Because the source archives from GitHub tags may not always produce the same tarball when fetching at different times. Having proper tarballs for releases also allows signing them i.e. with PGP.