We have very simmiliar issue.
All our databases have password Qwerty1234
Android keystore is checked in repository with access key in scripts.
Security keys for external services are also checked in into repository.
Some external services for production are managed by devs that are long time ago not working in our company