A dataset of Terraform plan JSON resource changes labeled with security/compliance risk categories (multi‑label) across AWS / GCP / Azure.
CI/CD pre-merge “risk scanning” of infrastructure changes
Fine-tuning / training a small classifier to predict risk labels from plan snippets
Bootstrapping deterministic OPA/Conftest policy packs (labels can be derived from policy denies)