I don't see what point you're trying to make. For me a tarball is at least as public as a "public git repo" (whatever that means). In fact I would argue a git repository allows for way more opportunities for obfuscation, seeing that it is a much more complex format.