Searched for a similar issue but only found #2504 which was more than a year ago. It seems like there is another vulnerability affecting fast-xml-parser (GHSA-37qj-frw5-hhjh) versions 4.3.6 to 5.3.4, and @google-cloud/storage appears to depend on fast-xml-parser@4.5.3