compare
Distribution vs Harbor
The same facts for both, read from GitHub every night, and the relation a person reviewed.
| Fact | Distribution | Harbor |
|---|---|---|
| Language | Go | Go |
| Licence | Apache-2.0 | Apache-2.0 |
| Stars | 11k | 30k |
| Latest | v3.1.2 | v2.15.3 |
| Last push | 2026-10-05 | 2026-10-06 |
| Release cadence | about 146 days between releases | about 1 day between releases |
| Active contributors | 16 commit authors on the default branch in the last 90 days | 32 commit authors on the default branch in the last 90 days |
| Flags | none | none |
How they relate
Harbor replaces Distribution. Alternatives to Distribution →
Full replacementBuilt on Distribution, with a web UI, users and policies on top.
Both replace Docker Hub. Alternatives to Docker Hub →
PartialDistributionThe reference OCI registry server, without a web UI, users or scanning.
Full replacementHarborProjects, access control, vulnerability scanning, signing and replication between registries.
Distribution
- v3.1.22026-09-24Welcome to the v3.1.2 release of registry!
- v3.1.12026-05-01Welcome to the v3.1.1 release of registry!
- v3.1.02026-04-06Welcome to the v3.1.0 release of registry!
- v3.0.02025-04-03Welcome to the v3.0.0 release of registry!
- v3.0.0-rc.42025-03-22Welcome to the v3.0.0-rc.4 release of registry!pre-release
Harbor
- v2.14.52026-10-06[CHERRY-PICK] Make openapi-generator-cli download URL configurable (#23186)
- v2.13.62026-10-06fix: pin redis 7.2.11 instead of 7.2.6 in the redis base image
- v2.15.32026-10-06(high): Path traversal vulnerability in distribution endpoints GHSA-qj39-pjf2-wmrc in a82c5528f
- v2.15.3-rc22026-09-24(cherry-pick) fix: avoid panic in user audit event resolver on nil event data (#23461)pre-release
- v2.15.3-rc12026-09-11(cherry-pick) fix: avoid panic in user audit event resolver on nil event data (#23461)pre-release
Distribution
✓ signed The latest release, v3.1.2, carries a signature GitHub verified.
Loading the security report
Harbor
unsigned The latest release, v2.15.3, carries no signature GitHub could verify.
Loading the security report