Certificates
Verify a repository you own, and get a seal that proves it.
The licence file in your repository is read at its current commit and matched against a published instrument. What comes back is a certificate carrying the commit, both digests, and the command anyone can run to reproduce the check. The seal is a link to that page, and asserts nothing on its own.
Sign in
Either route reaches the same certificate. GitHub can prove a repository is yours immediately. Google signs you in and asks to connect GitHub at the moment it is actually needed.
GitHub is asked for read access to your profile and nothing else. No write scope on any repository is ever requested.