ML-DSA has a 'context string' as an input; the idea is to allow the capability to bind a signature to a specific context. Should we specify that, when we implement ML-DSA within a composite signature, ...
It was brought to my attention in Pauan/rust-dominator#10 that JavaScript strings (and DOMString) allow for unpaired surrogates. When using TextEncoder, it will convert those unpaired surrogates into ...