I think its very important that you update your software on a regular bases. Hackers are always looking for a security hole, and if your running outdated software they are going to find it. I check for updates at least once a week. I think its very important once you have updated to make sure your updates didn't break anything.
As for bundled software I pretty much run my server box stock. Apache , Sendmail, MySQL, and VSFTP were all bundled with the Centos 4.2 server CD. I do how ever have many custom programs that I have installed on the server.
|