You'll notice
Publishing now blocks copy-sourced files that match a Read deny rule, not just the primary file.
When publishing, each copy-sourced file's slug is now run through the standard permission-rule deny check, not just the primary file_path/root as before. If any copied file is denied, the whole publish is blocked with a "nothing was published" error.