Note it can be very time consuming to figure out exactly how far/what was vulnerable in a compromise.
Depending on the precise circumstances it may be quick, or very slow to be able to come to a final conclusion on happened....
When freedesktop was compromised, it was several months before the *last* project hosted there verified that no source had been tampered with, and we could finally conclude it was extremely likely the compromise was just a spammer attracted to a fast machine on a gigabit/second link. Everything important was up within a week or so. In the RH/Fedora case, they are in a much worse situation.