An important to understand concept is how images in the Docker Hub are versioned. This is important to avoide accidential upgrades. Each line in the tags are the aliases, which refer to the same versions. E. g. for postgres:
Supported tags and respective Dockerfile links:
18.3, 18, latest, 18.3-trixie, 18-trixie, trixie
18.3-bookworm, 18-bookworm, bookworm
18.3-alpine3.23, 18-alpine3.23, alpine3.23, 18.3-alpine, 18-alpine, alpine
18.3-alpine3.22, 18-alpine3.22, alpine3.22
17.9, 17, 17.9-trixie, 17-trixie
17.9-bookworm, 17-bookworm
17.9-alpine3.23, 17-alpine3.23, 17.9-alpine, 17-alpine
17.9-alpine3.22, 17-alpine3.22
Meaning, postgres:18 is not pinned to version 18.0.0 but can refer to 18.3or .4 later on.
If you want to be safe, pin the version exactly - e. g. 18.3-alpine