"Publish subset only" (ro-crate-html-output's `publishOnly` option) removes unpublished collections/objects/files from the in-memory crate before rendering the generated preview HTML — but it never touches the actual files on disk. A folder holding just the generated preview (`ro-crate-preview.html` / `ro-crate-preview_html/`) still contains every file the crate ever had, published or not, so deploying that folder as-is can expose files that were deliberately filtered out.
Copy the files that survive the publish filter into a dedicated `ro-crate-preview-files/` directory during the build, and rewrite the generated HTML's own file links to point at the copies — so publishing the generated preview plus that one folder is self-contained and never leaks a filtered-out file.
"Publish subset only" (ro-crate-html-output's `publishOnly` option) removes unpublished collections/objects/files from the in-memory crate before rendering the generated preview HTML — but it never touches the actual files on disk. A folder holding just the generated preview (`ro-crate-preview.html` / `ro-crate-preview_html/`) still contains every file the crate ever had, published or not, so deploying that folder as-is can expose files that were deliberately filtered out.
Copy the files that survive the publish filter into a dedicated `ro-crate-preview-files/` directory during the build, and rewrite the generated HTML's own file links to point at the copies — so publishing the generated preview plus that one folder is self-contained and never leaks a filtered-out file.