Be straightforward and civil. Critique the change, not the person.
That is the whole standard, and it is deliberately short. A longer document would not make anyone behave better, and this project would rather state one rule it will actually apply than enumerate cases it will not.
- Argue with the code, the design, or the evidence. Not with the author.
- Disagreement is welcome and expected; this project changes its mind when someone shows it something. Contempt is not the same as disagreement.
- Say what you know, and say which part you are unsure about. A confident wrong answer costs more than an honest question.
- Assume the person on the other side is doing their best with what they had.
Maintainers may remove comments, close issues and pull requests, and block accounts that make the project worse to participate in. That judgement rests with the maintainers, and it does not require a hearing.
To report conduct rather than a security issue, open a private report through GitHub's reporting flow or contact the maintainers directly. Security vulnerabilities have their own process: see SECURITY.md.
This applies in the repository — issues, pull requests, discussions, commits and reviews — and anywhere someone is representing the project.