I didn’t use the GitHub integration and still received this email. That’s concerning, and to me, indicates a larger breach than they’ve communicated thus far.
Yes, same here. Looking like a really big breach is my guess given the strange wording and downplaying of the issue, combined with what we actually know (Heroku source code accessed; Github tokens leaked; some other tokens leaked and now mandatory password resets).
Just adding a "me too" to this thread. I just saw in my inbox my warning. I haven't used Heroku in roughly a decade. My last activity was circa early 2014, but mostly 2013.