456818875d
install.sh duplicated the raw deep ad-hoc re-sign, so install/repair and self-update could disagree about the app's signing identity — an update signed with the stable identity would be clobbered back to a cdhash-only DR by the next installer repair. Call the shared Python fixup (passing the shell's publisher-signing decision explicitly), and branch into the historical xattr + deep ad-hoc repair when the venv helper is missing or fails so a broken venv never leaves the bundle unlaunchable. Co-authored-by: cipry0200 <cipry0200@users.noreply.github.com> Co-authored-by: natebransc <natebransc@users.noreply.github.com> Co-authored-by: caseyanthony <caseyanthony@users.noreply.github.com>