My old school has done some very good work on pointing out how common it is for people to post keys in open source code. I am a fan of Open Source, but everyone needs to understand good practices, and never, NEVER, put credentials in your code, it is too easy to slip up and let them out.
https://www.zdnet.com/article/over-100000-github-repos-have-leaked-api-or-cryptographic-keys/