Platform & Image Hardening

August 21, 2026
Share on Bluesky

We released two smaller hardening changes that reduce attack surface and make policy configuration more durable, regardless of which Pomerium product you run.

Highlights:

  • Distroless, SSL-free published images — Pomerium's published container images now build on the base-nossl-debian12 distroless variant instead of base-debian12, structurally removing the unused libssl3 library from every deployment rather than just leaving it unused.

  • GitHub directory provider can key users by node_id — as an alternative to the GitHub login (username), which can change or be reused, the GitHub directory provider can now use GitHub's stable node_id as the primary key for directory users — so policy written against a person doesn't break if they rename their GitHub account.

See the core deployment documentation for image and configuration details.

Share: Share on Bluesky

Get our product updates delivered directly to your inbox

Revolutionize
Your Security

Embrace Seamless Resource Access, Robust Zero Trust Integration, and Streamlined Compliance with Our App.