Both Google and MS provide a disclaimer that explains Information Rights Management can't prevent "malicious programs" from by bypassing the restrictions.
Yep, Atlassian headquarters are in Sydney, so they could be issued a Technical Assistance Request to covertly undermine any repo they host (or have indirect control over via pushing out software updates).
While they could potentially be asked to change your code stored in Bitbucket, Git will refuse to pull if the commit hashes in Bitbucket don't match your local copy, so I don't think intelligence agencies are likely to request this as it is too easily detected.
I predict altering the binaries would be a better way for intelligence agencies to covertly inject a "capability" into your software. E.g. they could ask Atlassian to introduce a hidden code injection step as part of Bitbucket Pipelines, which would be very difficult to detect unless you have deterministic builds and manually verify the output.
Aside from your code, I expect intelligence agencies would be very interested to read your product's issue tracking database (all those "minor" security vulnerabilities that your team knows they should fix someday but don't have time for right now).
I think the general understanding of the need for formalized semantics on the web is going to grow when people realize that chatbots think the answer to "name a fruit that isn't orange" is "an orange": https://hashtag.ai/blog/2018/09/23/fruit.html
However, I've found you can print confidential emails if you comment-out/disable all the @media print rules using Firefox developer tools: https://grokprivacy.org/2018/06/24/archiving-self-destructin...