I’d normally say eventually it’d bite you if you fall into the habit and do it on a public repo by accident but it looks like it can bite you on a private one too.
Manage your secrets. Use something like Vault[1] or Pass[2] they’re free and awesome projects.
I keep all of my secrets even non-prod ones in one of these two because if you think about it, even your “non-prod” github credentials are kinda prod since you have access to code.
1- https://www.vaultproject.io/
2- https://www.passwordstore.org/
Also when it comes to AWS secrets, give your developers read only access, make them turn on MFA and assume a role that scopes permissions to the work they need to do.
Leaking AWS secrets is really asking for it. The amount of bots that consistently scan public git repos and then use the credentials to spin up massive instances to mine crypto currency is impressive. I’ve seen it do upwards of $10000 in AWS usage within five minutes of the commit containing the credentials.