> What could be done to prevent this?
> Always test new version control GUIs before using them in the wild. There could be a bug that could expose your data.
> Encrypt access keys in config files instead of just leaving them exposed in the config file.
> Better yet, move access keys to a seperate config file, and exclude this from Git deploys with a .gitignore.
The fact this supposedly security experienced and conscious developer thought it was okay to have any kind of access credentials stored in a git repository is glaring.
You should consider all data in any repository public for security reasons. Publishing to github publicly made it quite obvious - but he could have been just as screwed over by people he gave access to the private repositories and people who have broken into github and can directly access the repositories.
Sure the numbers on both those groups are lower than the numbers of people apparently scanning public github for access keys - but the severity of the risk of keeping access keys and other secrets in your revision control are the same.