Only the latest release on PyPI receives security fixes.
Please do not open a public issue. Report privately via GitHub Security Advisories.
Include a description, steps to reproduce, affected version and, if possible, a proof-of-concept file. You should receive an acknowledgement within 7 days. Once a fix is released, the advisory will be published with credit to the reporter unless you prefer to stay anonymous.
nctab edits files that are later run on real machine tools. Besides classic issues (path traversal, unsafe file writes, code execution via config/profile/snippet files), we treat as security-relevant any bug where a transform silently produces a program that differs from what the preview showed.