sudo version as built

As mac os ventura 13.1 1/30/23 reformatted
sudo sudo -V
Sudo version 1.9.5p2
Configure options: --with-password-timeout=0 --disable-setreuid       --with-env-editor --with-pam --with-libraries=bsm 
                   --with-noexec=no          --sysconfdir=/private/etc --without-lecture --enable-static-sudoers 
                   --with-rundir=/var/db/sudo
Sudoers policy plugin version 1.9.5p2        Sudoers file grammar version 48

Sudoers path: /etc/sudoers
Authentication methods: 'pam'
Syslog facility if syslog is being used for logging: authpriv
Syslog priority to use when user authenticates successfully: notice maybe info,  unsuccessfully: alert
Length at which to wrap log file lines (0 for no wrap): 80
Lecture user the first time they run sudo
 File containing the sudo lecture: /etc/sudo_lecture
 Path to lecture status dir: /var/db/sudo/lectured
Require users to authenticate by default
Root may run sudo
Allow some information gathering to give useful error messages
Visudo will honor the EDITOR environment variable
Set the LOGNAME and USER environment variables
Authentication timestamp timeout: 5.0 minutes
Password prompt timeout: 0.0 minutes
Number of tries to enter a password: 3
Umask to use or 0777 to use user's: 022
Send mail if the user is not in sudoers
mail:
    Path to mail program: /usr/sbin/sendmail        Flags for mail program: -t     Address to send mail to: root
    Subject line for mail messages: *** SECURITY information for %h ***
Incorrect password message: Sorry, try again.
Path to authentication timestamp dir: /var/db/sudo/ts
Default password prompt: Password: 
Default user to run commands as: root
Path to the editor for use by visudo: /usr/bin/vi
When to require a password for 'list' pseudocommand: any
When to require a password for 'verify' pseudocommand: all
File descriptors >= 3 will be closed before executing a command
Reset the environment to a default set of variables
Environment variables to check for safety:
    TZ       TERM       LINGUAS      LC_*        LANGUAGE        LANG        COLORTERM
Environment variables to remove:
    *=()*
    TMPPREFIX
    ZDOTDIR
    READNULLCMD         NULLCMD
    FPATH
    PS4
    ENV                 BASH_E
    GLOBIGNORE
    SHELLOPTS           BASHOPTS
    TERMCAP             TERMPATH      TERMINFO_DIRS TERMINFO
    DYLD_*
    _RLD*
    LD_*
    PATH_LOCALE          NLSPATH
    HOSTALIASES
    RES_OPTIONS
    LOCALDOMAIN
    CDPATH
    RUBYOPT             RUBYLIB
    PYTHONUSERBASE      PYTHONINSPECT   PYTHONPATH  PYTHONHOME
    PERL5DB             PERL5OPT       PERL5LIB     PERLLIB PERLIO_DEBUG
    JAVA_TOOL_OPTIONS
    IFS    Input Field Seperator

Environment variables to preserve:
      MAIL  HOME  VISUAL  EDITOR  TZ  SSH_AUTH_SOCK  LSCOLORS  COLUMNS  LINES  
      LC_TIME  LC_NUMERIC  LC_MONETARY  LC_MESSAGES  LC_CTYPE  LC_COLLATE  LC_ALL  LANGUAGE  LANG  CHARSET  
      __CF_USER_TEXT_ENCODING  
      COLORTERM  COLORFGBG  
      LS_COLORS  BLOCKSIZE  
      COLORS  
      XAUTHORIZATION  XAUTHORITY  
      PS2       PS1  
      PATH  
      KRB5CCNAME  
      HOSTNAME  
      DISPLAY  
Locale to use while parsing sudoers: C
Compress I/O logs using zlib
Directory in which to store input/output logs: /var/log/sudo-io
File in which to store the input/output log: %{seq}
Add an entry to the utmp/utmpx file when allocating a pty

PAM service name to use: sudo        PAM service name to use for login shells: sudo
Attempt to establish PAM credentials for the target user
Create a new PAM session for the command to run in
Perform PAM account validation management

Enable sudoers netgroup support
Check parent directories for writability when editing files with sudoedit
Allow commands to be run even if sudo cannot write to the audit log,  log file
Execute commands by file descriptor instead of by path: digest_only
Log entries larger than this value will be split into multiple syslog messages: 960
File mode to use for the I/O log files: 0600
Type of authentication timestamp record: tty
Ignore case when matching user names,  group names
Log when a command is allowed by sudoers,  denied 
Sudo log server timeout in seconds: 30
Enable SO_KEEPALIVE socket option on the socket connected to the logserver
Verify that the log server's certificate is valid

Set the pam remote user to the user running sudo
The format of logs to produce: sudo

Local IP address and netmask pairs:
    192.168.1.31/255.255.255.0
    fe80::cc80:55ff:fe78:4a6[89a]/ffff:ffff:ffff:ffff::
    fe80::188a:1474:f7f0:7695/ffff:ffff:ffff:ffff::
    2600:4041:4310:3c00:c26:85b2:b3e2:7197/ffff:ffff:ffff:ffff::
    2600:4041:4310:3c00:18f7:d784:f58:984a/ffff:ffff:ffff:ffff::
    fe80::1bea:f1ed:2c88:5e7f/ffff:ffff:ffff:ffff::
    fe80::383c:7fff:fe5f:b943/ffff:ffff:ffff:ffff::
    fe80::383c:7fff:fe5f:b943/ffff:ffff:ffff:ffff::
    fe80::608e:4b80:9573:d99b/ffff:ffff:ffff:ffff::
    fe80::7a62:a2fa:102:1f32/ffff:ffff:ffff:ffff::
    fe80::82e8:5148:e607:f662/ffff:ffff:ffff:ffff::
    fe80::ce81:b1c:bd2c:69e/ffff:ffff:ffff:ffff::
    fe80::e4dc:329a:f3b8:4402/ffff:ffff:ffff:ffff::
    fe80::f592:2508:a333:2907/ffff:ffff:ffff:ffff::

Sudoers I/O plugin version 1.9.5p2
Sudoers audit plugin version 1.9.5p2