Exactly right. When I enabled IPv6 on my home LAN, I made very sure that only those hosts (and ports!) I wanted open were available to the outside world. Otherwise, incoming IPv6 is DROP by default.
This is strange, oft-repeated, mostly incorrect argument. Almost every modern router, if it handles IPv6, handles IPv6 without NAT but with a firewall. Most consumer routers just have ALLOW ALL outbound, ALLOW EXISTING inbound, default firewall rules that would be just fine for IPv6.