Hi. GHC's source is huge. Even the diff to the last release is huge. Larger than what a single person can browse in any reasonable time, or at least what I can. As the maintainer of the GHC package in Debian, I'd feel to be in remiss if I didn't do something to verify that what I downloaded from haskell.org is indeed what you intended to release.
Could you please sign the release with GPG or at least provide a SHA1 sum or something of the released source? I'd feel more confident about focusing on the functional aspects of the compiler (no pun intended) and its build system that way.
signature.asc
Description: Digital signature