This ~prevents people from modifying the binary that you download, but doesn't prevent them from knowing that you downloaded it.
Your GET request, and the server's reply, is encrypted.
The hostname of your request might leak in SNI, or if your DNS lookup was insecure.
It is also plausible that an eavesdropper could make a solid guess as to what you downloaded by counting bytes, but that's obviously not worth much.
You don't need a DNS leak; if you aren't using SNI, the server(s) replying on that IP can only serve a single cert, so the snooper can usually find out the hostname by simply connecting to it and seeing what it gets.
The exception is if the site is behind something like Cloudflare, which stuff dozens or hundreds of hostnames in a single cert.