Why wouldn't they? Conveniently and safely in the same location as the code they were built with. Tagged the same way. Having a separate repository is just inviting trouble down the road, no?
Because they're binary files, used entirely for archival purposes. They shouldn't be changing, they shouldn't have "versions" that are anything to deal with meaningfully as far as your repository is concerned.
They should be in flat storage somewhere, with some directory or file name scheme that makes sense based on your version numbers / builds / what have you. Backed up, (ideally) with hashes that verify that they're the same file they once were.