I have just committed an update to Entity API and Commerce, but I'm unsure what to do about Rules, because the latest release has regressions when used with Commerce: #2093881: Rules 7.x-2.5 inadvertently hides disabled payment method rules

Just rolled a release with your updates and the core update to 7.23. We'll leave Rules at 2.3 until some fix comes into Commerce itself or Rules to fix the visibility problem.

What about the current version of Rules?
Current Commerce Kickstart is using a version with security problems.

The latest Rules version doesn't work with Drupal Commerce. Once they fix their regression and tag a new release, we'll get it into Kickstart.

I don't think there have been any security fixes since 2.3. I could be wrong, but that's the last release of Rules that actually shows a SA notice. I think the code checking the module version here on d.o is providing a false security notification.

