Would putting your Gitlab instance behind a VPN mitigate this issue and similar? At least, it would limit attackers to malicious people with VPN access.
It's not a silver bullet but in many cases it will be the difference between getting hacked and not getting hacked.
It is totally possible to design applications that can be safely exposed to the public internet but it requires some real effort.