We released two smaller hardening changes that reduce attack surface and make policy configuration more durable, regardless of which Pomerium product you run.
Highlights:
- Distroless, SSL-free published images — Pomerium's published container images now build on the
base-nossl-debian12distroless variant instead ofbase-debian12, structurally removing the unusedlibssl3library from every deployment rather than just leaving it unused. - GitHub directory provider can key users by
node_id— as an alternative to the GitHublogin(username), which can change or be reused, the GitHub directory provider can now use GitHub's stablenode_idas the primary key for directory users — so policy written against a person doesn't break if they rename their GitHub account.
See the core deployment documentation for image and configuration details.
