I would scrub the repo anyways because revoked secrets can still be used for social engineering. "Hey $HOST, I got hacked. My old password was $PASSWD and you can be sure it's me because $PUBLIC_INFORMATION. Can you send a password reset to $ATTACKER_EMAIL?"