← Back to home
Comparison · Infra & APIs

Harbor vs Skipper

A side-by-side editorial comparison of Harbor and Skipper — release velocity, themes, recent moves, and the top alternatives to consider.

Harbor vs Skipper: at a glance

FeatureHarborSkipper
SectorInfra & APIsInfra & APIs
Velocity score5.06.3
Sparks · 30d00
Top themescontainer-registry, security-hardening, valkey, supply-chainreverse-proxy, caching, auth, performance
Last editorial update2h ago1d ago
WebsiteVisit →Visit →

What is Harbor?

Harbor 2.15 patches swap Redis for Valkey and tighten registry security.

Harbor is shipping 2.15.x patch candidates with security and dependency work. 2.15.2 replaced Redis with Valkey as the cache backend and moved to Go 1.26. 2.15.3 added a manifest upload size limit, blocked proxy-cache poisoning through robot-name prefixes and neutralised CSV formulas in scan exports. 2.15.4-rc1 relaxes two defaults that had caused regressions: webhooks can reach private networks and legacy signer pulls are allowed.

Read the full Harbor trajectory →

What is Skipper?

Skipper fixes cache revalidation that could serve stale 404s forever.

Skipper is on a near-daily patch cadence. Recent substantive changes are an RFC 8693 tokenExchange() filter, a fade-in load-balancing path that no longer copies endpoints per request, and a fix for stale-while-revalidate caching that had left stale entries, including cached errors, unable to refresh. The latest build only stabilizes a flaky shadow-traffic test.

Read the full Skipper trajectory →

Harbor vs Skipper: editorial side-by-side

H
Harbor
INFRA · APIS
5.0

Harbor 2.15 patches swap Redis for Valkey and tighten registry security.

◆ Current state

Harbor is shipping 2.15.x patch candidates with security and dependency work. 2.15.2 replaced Redis with Valkey as the cache backend and moved to Go 1.26. 2.15.3 added a manifest upload size limit, blocked proxy-cache poisoning through robot-name prefixes and neutralised CSV formulas in scan exports. 2.15.4-rc1 relaxes two defaults that had caused regressions: webhooks can reach private networks and legacy signer pulls are allowed.

◆ Where it's heading

The patch line is closing abuse paths in a registry many teams expose internally, while walking back defaults that broke existing setups. The Valkey switch shows Harbor following the wider move off Redis after its licence change.

◆ Prediction

Expect 2.15.4 to go final with the restored defaults and a refreshed Trivy; the entries don't show what the next minor release contains.

S
Skipper
INFRA · APIS
6.3

Skipper fixes cache revalidation that could serve stale 404s forever.

◆ Current state

Skipper is on a near-daily patch cadence. Recent substantive changes are an RFC 8693 tokenExchange() filter, a fade-in load-balancing path that no longer copies endpoints per request, and a fix for stale-while-revalidate caching that had left stale entries, including cached errors, unable to refresh. The latest build only stabilizes a flaky shadow-traffic test.

◆ Where it's heading

Skipper keeps taking on more edge responsibility (identity via token exchange, response caching) while hardening the hot path. Releases are small and frequent, so meaningful changes arrive one at a time between maintenance and test builds, often with production incidents as the trigger.

◆ Prediction

Expect more cache and proxy hot-path fixes, and possibly further auth filters building on token exchange; the entries don't indicate a larger release.

Alternatives to Harbor and Skipper

Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Harbor or Skipper.

See all Harbor alternatives → · See all Skipper alternatives →

Recent activity from Harbor and Skipper

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 1d agoHarbor2.15.4-rc1 restores private-network webhooks and legacy signer pulls
  2. 1d agoSkipperv0.28.30: flaky shadow-traffic test stabilized
  3. 3d agoSkipperv0.28.29: unit tests for ingress status addresses
  4. 3d agoSkipperv0.28.28: cache revalidation fixed for stale entries and RFC mode
  5. 3d agoSkipperv0.28.27: fade-in balancing stops copying endpoints per request
  6. 4d agoSkipperv0.28.26: RFC 8693 token-exchange filter
  7. 4d agoSkipperv0.28.25: fuzz image dependency bump
  8. 16d agoHarbor2.15.3-rc2: second candidate of the security patch
  9. 29d agoHarbor2.15.3-rc1: manifest size limit and proxy-cache poisoning fix
  10. 3mo agoHarbor2.15.2-rc3: Valkey replaces Redis as cache backend
  11. 3mo agoHarbor2.15.2-rc2: earlier candidate of the Valkey patch

Frequently asked questions

What is the difference between Harbor and Skipper?

They serve adjacent needs but don't currently overlap on shipped themes. Skipper is currently shipping more aggressively (velocity 6.3 vs 5.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Harbor better than Skipper?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Skipper is currently shipping more aggressively (velocity 6.3 vs 5.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.

What are the best alternatives to Harbor?

Top Harbor alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Harbor alternatives" section above for the current picks, or visit /alternatives/harbor for the full list with editorial commentary on each.

What are the best alternatives to Skipper?

Top Skipper alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Skipper alternatives" section above for the current picks, or visit /alternatives/skipper for the full list with editorial commentary on each.