> But as you can see elsewhere, we shouldn't pipe streams into anything.
Firstly, I'll assume you mean untrusted streams since if you didn't mean that, we might as well throw out UNIX entirely.
Even given that caveat though, I disagree. Downloading an image and then converting that image into another format is not a case where there's a material improvement in security when making temporary files instead of using pipes. I'd argue in some cases it may have the opposite effect.
It's indicative of the lack of rationale on this more general case that you selected an example where the piping is into sh here.
I agree with all of your points about piping into sh, just not that we can turn that into a general principal. It's OK if we have different best practices between these two cases.
This kind of advice taken by a laymen or junior dev can cause problems, because the second you put the file on disk there's a risk you won't clean up that content, which for an automated system will ultimately bring it down when the disk fills up. In addition, if the information downloaded is sensitive, you are creating a security problem if you are intentionally writing it on disk even if you do clean it up later, as filesystem data remains persistent after unlink.