But it hides the HTTP request itself - Sourceforge hosts thousands of different projects, if served over HTTPS it'd be considerably harder to tell which download had been requested.
Your GET request, and the server's reply, is encrypted.
The hostname of your request might leak in SNI, or if your DNS lookup was insecure.
It is also plausible that an eavesdropper could make a solid guess as to what you downloaded by counting bytes, but that's obviously not worth much.
You don't need a DNS leak; if you aren't using SNI, the server(s) replying on that IP can only serve a single cert, so the snooper can usually find out the hostname by simply connecting to it and seeing what it gets.
The exception is if the site is behind something like Cloudflare, which stuff dozens or hundreds of hostnames in a single cert.