Pretty sure (don't quote me) those are read only and repo specific but that could contain all sorts of juicy info depending how lax you are with security of configs in private repos.
Even then just read access to code often allows enough info for leveraging/escalating privilege.