Well it's still vulnerable. At least in Gitlab you can use fancy features like requiring 2FA for members of a group. But you still need to secure its infrastructure.
I think the most common attacks on Github repos and groups have been on individual accounts. Which 2FA would mitigate.