Have bad actors set up automation to watch all commits to all Github repositories to detect mistakes like this? Otherwise, how can the mistake be exploited in 5 minutes?
And if so, maybe Github should deploy some countermeasures? Like, block the uploading of private keys unless they are explicitly whitelisted by the repository owner?
I think there is a similar argument to be made for commits that contain e.g. database credentials or private data.