What it means
An OAuth app requests user authorization using scopes that can be broad. A GitHub App uses more granular permissions and can be installed on selected repositories; it can also act independently of a particular user for some operations. GitHub generally recommends GitHub Apps for integrations, but both kinds can appear in a person's authorized applications. The name of an integration alone does not describe the data it can reach.
A real-world example
A writing service asks to sign in with GitHub and requests access to all private repositories merely to display a profile. A repository-specific GitHub App grant would be narrower for many tasks, while a basic sign-in flow should not need repository write access.
What to do
Review Authorized OAuth Apps and Authorized GitHub Apps separately under Settings, Applications. Inspect scopes, repository selection and the vendor's purpose. Revoke a grant you no longer need and test legitimate automations afterward; organization installations may need an owner to change them.
The distinction that matters
A GitHub App can still be overprivileged if installed broadly. An OAuth app can be legitimate when its requested scope matches the task. Revoking an app authorization is not the same as deleting a personal access token or SSH key, and it cannot undo data already read.
GitHub app model comparison OAuth app review