The two incidences I had planned to include have been resolved as
"wontfix," basically:
1. A re-read of RFC 3370 has revealed that whether the parameters
field is supposed to be absent or NULL is completely ambiguous,
so we'll accept both now.
2. As for rsaEncryption vs sha256WithRSAEncryption for public keys,
the relevant sidr mailing list thread is currently favoring the
former. And the vast majority of the global RPKI does the same,
so there's no error to silence.