@stefan (stefbun) There's no need to ask lawyers, this is a well established practice.
Every source file should have a license header.
And other files such as images should have their license clarified somewhere in the repo. Either in the readme, or a separate txt file containing image attributions, or just putting something like a image.png.txt file next to the image with the license in it. Anything works as long as it is clear which image has which license.