You're confusing HSTS with HPKP (key pinning). HSTS only mandates HTTPS but it never address
what certificate is the server's. HPKP
is the standard detailing certificate pinning (ensuring that the only certs are the correct one), but browsers ultimately decided against its implementation because of the difficulties associated with a hacked site effectivey ransomed by sending a HPKP with attacker-controlled certs.
Edit: since that you might get confused on why HPKP can ransom a site, consider this case:
0. The owner of the website doesn't know about HPKP or decides against implementing HPKP due to its burden.
1. Either the web server, DNS service or BGP corresponding to the IP address of the server is hacked. The attacker can now control the site.
2. The attacker then issues a new certificate. Since that they control the keys, they can send an HPKP header that only locks the key that attackers controlled.
3. Unknowing users visit the site. The site can either be still active (web server hack) or proxied back to the legitimate site (DNS or BGP hijack). HPKP keys are remembered.
4. The owner now realises that their site is hacked and tries to restore it. Let's assume that they have revoked their old cert and issues a new and shiny one which is never in the HPKP header in the first place.
5. Users visit the supposedly now-restored site, but instead of succesfully connecting back it errors out with an HPKP error. The owner can't do anything but to migrate to a new domain name.