Be decent. If that needs elaborating: no harassment, no personal attacks, no discrimination, and no treating a bug report as an accusation.
Technical disagreement is the point of a code repository and is not incivility. "This is wrong and here is why" is welcome; "you are an idiot" is not. Assume the other person has a reason you have not heard yet, and ask.
Two things specific to this project:
Bug reports from events are the most valuable thing here, and often the least polished. Somebody typing a report at 23:00 after a bad twenty minutes at a door is not going to produce a minimal reproduction. Meet that with gratitude, not a template.
Security reports get patience. Somebody who found a flaw and told us privately did the right thing, at their own cost, and gets a thank you regardless of how it was worded.
Report it to the address on github.com/ManasMadan. It will be read by one person, kept private, and acted on.