diff --git a/CHANGELOG.md b/CHANGELOG.md
index ad77012..42da723 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -6,6 +6,42 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
Release notes for GitHub Releases are extracted from the matching version section here.
+## [0.14.1] - 2026-09-22
+
+
+### Documentation
+
+- **spec:** Restore the js-libp2p evidence cell truncated by #110
+
+- Document the LFS carriers and the unfiltered PR validation triggers
+
+- **knowledge:** Record the unfiltered pull-request validation triggers
+
+- **knowledge:** Drop the stale path-filter claims from the knowledge index
+
+- **spec:** Complete connect dependency evidence
+
+
+### Fixed
+
+- **connect:** Pin the C contract header to LF and verify its provenance
+
+- **connect:** Refresh Windows carrier provenance
+
+
+### Internal
+
+- Schedule every required check on every pull request
+
+- **connect:** Keep the carrier refresh artifact flowing on provenance drift
+
+- Run the connect identity proof on every pull request
+
+
+### build
+
+- **connect:** Track the C carrier dynamic libraries with git-lfs
+
## [0.14.0] - 2026-09-22
diff --git a/Cargo.lock b/Cargo.lock
index 547e8e6..7277b56 100644
--- a/Cargo.lock
+++ b/Cargo.lock
@@ -3100,7 +3100,7 @@ dependencies = [
[[package]]
name = "spoke-connect"
-version = "0.14.0"
+version = "0.14.1"
dependencies = [
"async-trait",
"base64",
@@ -3126,7 +3126,7 @@ dependencies = [
[[package]]
name = "spoke-connect-capi"
-version = "0.14.0"
+version = "0.14.1"
dependencies = [
"serde_json",
"spoke-connect",
@@ -3134,7 +3134,7 @@ dependencies = [
[[package]]
name = "spoke-fixture-toy-world"
-version = "0.14.0"
+version = "0.14.1"
dependencies = [
"async-trait",
"futures",
@@ -3147,7 +3147,7 @@ dependencies = [
[[package]]
name = "spoke-operations"
-version = "0.14.0"
+version = "0.14.1"
dependencies = [
"async-trait",
"chrono",
@@ -3160,7 +3160,7 @@ dependencies = [
[[package]]
name = "spoke-schemas"
-version = "0.14.0"
+version = "0.14.1"
dependencies = [
"chrono",
"regress",
diff --git a/Cargo.toml b/Cargo.toml
index fdc8b5a..764dd22 100644
--- a/Cargo.toml
+++ b/Cargo.toml
@@ -18,7 +18,7 @@ default-members = [
resolver = "2"
[workspace.package]
-version = "0.14.0"
+version = "0.14.1"
edition = "2021"
authors = ["42ch"]
license = "Apache-2.0"
diff --git a/crates/spoke-connect/Cargo.toml b/crates/spoke-connect/Cargo.toml
index 36a51d2..08305a4 100644
--- a/crates/spoke-connect/Cargo.toml
+++ b/crates/spoke-connect/Cargo.toml
@@ -13,11 +13,11 @@ description = "SPOKE Connect reference spike — libp2p transport, noise-peerid
exclude = ["bindings/**", "examples/**"]
[dependencies]
-spoke-schemas = { version = "0.14.0", path = "../spoke-schemas" }
+spoke-schemas = { version = "0.14.1", path = "../spoke-schemas" }
# RemoteAdapter (the `remote-adapter` feature) implements the operations
# BaselinePorts + SpokeResult types; optional so default connect builds stay
# lean (TS equivalent: the `./remote` subpath export).
-spoke-operations = { version = "0.14.0", path = "../spoke-operations", optional = true }
+spoke-operations = { version = "0.14.1", path = "../spoke-operations", optional = true }
# Loopback smoke host (RemoteAdapter FFI binding smokes; `ffi-smoke-host` only).
libp2p.workspace = true
serde.workspace = true
diff --git a/crates/spoke-connect/bindings/csharp/42ch.Spoke.Connect.csproj b/crates/spoke-connect/bindings/csharp/42ch.Spoke.Connect.csproj
index d778139..a40d4cf 100644
--- a/crates/spoke-connect/bindings/csharp/42ch.Spoke.Connect.csproj
+++ b/crates/spoke-connect/bindings/csharp/42ch.Spoke.Connect.csproj
@@ -18,7 +18,7 @@
42ch.Spoke.Connect
- 0.14.0
+ 0.14.1
42ch
42ch
SPOKE Connect session-core C# bindings (uniffi + native spoke_connect FFI). Transport stays product-owned.
diff --git a/crates/spoke-connect/bindings/kotlin/build.gradle.kts b/crates/spoke-connect/bindings/kotlin/build.gradle.kts
index dec30e7..c6e2d71 100644
--- a/crates/spoke-connect/bindings/kotlin/build.gradle.kts
+++ b/crates/spoke-connect/bindings/kotlin/build.gradle.kts
@@ -5,7 +5,7 @@ plugins {
group = "dev.42ch"
// Lockstep SemVer — asserted/bumped with tooling/release lockstep surfaces.
-version = "0.14.0"
+version = "0.14.1"
repositories {
mavenCentral()
diff --git a/crates/spoke-connect/bindings/python/pyproject.toml b/crates/spoke-connect/bindings/python/pyproject.toml
index 6f4709f..f1c98f5 100644
--- a/crates/spoke-connect/bindings/python/pyproject.toml
+++ b/crates/spoke-connect/bindings/python/pyproject.toml
@@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta"
[project]
name = "spoke-connect"
-version = "0.14.0"
+version = "0.14.1"
description = "SPOKE Connect session-core Python bindings (uniffi + native spoke_connect FFI)"
readme = "README.md"
license = "Apache-2.0"
diff --git a/crates/spoke-operations/Cargo.toml b/crates/spoke-operations/Cargo.toml
index 8ce9922..f5c5356 100644
--- a/crates/spoke-operations/Cargo.toml
+++ b/crates/spoke-operations/Cargo.toml
@@ -11,7 +11,7 @@ keywords = ["spoke", "knowledge-entry", "operations"]
categories = ["data-structures"]
[dependencies]
-spoke-schemas = { version = "0.14.0", path = "../spoke-schemas" }
+spoke-schemas = { version = "0.14.1", path = "../spoke-schemas" }
serde.workspace = true
serde_json.workspace = true
chrono.workspace = true
diff --git a/fixtures/toy-world/package.json b/fixtures/toy-world/package.json
index 9541f32..8ae09e3 100644
--- a/fixtures/toy-world/package.json
+++ b/fixtures/toy-world/package.json
@@ -1,6 +1,6 @@
{
"name": "@42ch/spoke-fixture-toy-world",
- "version": "0.14.0",
+ "version": "0.14.1",
"private": true,
"description": "SPOKE toy-world protocol fixtures and AJV/Vitest conformance harness",
"license": "Apache-2.0",
diff --git a/package.json b/package.json
index 23a42ec..311a4e6 100644
--- a/package.json
+++ b/package.json
@@ -1,6 +1,6 @@
{
"name": "spoke",
- "version": "0.14.0",
+ "version": "0.14.1",
"private": true,
"description": "SPOKE protocol monorepo — JSON Schema SSOT with generated TypeScript and Rust types",
"license": "Apache-2.0",
diff --git a/packages/spoke-connect-ts/package.json b/packages/spoke-connect-ts/package.json
index e926347..728b63c 100644
--- a/packages/spoke-connect-ts/package.json
+++ b/packages/spoke-connect-ts/package.json
@@ -1,6 +1,6 @@
{
"name": "@42ch/spoke-connect",
- "version": "0.14.0",
+ "version": "0.14.1",
"description": "SPOKE connect client library — pure-TS identity derivation, Ed25519 hello signing, and RFC 8785 JCS canonicalization",
"license": "Apache-2.0",
"repository": {
diff --git a/packages/spoke-operations/package.json b/packages/spoke-operations/package.json
index 42733ac..2f4caaa 100644
--- a/packages/spoke-operations/package.json
+++ b/packages/spoke-operations/package.json
@@ -1,6 +1,6 @@
{
"name": "@42ch/spoke-operations",
- "version": "0.14.0",
+ "version": "0.14.1",
"description": "SPOKE lifecycle operations — pure helpers over wire types",
"license": "Apache-2.0",
"repository": {
diff --git a/packages/spoke-schemas/package.json b/packages/spoke-schemas/package.json
index cfcc1b5..4e1a5cd 100644
--- a/packages/spoke-schemas/package.json
+++ b/packages/spoke-schemas/package.json
@@ -1,6 +1,6 @@
{
"name": "@42ch/spoke-schemas",
- "version": "0.14.0",
+ "version": "0.14.1",
"description": "SPOKE wire types — TypeScript generated from JSON Schema",
"license": "Apache-2.0",
"repository": {
diff --git a/tooling/codegen/package.json b/tooling/codegen/package.json
index 1987f14..d6cf338 100644
--- a/tooling/codegen/package.json
+++ b/tooling/codegen/package.json
@@ -1,6 +1,6 @@
{
"name": "@42ch/spoke-codegen",
- "version": "0.14.0",
+ "version": "0.14.1",
"private": true,
"license": "Apache-2.0",
"description": "SPOKE schema-to-code generation pipeline (TypeScript + Rust)",