Even if you take every single precaution into account, it still won't save you from 0day exploits that exist on nearly every operating system with the exception of TempleOS. Even hardened BSD builds are affected.
You can disable Javascript manually in about:config, you can have NoScript enabled globally, and set Tor's browser security settings to the absolute max on Gentoo with OpenRC using off-shore VPN's with a MAC address spoofer in the background while leeching off of WiFi access point, and it still won't stop the federales from peering into your computer. At the very least, it's better than the idiots who straight use Tor on Windows 10 with telemetry left running in the background.