Release v2.14.2
See commit message: @cratis/ai has no OIDC trusted-publisher trust configured on npmjs.com yet (couldn't be, before the package existed). Wires the short-lived NPM_TOKEN repo secret as a classic auth fallback for this one publish step so CI can actually publish going forward. --provenance is unaffected (depends on id-token: write, not on which auth path npm itself uses). Follow-up: configure npm trusted publishing for @cratis/ai and remove this once someone with @Cratis npm org access has a moment.