Understanding the mean time to detection of a vulnerability is interesting, there are two key pieces of information that you need.
The first piece of information is around where a vulnerability may have been introduced, you need to be monitoring, measuring and capturing information about all of the various different changes and sources of potential vulnerabilities in order to truly understand the advent and the provenance.
The second thing you need to do is consolidate your understanding on what you consider to be a vulnerability. Do you consider something that a very paranoid SAST tool has highlighted as a potential deficiency to be a vulnerability? Or do you consider it to be a vulnerability when you've got a level of confidence in the validity of it when its been manually verified in some way?
You really need to have a system where you can funnel in all of these feeds of information about both the changes and about the vulnerabilities (with their related details) and combine these together in order to properly gauge your mean time to detection.