What separates organizations that fix their vulnerabilities from those that don’t? That’s what the research team at Semgrep wanted to know when it set out to analyze anonymized remediation patterns across thousands of actively developed repositories and organizations.