JFrog

Sure, JFrog JFrog Artifactory is awesome.

But have you considered these open source alternatives?

They are free, self-hostable and community-driven.

Check by yourself: Harbor  Harbor ,  Quay .

  1. So is Harbor Harbor

    Registry that stores, signs, and scans content

    ★ 25K Container Registry Security License: Apache-2.0

    Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Harbor extends the open source Docker Distribution by adding the functionalities usually required by users such as security, identity and management. Having a registry closer to the build and run environment can improve the image transfer efficiency. Harbor supports replication of images between registries, and also offers advanced security features such as user management, access control and activity auditing.

  2. So is Quay

    Applications and containers Registry

    ★ 2.6K Container Registry Security License: Apache-2.0

    Project Quay builds, stores, and distributes your container images.

    Features

    • Store your containers securely: Ensure your apps are stored privately, with access that you control. Quay is teamwork optimized, with powerful access controls.
    • Build & deploy new containers easily: Use Quay to automate your container builds, with integration to GitHub, Bitbucket, and more. Robot accounts allow you to lock down automated access and audit each deployment.
    • Automatic Security Scanning: Quay continually scans your containers for vulnerabilities, giving you complete visibility into known issues and how to fix them.