BLAKE3 is nice, but it's not FIPS-certified, and we want to support environments that require this. SHA-3-256 is, like BLAKE3, not subject to length-extension / truncation attacks (unlike SHA-2!), so we don't need to change our truncation for Merkle hashes. (See https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf for more on this.)
BLAKE3 is nice, but it's not FIPS-certified, and we want to support environments that require this. SHA-3-256 is, like BLAKE3, not subject to length-extension / truncation attacks (unlike SHA-2!), so we don't need to change our truncation for Merkle hashes. (See https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf for more on this.)