Yeah, I agree, but then you are at the mercy of whatever vulnerability is found in the current version(s). It just feels like a lose-lose situation no matter what you do.
pnpm audit —fix for example will whitelist releases in cooldown phase when theres a known security issue for a version you currently use.