Why this one bites students hardest
You finish a project at 3 a.m., commit everything, push to a public GitHub repository so the examiner can see it. Inside config.py is a live API key for a payment sandbox, or a Firebase key, or an SMTP password.
Bots scan every new public commit on GitHub within seconds of the push. This is not a theoretical risk; it is an automated industry. Cloud keys are found and used for cryptocurrency mining fast enough that the first sign of trouble is a bill.
And the worst part: deleting the line in the next commit does not help. Git keeps history. The key stays in the repository forever, reachable by anyone who clones it.