I consider this in the same realm as storing passwords to plain text. People do it out of ignorance until they're learn the hard way not to (or some kind soul saves them from that disaster).
Rails deployments aren't leaking their ssh keys or database content because that is stored separately. To paraphrase the title: these things are stored separately for a reason.
Get this thing out of the source, guys.
secret_token.rb is placed where it is, because it is a initializer.
http://guides.rubyonrails.org/configuring.html#locations-for...