent._

| Capability | Supported |
|---|:--:|
| **Deployment** | |
| Hosting | Cloud + self-hosted |
| **Standards** | |
| OCI Distribution Spec compliant | ✓ |
| **Scope** | |
| Artifact types | Container images only |
| **Security** | |
| Built-in vulnerability scanning | ✓ |
| Image signing (Cosign/Notation) | - |
| SBOM generation / storage | - |
| **Access** | |
| Fine-grained RBAC / robot accounts | ✓ |
| Private repositories | ✓ |
| **Distribution** | |
| Geo-replication / mirroring | - |
| Pull-through cache / proxy | - |
| **Integration** | |
| Native cloud IAM integration | - |
| **Pricing** | |
| Pull-rate limits | - |
| **UX** | |
| Web UI / console | - |
| **Ops** | |
| High-availability deployment | - |

## Release history

| Version | Date | Type |
|---|---|---|
| [v2.1.20](https://github.com/project-zot/zot/releases/tag/v2.1.20) | 2026-08-04 | stable |
| [v2.1.19](https://github.com/project-zot/zot/releases/tag/v2.1.19) | 2026-08-04 | stable |
| [v2.1.18](https://github.com/project-zot/zot/releases/tag/v2.1.18) | 2026-06-24 | stable |
| [v2.1.17](https://github.com/project-zot/zot/releases/tag/v2.1.17) | 2026-05-18 | stable |
| [v2.1.16](https://github.com/project-zot/zot/releases/tag/v2.1.16) | 2026-04-19 | stable |
| [v2.1.15](https://github.com/project-zot/zot/releases/tag/v2.1.15) | 2026-03-08 | stable |
| [v2.1.14](https://github.com/project-zot/zot/releases/tag/v2.1.14) | 2026-01-25 | stable |
| [v2.1.13](https://github.com/project-zot/zot/releases/tag/v2.1.13) | 2025-12-23 | stable |
| [v2.1.12](https://github.com/project-zot/zot/releases/tag/v2.1.12) | 2025-12-21 | stable |
| [v2.1.11](https://github.com/project-zot/zot/releases/tag/v2.1.11) | 2025-11-20 | stable |
| [v2.1.10](https://github.com/project-zot/zot/releases/tag/v2.1.10) | 2025-10-18 | stable |
| [v2.1.9](https://github.com/project-zot/zot/releases/tag/v2.1.9) | 2025-10-14 | stable |
| [v2.1.8](https://github.com/project-zot/zot/releases/tag/v2.1.8) | 2025-09-01 | stable |
| [v2.1.7](https://github.com/project-zot/zot/releases/tag/v2.1.7) | 2025-08-03 | stable |
| [v2.1.6](https://github.com/project-zot/zot/releases/tag/v2.1.6) | 2025-07-27 | stable |

_… and 5 earlier release(s)._

## Security & compliance


Known vulnerabilities: 1 (1 in the last 12 months), max severity HIGH ([source](https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=zotregistry.dev%2Fzot%2Fv2&per_page=100)). A count reflects scale and disclosure, not quality.

## Facts

Every value below carries its source and our confidence. Facts are re-crawled on a freshness schedule.

### pricing

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| pricing.free_tier | yes | [link](https://zotregistry.dev) | 2026-08-03 | 60% (medium) |
| pricing.model | open_source | [link](https://zotregistry.dev) | 2026-08-03 | 60% (medium) |
| pricing.price_level | free | [link](https://zotregistry.dev) | 2026-08-03 | 60% (medium) |
| pricing.transparent | yes | [link](https://zotregistry.dev) | 2026-08-03 | 60% (medium) |

### integrations

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| integrations.count | 1 | [link](https://zotregistry.dev) | 2026-08-16 | 60% (medium) |

### activity

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| activity.commits_last_30d | 54 | [link](https://github.com/project-zot/zot/pulse) | 2026-08-26 | 65% (medium) |

### adoption

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| adoption.github_stars | 2,659 | [link](https://github.com/project-zot/zot) | 2026-08-26 | 90% (high) |
| adoption.dependent_repos | 0 | [link](https://packages.ecosyste.ms/api/v1/packages/lookup?repository_url=https%3A%2F%2Fgithub.com%2Fproject-zot%2Fzot) | 2026-08-26 | 85% (high) |

### language

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| language.primary | Go | [link](https://github.com/project-zot/zot) | 2026-08-26 | 90% (high) |

### license

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| license.spdx | Apache-2.0 | [link](https://github.com/project-zot/zot) | 2026-08-26 | 95% (high) |

### release

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| release.cadence_days | 29 | [link](https://github.com/project-zot/zot/releases) | 2026-08-26 | 70% (medium) |

### security

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| security.scorecard | 8.2 | [link](https://api.securityscorecards.dev/projects/github.com/project-zot/zot) | 2026-08-26 | 90% (high) |
| security.vulnerabilities | `{"count":1,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=zotregistry.dev%2Fzot%2Fv2&per_page=100","last_12m":1,"max_severity":"HIGH"}` | [link](https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=zotregistry.dev%2Fzot%2Fv2&per_page=100) | 2026-08-26 | 90% (high) |

---
*Source: Vioscale (https://www.vioscale.ai/software/zot). Independent, evidence-based software intelligence. Cite the canonical URI.*
