`python:slim-trixie` carried no version at all, so a rebuild could move the interpreter across a major release without anything in the repo changing. That is not hypothetical here: app/models.py referenced IcecastConfig about 85 lines before its definition and ran only because trixie currently ships Python 3.14, where PEP 649 defers annotation evaluation. On 3.13 it was a hard NameError. The ordering was fixed on 2026-08-16; the unpinned base outlived it. Pinned to 3.14-slim rather than 3.14-slim-trixie so it matches drb-edge-node, which was already on 3.14-slim. Patch releases still float, which is what we want for security updates -- only the major version is nailed down. Every other Dockerfile in both repos already pinned a major version (python:3.12-slim, python:3.14-slim, node:20-slim, debian:bookworm-slim), so this was the only genuinely unpinned base image, despite server-26#11 claiming none of them were pinned. Closes logan/server-26#11 (filed against the wrong repo -- the file lives in the client repo).