`pnpm` also has that and it's on by default since `v11`:
I guess it could work better if it was enabled for only actual attack vectors projects.
Many places run analyzers on published code; many security users have reason to shorten the period. The default period becomes the period where white hats have a chance to detect it and stop it passing the threshold.