## Diamond Recursion Scan — CLEAN **Scan date:** 2026-03-29 **Pattern:** Recursive cycle/dependency check without visited set (CWE-407 diamond recursion, O(2^D)) ### Files examined - `pkg/chart/v2/util/dependencies.go` — `processDependencyEnabled`, `processDependencyImportValues` - `internal/chart/v3/util/dependencies.go` — same (v3 equivalent) - `pkg/chart/v2/lint/rules/dependencies.go` — `validateDependenciesUnique` - `pkg/engine/engine.go` — `recAllTpls`, `allTemplates` - `pkg/action/install.go` — `CheckDependencies` ### Findings **processDependencyEnabled:** Recurses into sub-charts. However, Helm charts embed their dependencies as nested tarballs — the dependency tree is structurally a tree (each chart is a separate embedded copy), not a DAG with shared references. Diamond graphs are impossible in this structure. CLEAN. **recAllTpls:** Recurses through `accessor.Dependencies()` — same tree structure argument applies. No shared nodes, no diamond. CLEAN. **CheckDependencies:** O(R×D) nested loop — no recursion. CLEAN. **validateDependenciesUnique:** Iterates flat arrays, no recursion. CLEAN. Note: `helm-0001` through `helm-0003` cover pre-existing CWE-407 defects in release filtering and repo update operations. ### Verdict: CLEAN — no diamond recursion CWE-407 found (Helm chart structure is a tree, not a DAG)