For anyone wondering where this is....it is in your project -> "Deploy" -> "Deployment method" -> "Connect to Github".
For checking your Github audit logs, you can go directly here (replace ORG_NAME with your own): https://github.com/organizations/<ORG_NAME>/settings/audit-l...
Or from: Organization > Settings > Archive > Logs > Audit Log
I hope we get some more clarity on the extent of this incident soon. We'll rotate our keys anyway but I really hope the attackers did not have access to the ENV vars that are commonly set on Heroku directly.
I had to remove them one by one.