ORAS
Pushes and pulls arbitrary artifacts through an OCI registry — Helm charts, SBOMs, signatures, models — using the registry as general artifact storage rather than image storage.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| OCI Image, Runtime and Distribution | transfers |
Pushes and pulls arbitrary artifacts through an OCI registry, not just images. |
- Interfaces
clilibrary- Install
-
brew
oras - Invoke
oras push <registry>/<repo>:<tag> <file>:<media-type>- Consumes
- filesystem
- Emits
- oci-image
- Runtime
- Needs network Deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
The reason the Distribution spec matters beyond containers — registries turn out to be the artifact store organisations already run.
- Website
- https://oras.land
- Repository
- https://github.com/oras-project/oras
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-09-17
- Stars
- 2433 · last commit 2026-09-15
- Also known as
- oras, OCI Registry As Storage
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.