But the second one is a patch I sent to OpenBSD. Apparently the portable version of sudo keeps an up-to-date copy of this file.
Sudo is a super useful tool, and Todd has made a wonderful job at maintaining it for the past 20 years or so.
Most opensource projects have only one maintainer. This is not necessarily a bad thing; it oftens allows them to iterate quickly.
And it doesn't mean the code is only read by one pair of eyeballs either. In particuler, sudo is part of OpenBSD, and other OpenBSD developers take a look at the changes when a new version gets merged.
I then went back 25 commits, and there aren't any others marked this way.