As far as I know, Github pages doesn't support https for custom domains [1]. A better option for free hosting would be netlify, which supports Let's encrypt for custom domains.
> Github pages does not offer secured custom domain name. The best way to get this feature for free is to use Cloudflare.
[The article then proceeds on how exactly do that.]
[1] https://support.cloudflare.com/hc/en-us/articles/203349264-A...
+------------------+ +------------------+ +-----------------------+
| | | | | |
| CLIENT | +----------> | CLOUDFLARE | +---------> | YOU |
| | SSL | | NOT SSL | |
+------------------+ +------------------+ +-----------------------+Full SSL doesn't really protect you since Cloudflare won't check if the certificate is valid, an attacker could make their own self-signed cert and MITM you.
Full SSL (Strict) requires a valid cert for the domain being requested. If you had that, you wouldn't need Cloudflare in the first place.
Edit: Looks like you're correct. Sorry!