An internal code repo used by New York State’s IT office was exposed online
techcrunch.com
techcrunch.com
It's incredible that folks still think that network security and access is sufficient. There are many tools available to manage secrets that don't involve checking them in (assuming in plain text here) to a git repo. It doesn't matter where the repo is hosted, just don't commit secrets.