Yes it is, it’s ensuring that what the maintainer of the formula verified is still what’s being downloaded now. HTTPS does nothing to protect someone modifying the source URL, but the hash does that (assuming the maintainer actually inspected the initial download, which many if not most do).
> but given that most formulas download code from the Internet and run it, that's not much help.
1) the previously erroneously dismissed hash helps there.
2) the sandbox which you linked to later also helps too.