
Security News
Open VSX Begins Implementing Pre-Publish Security Checks After Repeated Supply Chain Incidents
Following multiple malicious extension incidents, Open VSX outlines new safeguards designed to catch risky uploads earlier.
tip-component
Advanced tools
Tip component. Inspired by tipsy without the weird jQuery API.


Live demo is here.
$ npm install tip-component
show the tip is shownhide the tip is hiddenEquivalent to Tip(el, { value: string }).
Attach a Tip to an element, and display the title
attribute's contents on hover. Optionally apply a hide delay
in milliseconds.
var tip = require('tip');
tip('a[title]', { delay: 300 });
Create a new tip with content being
either a string, html, element, etc.
var Tip = require('tip');
var tip = new Tip('Hello!');
tip.show('#mylink');
toptop righttop leftbottombottom rightbottom leftrightleftOptions:
auto set to false to disable auto-positioningShow the tip attached to el, where el
may be a selector or element.
Show the tip at the absolute position (x, y).
Hide the tip immediately or wait ms.
Attach the tip to the given el, showing on mouseover and hiding on mouseout.
Use effect name. Default with Tip.effect = 'fade' for example.
MIT
FAQs
Tip component
The npm package tip-component receives a total of 20 weekly downloads. As such, tip-component popularity was classified as not popular.
We found that tip-component demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 25 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Following multiple malicious extension incidents, Open VSX outlines new safeguards designed to catch risky uploads earlier.

Research
/Security News
Threat actors compromised four oorzc Open VSX extensions with more than 22,000 downloads, pushing malicious versions that install a staged loader, evade Russian-locale systems, pull C2 from Solana memos, and steal macOS credentials and wallets.

Security News
Lodash 4.17.23 marks a security reset, with maintainers rebuilding governance and infrastructure to support long-term, sustainable maintenance.