I have no problem with doas on debian or arch through a package either.
Many sudo policies are often kind of horrible (even by default) and often facilitate privilege escalation, and then there was CVE-2019-14287 ( < 1.8.28 ) and CVE-2021-3156 ( < 1.9.5p2 ) which were plenty nasty. It's just way too huge for a setuid program, security tools shouldn't represent security holes as best as we can get away with it.
[1] https://www.thehacker.recipes/infra/privilege-escalation/uni...