Most changes have a github issue attached with discussion, all of the changes have descriptive commit messages regardless of who authored them and there is significant effort to document the decisions and decision process throughout.
I can't speak for the release frequency for other organizations' production that consumes this code. That includes many publishers, as well as other AMP caches such as Bing and webmail clients like Yahoo.
The repo is for all of AMP, not just the validator. The validator related issues are handled by the "caching" working group (since caches are the consumer of the validator) and you can search for them with this query: https://github.com/ampproject/amphtml/issues?q=is%3Aissue+is...