Hi royosherove! Very interesting GOTO! I think these metrics you are talking about are really interesting.
At minute 30:13 you talk about those indicators and put some examples at the blackboard, I find most of them very interesting but for "Critical Security Issues" I'm really wondering how can you differentiate between PRs that are fixing things that PRs that are just implementing new features?
Thanks for reply :)