Technically, Google does not follow or pass any signals from a link on a page that has a nofollow attribute on them. If you are super paranoid about that link ever dropping the nofollow, then using the disavow file should work for that paranoia.
John Mueller of Google said on Twitter that links that have a nofollow on them do not pass any signals. But if you want to disavow them as well, it does no harm he said.
Here are the tweets:
They don't pass any PR so there's nothing to disavow. It doesn't harm though.
— John ☆.o(≧▽≦)o.☆ (@JohnMu) November 11, 2017
I thought I'd lighten up the nofollow/disavow chatter going on now, since it is getting pretty heated.
Forum discussion at Twitter.