No I don't agree that it should be allowed to continue, but how is naming&shaming people going to fix anything? Nothing is going to come of this, other than maybe some other hackers will see them as weak targets. Do you expect this list to be read on prime time CNN or something? People who want to buy something online aren't going to search through GitLab to check if the site has been hacked (maybe they should though), they just look for the green padlock and assume it's safe.
As I said, and GitLab suggested, OP should at least contact them. If you contact them and they say they won't do anything, now that's a different story...