Yeah it does, because you left the key for the place where you stored everyone else's keys out in the relative open. It reduces your defensive depth to 1, as in, 1 compromise was all it took.
For a tortured analogy, let's say you keep your guns in a gun-safe in your garage, and then hang the key for the safe in the garage. With a sign saying "gun safe key".
Not leaving the safe key out in the open doesn't guarantee your guns are impervious, of course, a sufficiently motivated and skilled burglar willing to put time and effort into breaking open the safe would be able to access your guns.
But, that takes time. And it makes noise. Both of which increase the chance of being caught.
But if the key is right there? Easy as.
Yep, they had obtained access to the repo, like the burglar had obtained access to the garage.
But if the AWS secrets weren't just hanging on the wall, then progressing from Gitlab compromise to S3 compromise would a) be harder and b) take longer, both of which increase the chance of discovery.
Just saying, if you care about the security of your guns and/or customer data, don't leave the key hanging about in plain sight as a good first step.
Make them compromise multiple things, not just one thing.
I'm desperately trying to work encryption at rest into this analogy. Um... trigger locks?