Don't trust corporate PR. They're obviously lying when they say "out of an abundance of caution". The private key was exposed in a public GitHub repo, it could literally be anywhere.
So MITM for some of 50m users is strictly better than MITM for all of 50m users.
> The private key was exposed in a public GitHub repo.
How do you know this?
Github runs scanner for private keys in public and private repos and notifies owner (I did it once so I know ... ;)). So some Github engineer likely would have received such an email if what you say is true. Hilarious.
So MITM for some of 50m users is strictly better than MITM for all of 50m users.