If you commit your AWS secrets/tokens, or similar, inside a python script it will now be discovered by github automatically.
They have integrations with a bunch of services to recognize the tokens, and disable them. This means malicious users can't copy/paste them, spin up servers and leave you with a big bill. (Ideally, of course it could still happen, but the aim is to prevent that kind of thing.)