Never said it should be a requirement. But downloading a .zip file from a site which does not have a valid SSL certificate nor supports SSL in the first place does not instill confidence. Software security is a thing.
Agreed about the SSL/TLS, but the comment sounded more like not having a public git was the complaint.