It's immoral to discriminate on the basis of fear, prejudice, and rumor.
One client can demand that Gitlab get rid of Chinese and Russian nationals today. Tomorrow, a different client can make similar demands - aimed at the nationals of different countries. This makes no sense whatsoever, and will blow out of control quickly.
Sanction programs are the established legal frameworks for such things: https://www.treasury.gov/resource-center/sanctions/programs/...
It's disappointing to see the promise of some money making the company go full 180 on its hiring and employment procedures - going as-far as potentially rescinding one employee's offer, and flagging another employee's personal choice to live in a different country as a risk.
The due process here is concerning. Some techbro starts by creating a "we need to block all Russian/Chinese" issue - followed by a bunch of echo-chamber "yessir" comments. When a legal advisor steps in - everyone tries to silence her and convince her it's just an "iterative process".
Finally - it actually looks like Gitlab's security practices are truly lacking. That an employee is Chinese/Russian shouldn't be a consideration - the systems should be tight enough to make sure absolutely no-one has access to customer data without consent - and that any actions taken are logged for auditing. Whenever necessary - pass your employees through a background-check. In sensitive (government) scenarios - restrict to employees with government clearance.
Honest question: Is Gitlab now a company not in a position to say "no"? Investors and potential customers need to know.