So can we assume that companies touched by In-Q-Tel are compromised to the same level as Crypto AG was? I'd like to collate a list.
Judging by the company names: Investments into RF companies also are more likely on the "tools we use" instead of the "rigged" side of things. The amount of Biotech makes me assume the decision-makers think this is an emerging market which will make a good investment.
So answering to GP: No, not compromised. I wouldn't be surprised if there were one or maybe even two hiding in plain sight, but I think for each individual company on that list, it is very, very, very unlikely that this specific company is compromised. If you don't trust them, make your sensitive GitLab and MongoDB instances accessible via Intranet/VPN only - but I suppose that's good practice anyway?