Given that docker compose v3 does not support adding pids limit on containers, it would be convenient setting this limit on daemon config level. Should work like the default for no-new-privileges.
docker/compose#4792
docker/docker-bench-security#319
#18697