If your repositories or forks have been or will be public at any point, storing sensitive information on GitHub can be risky, as it may be accessible by others in some way.
Additionally, while this might change in the future, even if you remove credentials from the repository later, they could still be accessible.
Here is an article that provides more details about GitHub's potential flaws: https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github