You can use Full SSL on CloudFlare with GitHub Pages, which is end to end.
https://blog.cloudflare.com/secure-and-fast-github-pages-wit...
https://blog.cloudflare.com/secure-and-fast-github-pages-wit...
https://www.cloudflare.com/ssl/
https://github.com/isaacs/github/issues/156#issuecomment-110...
For example, if the origin server presents a certificate with a SAN for *.github.io and you have a CNAME to yourusername.github.io, this will (soon) validate as Strict.
https://support.cloudflare.com/hc/en-us/articles/200170416-W...