Project Quay
ATH Infosystems · Software Development
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 7 captures on record
What the publisher says
As described on Microsoft Marketplace.
Project Quay is an open-source container registry platform designed for securely storing, managing, scanning, and distributing container images and OCI artifacts. It provides enterprise-grade image management, vulnerability scanning, role-based access controls, repository mirroring, automation capabilities, and seamless integration with Kubernetes, OpenShift, and CI/CD pipelines, making it suitable for cloud-native application delivery, DevOps workflows, software supply chain security, and large-scale container deployments.
Key Features of Project Quay:
Show the rest of the publisher’s description (14 more lines)
- Open-source enterprise container registry supporting Docker and OCI-compliant images.
- Built-in vulnerability scanning for detecting security issues in container images.
- Role-based access control (RBAC) for secure repository and user management.
- Support for public and private container repositories.
- Repository mirroring and geo-replication for distributed deployments.
- Automated image builds and integration with source code repositories.
- Webhook support for CI/CD automation and deployment workflows.
- RESTful APIs for registry management, automation, and integrations.
- High availability and scalable architecture for enterprise environments.
- Comprehensive audit logging, authentication, and security policy enforcement.
- Integration with Kubernetes, OpenShift, and container orchestration platforms.
- Support for OCI artifacts, container images, and cloud-native software distribution. Project Quay Usage:
# Check Project Quay container status $ podman ps # Access the Project Quay web interface http://SERVER_IP:8080 # View Project Quay logs $ podman logs quay # Stop Project Quay $ podman stop quay # Start Project Quay $ podman start quay Disclaimer:
Project Quay is an open-source container registry platform developed and maintained by the Project Quay community and Red Hat. It is not affiliated with or endorsed by any third-party software, operating system, cloud provider, container platform, or service mentioned for compatibility, integration, or deployment purposes.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Reconciled on 9/3/2026
Sources
Publisher resources
1 linkLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

