I've put some time into trying to figure out. It is very frustrating and far from obvious.
Open to the repository, there is a section for pull requests. I know some users have pulled the code down -- but bitbucket is telling me there have been no pulls. So I'm guessing that cloning the code is not pulling the code also? So then anyone who wants to do a pull without it being logged, just clones instead??
Digging in the docks it says there is a log of audit events. I've pushed every button on the UI, and I don't see it. The doc pages says: "You can find the log file in the <<a href="https://confluence.atlassian.com/bitbucketserver/bitbucket-server-home-directory-776640890.html" target="_blank" rel="nofollow noopener noreferrer">Bitbucket Server home directory</a>><span>/log</span>/audit directory." If I type a url https://bitbucket.org/user/repo/log/audit it gives me an error saying "that link has no power here" same if I just use /log after the repo. If they are talking about the source code tree, then no, there is no log directory there.
Who has our code, and how can I see that??? And just as importantly, how can I document that?