This article kind of confuses me - what does it mean for a gem do be 'secure' ? The idea of many gems being 'secure' or 'non-secure' is a non-sequitur. Obviously for some projects, like Rails, it's fairly clear what is meant when someone talks about a vulnerability - that you can hacked somehow. However, if someone wrote a gem to wrap eval into a command line tool so they can use some random ruby commands or libraries from their shell, well, secure would be a non-sequitur, but also beside the point.