That is a valid concern. However, once a password is published (especially in docs or tutorials) it is insecure whether they are random values or not - simply because they are public and clearly linked to the product you're running.
That's why I chose to make it explicit, and thus more likely to be caught in review if done.