Mandatory XKCD:
https://xkcd.com/538/Nobody's code is that secret, especially not from a vendor like Microsoft.
Unless all development is done with air-gapped machines, realistic development environments are simultaneously exposed to all of the following "leakage risks" because they're using third-party software, almost certainly including a wide range of software from Microsoft:
- Package managers, including compromised or malicious packages.
Microsoft owns both NuGet and NPM!
- IDEs and their plugins, the latter especially can be a security risk.
What developer doesn't use Microsoft VS Code these days?
- CLI and local build tools.
- SCM tools such as GitHub Enterprise (Microsoft again!)
- The CI/CD tooling including third-party tools.
- The operating system itself. Microsoft Windows is still a very popular platform, especially in enterprise environments.
- The OS management tools, anti-virus, monitoring, etc...
And on and on.
Unless you live in a total bubble world with USB sticks used to ferry your dependencies into your windowless facility underground, your code is "exposed" to third parties all of the time.
Worrying about possible vulnerabilities in encrypted VMs in a secure cloud facility is missing the real problem that your developers are probably using their home gaming PC for work because it's 10x faster than the garbage you gave them.
Yes, this happens. All the time. You just don't know because you made the perfect the enemy of the good.