That's not a bad point. GitHub is convenient, yes, but if you manage security for companies that are collectively worth billions, you want to minimize your attack surface.
In my experience, security is usually an afterthought in most tech companies. Just look at how many MongoDB instances in production were running on open ports with the default password, which was... no password.