Maybe also make /usr/bin/sudo immutable? would that help prevent a package manager from messing with it? I think so.
On Debian, for example, I have unattended-upgrades set up to automatically install security updates. sudo is reasonably likely to have updates for security reasons.
https://wiki.debian.org/DebianAlternatives
https://www.debian.org/doc/debian-policy/ap-pkg-diversions.h...
You need the `i` attribute. But this is filesystem dependent. Anyway protecting the `sudo` binary from package managers is a so-so idea.