This isn't any different from many download procedures. Consider that even a general-purpose package manager like Pacman uses HTTP, because there's little point in using transport-level security when the payload is cryptographically signed and there's a solid root of trust.
The only reasonable problem I see with this approach is that a MITM can make clients download an older version that is known to have critical bugs.