Is this because of the xz utils thing? The backdoor was included into the tarball, but it wasn't in the git repo.
By switching away from tarballs they pribably hope to prevent that, although this article doesn't mention that. It's possible this shift has been happening since before the xz utils.