I'm pretty sure if you're using herokuapp.com then you're not using your own cert and Heroku will update it for you. If you're using ssl:endpoint then you will have had to submit your own cert, and that will need replacing.
However, this blogpost says, "As of Tuesday, April 8 at 15:55 UTC, all Heroku certificates and infrastructure have been updated and are no longer vulnerable"... while the certificate still superficially looks like it's almost 3 months old. Something isn't as it seems, I hope it's just the certificate age.