Zot
A production OCI-native registry that stores only OCI images and artifacts, with built-in vulnerability scanning and a search API.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| OCI Image, Runtime and Distribution | stores |
- Interfaces
containerhttp-api- Emits
- oci-image, json
- Runtime
- Runs offline Non-deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
- Website
- https://zotregistry.dev
- Repository
- https://github.com/project-zot/zot
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-09-17
- Stars
- 2771 · last commit 2026-09-17
- Also known as
- zot
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.