diff --git a/CHANGELOG.md b/CHANGELOG.md
index c4be2cc..d486e3d 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -3,6 +3,8 @@ Changelog
*Also see [Tools and installer changelog](https://github.com/clojure/brew-install/blob/1.11.1/CHANGELOG.md)*
+* next
+ * Revert update of Maven resolver libs - seeing resolution differences
* 0.18.1370 on Dec 4, 2023
* TDEPS-256 create-basis - when different project dir is specified, should be used to resolve relative local deps
* Update deps to latest
diff --git a/deps.edn b/deps.edn
index beb8509..e1c4186 100644
--- a/deps.edn
+++ b/deps.edn
@@ -1,15 +1,17 @@
{:paths ["src/main/clojure" "src/main/resources"]
:deps {
org.clojure/clojure {:mvn/version "1.10.3"}
- org.apache.maven.resolver/maven-resolver-api {:mvn/version "1.9.18"}
- org.apache.maven.resolver/maven-resolver-spi {:mvn/version "1.9.18"}
- org.apache.maven.resolver/maven-resolver-impl {:mvn/version "1.9.18"}
- org.apache.maven.resolver/maven-resolver-util {:mvn/version "1.9.18"}
- org.apache.maven.resolver/maven-resolver-connector-basic {:mvn/version "1.9.18"}
- org.apache.maven.resolver/maven-resolver-transport-file {:mvn/version "1.9.18"}
- org.apache.maven.resolver/maven-resolver-transport-http {:mvn/version "1.9.18"}
- org.apache.maven/maven-resolver-provider {:mvn/version "3.9.6"}
- org.apache.maven/maven-core {:mvn/version "3.9.6"}
+ org.apache.maven.resolver/maven-resolver-api {:mvn/version "1.8.2"}
+ org.apache.maven.resolver/maven-resolver-spi {:mvn/version "1.8.2"}
+ org.apache.maven.resolver/maven-resolver-impl {:mvn/version "1.8.2"}
+ org.apache.maven.resolver/maven-resolver-util {:mvn/version "1.8.2"}
+ org.apache.maven.resolver/maven-resolver-connector-basic {:mvn/version "1.8.2"}
+ org.apache.maven.resolver/maven-resolver-transport-file {:mvn/version "1.8.2"}
+ org.apache.maven.resolver/maven-resolver-transport-http {:mvn/version "1.8.2"}
+ org.apache.maven/maven-resolver-provider {:mvn/version "3.8.6"}
+ org.apache.maven/maven-core {:mvn/version "3.8.6" :exclusions [commons-io/commons-io com.google.guava/guava]}
+ commons-io/commons-io {:mvn/version "2.15.1"} ;; update transitive dep due to CVE-2021-29425
+ com.google.guava/guava {:mvn/version "31.1-jre"} ;; update transitive dep due to CVE-2020-8908
org.clojure/data.xml {:mvn/version "0.2.0-alpha8"}
org.clojure/tools.gitlibs {:mvn/version "2.5.197"}
org.clojure/tools.cli {:mvn/version "1.0.219"}
diff --git a/pom.xml b/pom.xml
index eb1f7d1..66e3145 100644
--- a/pom.xml
+++ b/pom.xml
@@ -21,8 +21,8 @@
true
1.10.3
- 1.9.18
- 3.9.6
+ 1.8.2
+ 3.8.6
1.10.3
@@ -78,6 +78,26 @@
org.apache.maven
maven-core
${mavenVersion}
+
+
+ commons-io
+ commons-io
+
+
+ com.google.guava
+ guava
+
+
+
+
+ commons-io
+ commons-io
+ 2.15.1
+
+
+ com.google.guava
+ guava
+ 31.1-android
org.slf4j