Harbor v2.15.0 adds Cosign-signed release artifacts
Harbor is an open-source, CNCF-graduated container registry that extends Docker Distribution with enterprise-grade features like RBAC and vulnerability scanning. The latest v2.15.0 update introduces cryptographically signed release artifacts and pins modern security scanners to strengthen its "secure-by-default" posture for cloud-native workloads.
Harbor remains the industry benchmark for self-hosted container registries, particularly for enterprises needing air-gapped or complex hybrid-cloud environments where public registries fall short. The platform integrates vulnerability scanning with Trivy and content trust through Cosign/Notary to provide a robust defense against supply chain attacks. Policy-based replication enables teams to synchronize images and Helm charts across geographically dispersed registries, while native OCI support allows management of container images, machine learning models, and WASM modules. Its mature multi-tenancy through project-based isolation and OIDC/LDAP integration continues to make it the standard for large-scale internal developer platforms.
DISCOVERED
3d ago
2026-04-08
PUBLISHED
3d ago
2026-04-08
RELEVANCE