How is it secured and made private?
Also the author checked in a credentials and a master key to github
Rails uses the "master key" to let you check in encrypted database credentials. I don't use that but Rails still requires a key for deployment--so I just checked in a key. Rails is really designed for a codebase that matches to a single deployment so this is a bit of a workaround.
It's safe to bet that someone will deploy this and use that master key instead of generating their own.