Never said it should be a requirement. But downloading a .zip file from a site which does not have a valid SSL certificate nor supports SSL in the first place does not instill confidence. Software security is a thing.
If it's that onerous to download the zip, maybe we should build a tool to browse .zip/.tgz source links instead of pressuring everyone to centralize all source code on the planet into just two web sites.