I stand corrected, unbundling, which happens during transfer, does seem to check SHA-1. Which surprises me, because I would expect SHA-1 hashing on all the manifests on mozilla-central to take a lot more time than what a clone takes (250k+ manifests of more than 5MB each on average (most recent ones are larger than 10MB), even with a SHA-1function doing 1GB/s (and I think we barely reach half that), that should take more than 20 minutes). But maybe a clone does take longer than that these days?
That said, while it doesn't during transfer, Git does check sha1s when objects are accessed. The code is in object.c in parse_object(), which calls check_sha1_signature(). But disappointingly not everything is going through that code path.
$ git init
$ echo a > a ; echo b > b
$ git add a b
$ git cat-file blob 78981922613b2afb6025042ff6bd878ac1994e85
a
$ cp -f .git/objects/61/780798228d17af2d34fce4cfbdf35556832472 .git/objects/78/981922613b2afb6025042ff6bd878ac1994e85
$ git cat-file blob 78981922613b2afb6025042ff6bd878ac1994e85
b
$ git show 78981922613b2afb6025042ff6bd878ac1994e85
error: sha1 mismatch 78981922613b2afb6025042ff6bd878ac1994e85
fatal: bad object 78981922613b2afb6025042ff6bd878ac1994e85