These specific expressions may contain non-public information about the structure of the tokens.
But imagine we live in a world where companies are OK with exposing this information publicly and investing time in keeping the expressions up to date.
Now what? How do you report it to services whilst stopping abuse? Like, if the code isn’t public then all this is an endpoint to let anyone to disable another users (or companies) key without any explanation or recourse.
Pushing to GitHub is actually quite an elegant solution to these issues I think, even if I do think it is a bit too centralized.