Those keys absolutely need to be rotated, regardless of whether you delete the commit or repo after accidentally pushing them.
At which point you may as well leave them there...
At which point you may as well leave them there...
You may get lucky and remove/hide it fast enough, or think you did...
This is an with Github today, all public repos are being watched by bots reviewing all commits for accidentally-pushed credentials.
The only solution is to not use a public repo.
On GitHub yes someone might be watching, but deletes are still possible.