Ruby Devs – You’re too trusting. Gems could screw you. » RubySource
rubysource.com
rubysource.com
gem 'rails', '3.0.7' # for example
And also version the Gemfile.lock file. That way my environment is locked down until I decide to upgrade.
The big downside to this is that by missing out on the small incremental updates, when you do decide to update (or are forced to), then the chances of something breaking are pretty high as you suddenly leap up 27 versions of the gem. (Which of course makes you want to upgrade less often, which just makes the problem worse =)
I really hadn't thought too much about the security implications of the Gems - this is definitely something I'll need to start considering...