Why can't you say "this is how we should not do things" during the code review window? You should have a policy in place that all comments need to be addressed before approval, and with your comment in there (e.g. "we should not hardcode api keys" or "pull default params from the config file, not ENV variables"), others should not approve. Your CI process should require approval before merging. Now if it makes it past review and approval and gets merged, you can create a "tech debt" issue to refactor. You should also have a meeting of the minds to put these standards in a style guide and make sure it is followed when reviewing PRs.