I don’t think many people intentionally commit secrets to source control. Frequently, it’s a matter of committing a bunch of work and accidentally missing the credentials you stuck in some prototype code.
This is good advice, but even if you don't, it's possible that someone else on your team will.