Indirect require section in go.mod file is essentially a lockfile. Once decision is made by tool, it's codified for future builds.
In go 1.17 they were added so that project loading did not require downloading the go.mod of every dependency in the graph.