No repo should have secrets of any kind, no keys, no passwords.
True, but just static analysis of private source code is likely to discover several vulnerabilities, forget about experts looking for them in the source code. How many companies even do security based static code analysis using state of the art tools?
This kind of reasoning is why many of us avoid closed source software.
And why having the confidence to open source your code is good for your customers. At very least it's pressure not to fix that bug tomorrow rather than after lunch.
not only that but internal projects that one can glean information from just by knowing or seeing their existence and how they are constructed. or for yet unreleased things.. I'm surprised the few comments in this thread don't consider these sorts of things
but what does that have to do with me not wanting hackers to know what type of projects power my company, or unreleased things we're building? a whole slew of things that i would not want people seeing...thats why the repo is _private_
Nothing, but the topic is security. Hackers will discard your data - no immediate gain.