I have a native iOS app that works with GitHub's API. I had the exact same concern as you. As a user, I would much rather use an oath of flow instead of entering my password.
Unfortunately, GitHub actually suggests you use basic auth for native applications. Their reasoning is that the application secret would need to be shipped with the binary, thus making it… not secret (even with various obfuscation).
Source: http://developer.github.com/v3/oauth/#non-web-application-fl...