Given the CentOS shit, I'm not convinced jumping from Docker Inc to RedHat is appropriately mitigating the risk of a corporate rug pull once they've decided its time for the next step in their enshittification plan...
It started as a CoreOS project and for a long time it was the only ebterprisey registry, and it included security scanning. Had some availability issues some time ago, but AFAIK today it's pretty good.