Heroku Git and Container Registry TLS Policy Update

Change effective on 24 February 2026

Heroku Git (git.heroku.com) and the Heroku Container Registry (registry.heroku.com) now require TLS version 1.2 or later using non-CBC ciphers. Specifically, we disabled support for the ECDHE-RSA-AES128-SHA256 and ECDHE-RSA-AES256-SHA384 ciphers. This update aligns our platform services with modern security best practices and compliance standards by disabling legacy CBC ciphers. Most modern clients, including the Heroku CLI, Git, and Docker, already support these modern ciphers and don’t require any changes. This update only affects the Git and Container Registry services and doesn’t affect routing to dynos.