You gave GitHub the right to use your domain to serve content (including over HTTPS) when you pointed your domain at GitHub servers. This is not a problem.
There is no huge problem, just an interrogation over how this happened since the UI doesn't allow it and the documentation states this is not possible.