I think you might have misunderstood. The source code of SourceHut itself is hosted on SourceHut, and it has a CI/CD setup that packages the microservices as alpine packages, signs and uploads them automatically to mirror.sr.ht, as files. This is no different than having a pypi-upload action (or similar) on GitHub.
The only material difference is that the deploy keys for *.sr.ht present (by design) on builds.sr.ht also have access to `doas apk upgrade -Ua` and to `doas rc-service *.sr.ht restart` on the production infra. Which is harmless by itself, but might result in Continuous Ownage if a rogue build happens to have access to the keys.