This morning (in my local timezone), I received word of a security vulnerability in an upstream component of ProsePoint. In this case, it was SA-CONTRIB-2009-046 - Date - Cross Site Scripting (http://drupal.org/node/534636) and it affects the Drupal Date module.
For most security updates, I simply patch ProsePoint, test, and release. It takes a few hours, but otherwise I just churn the handle. Usually the release is out within about 12 hours of the disclosure of the original announcement, well within the self-imposed 24 hours response time.