Covering up legit vulnerabilities is dangerous - it is a criminal offense. And no “my manager doesn’t like it” is not an effective defense (see uber ciso case)
That is a sign that you work at a deeply unhealthy company. Even at a moderately healthy company it's usual to have "Don't shoot the messenger" policies in place to avoid blaming developers for doing their job.