Thank God that most people, black hats included are frightened at X source code and generally wont touch it with a 10 foot pole.
Once all mainstream distributions begin shipping the modularized and autotooled freedesktop.org xlibs packages, the amount of pain which occurs when security issues are found will hopefully subside. The entire source tree really needs a heavy security audit, as well as a general cleanup. There's a lot of cruft there that hasn't been seen by human eyes for over 10 or more years.
FOAF updates: Trust rankings are now exported, making the data available to other users and websites. An external FOAF URI has been added, allowing users to link to an additional FOAF file.
Keep up with the latest Advogato features by reading the Advogato status blog.
If you're a C programmer with some spare time, take a look at the mod_virgule project page and help us with one of the tasks on the ToDo list!