What assurances does that give you beyond the https certificate on their official website which contains the binary downloads and hashes?
To argue in its favor tho, file-hosting and site-serving may be handled by different systems with different security characteristics, and potentially even different datacenters (e.g. a CDN). If you only have to compromise one system, it's generally easier to do so than when you have to compromise N and make them all agree with each other.
This is a legitimate case as it's happened to other projects in the past.
FWIW the macOS pkg you download is signed.