The CI platform needs read access to the source code. And last week, even GitHub’s own CodeQL was compromised and the attacker had the ability to compromise thousands of repositories using Code QL. And AWS/Google Cloud can pull source code from GitHub via GitHub Applications, so, no more pesky secrets that can potentially leak.