Also: if you're an employer, why not make this a policy? Apart from the ethical arguments, I've seen many commercial projects stall waiting for an open source feature or taking a hard to maintain internal branch when they could have just submitted the fix upstream for everybody. And it will please the kind of staff who you actually want to retain.
Open source maintainers at profitable companies: stop asking permission to fix what your employer already depends on.
No paperwork. No programme. No manager’s blessing. Just maintain it on the clock.